Professional Webmasters Community
Would you like to react to this message? Create an account in a few clicks or log in to continue.

Firesheep - Firefox HTTP session hijacking extension

Go down

Firesheep - Firefox HTTP session hijacking extension Empty Firesheep - Firefox HTTP session hijacking extension

Post  andry Wed Dec 15, 2010 2:53 am

Firefox extension that demonstrates HTTP session hijacking attacks

When logging into a website you usually start by submitting your username and password. The server then checks to see if an account matching this information exists and if so, replies back to you with a "cookie" which is used by your browser for all subsequent requests.
It's extremely common for websites to protect your password by encrypting the initial login, but surprisingly uncommon for websites to encrypt everything else. This leaves the cookie (and the user) vulnerable. HTTP session hijacking (sometimes called "sidejacking") is when an attacker gets a hold of a user's cookie, allowing them to do anything the user can do on a particular website. On an open wireless network, cookies are basically shouted through the air, making these attacks extremely easy.

Firesheep is free, open source, and is available now for Mac OS X and Windows. Linux support is on the way.
Websites have a responsibility to protect the people who depend on their services. They've been ignoring this responsibility for too long, and it's time for everyone to demand a more secure web. My hope is that Firesheep will help the users win.

Download and more details : http://codebutler.com

check also Firefox extension allows users to hack into Facebook, Twitter accounts
andry
andry
Moderator
Moderator

Posts : 467
Join date : 2010-05-07

Back to top Go down

Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum