1. URL address bar spoofing
Move the mouse over the URL - the status bar displays the URL
Mouse click/drag and drop URL—load address bar and page
URL address bar spoofing
Click URL Spoofing
Browser functionality
Onclick(), Onmouseup(), Onmousedown()
Browser differences
HTML5 pushState(), 20%, long 20%, space,?
Browser's own characteristics...
Drag and Drop URL Spoofing
Chrome, Firefox, IE, Safari
ondragstart
event.dataTransfer.setData('url type','url')
DEMO
2. URL status bar spoofing
URL status bar spoofing
Tag spoofing attack principle
How Tabnabbing works
User normal browser website
Detection of page losing focus for a long time
Tamper with tag icon, title, page content
Users view numerous open tabs again, and fake tabs create visual deception.
The user opens the fake page, logs in...and jumps to the real page.
Affected: Chrome, Firefox