daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (2541B)


      1 ---
      2 title: "Tabnabbing"
      3 topic: "Tabnabbing"
      4 topicSlug: "tabnabbing"
      5 sourcePath: "Tabnabbing/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Tabnabbing/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Tabnabbing
     12 
     13 > Reverse tabnabbing is an attack where a page linked from the target page is able to rewrite that page, for example to replace it with a phishing site. As the user was originally on the correct page they are less likely to notice that it has been changed to a phishing site, especially if the site looks the same as the target. If the user authenticates to this new page then their credentials (or other sensitive data) are sent to the phishing site rather than the legitimate one.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Methodology](#methodology)
     19 * [Exploit](#exploit)
     20 * [Discover](#discover)
     21 * [References](#references)
     22 
     23 ## Tools
     24 
     25 * [PortSwigger/discovering-reversetabnabbing](https://portswigger.net/bappstore/80eb8fd46bf847b4b17861482c2f2a30) - Discovering Reverse Tabnabbing
     26 
     27 ## Methodology
     28 
     29 When tabnabbing, the attacker searches for links that are inserted into the website and are under his control. Such links may be contained in a forum post, for example. Once he has found this kind of functionality, it checks that the link's `rel` attribute does not contain the value `noopener` and the target attribute contains the value `_blank`. If this is the case, the website is vulnerable to tabnabbing.
     30 
     31 ## Exploit
     32 
     33 1. Attacker posts a link to a website under his control that contains the following JS code: `window.opener.location = "http://evil.com"`
     34 2. He tricks the victim into visiting the link, which is opened in the browser in a new tab.
     35 3. At the same time the JS code is executed and the background tab is redirected to the website evil.com, which is most likely a phishing website.
     36 4. If the victim opens the background tab again and doesn't look at the address bar, it may happen that he thinks he is logged out, because a login page appears, for example.
     37 5. The victim tries to log on again and the attacker receives the credentials
     38 
     39 ## Discover
     40 
     41 Search for the following link formats:
     42 
     43 ```html
     44 <a href="..." target="_blank" rel=""> 
     45 <a href="..." target="_blank">
     46 ```
     47 
     48 ## References
     49 
     50 * [Reverse Tabnabbing - OWASP - October 20, 2020](https://web.archive.org/web/20200428035205/https://owasp.org/www-community/attacks/Reverse_Tabnabbing)
     51 * [Tabnabbing - Wikipedia - May 25, 2010](https://web.archive.org/web/20251216150740/https://en.wikipedia.org/wiki/Tabnabbing)