crowdersblog.com

  • Contact Us
«  

February

  »
M T W T F S S
 
 
1
 
2
 
3
 
4
 
5
 
6
 
7
 
8
 
9
 
10
 
11
 
12
 
13
 
14
 
15
 
16
 
17
 
18
 
19
 
20
 
21
 
22
 
23
 
24
 
25
 
26
 
27
 
28
 
29
 
 
 
 
 

Navigation

  • Blogs
  • Mobile Site
  • Feed aggregator
    • Categories
      • Anglian Water
      • Angling News
      • IT Security
      • SANS
      • Trout Fishing
    • Sources

Bookmark and Share This Page

share

User login

Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password

Recent blog posts

  • Non Native Invasive Bloody Red Mysid Shrimp in Rutland Water - Hemimysis anomala
  • Invitation From A Double World Champion
  • Seasons Greeting From New Zealands North Island
  • Troutmasters Final 2011
  • Cormorant Watch
  • Sheeva Plug Computer Setup
  • Firesheep exposes weaknesses of open wireless networks
  • Invasion of the Killer Shrimp
  • Trout Personal Bests
  • Rutland 5lb 5oz Personal Best Rainbow Trout
more

Valid W3C XHTML 1.0 Strict

W3C XHTML 1.0

Anglian Water Leisure

  • Vitruvian Triathlon at Rutland Water Park
  • British Birdwatching Fair 2012
  • Great East Swim Alton Water
  • Dambuster Duathlon
  • Family nest box challenge
more

Anglian Water News

  • Fighting the fat in Lincoln
  • Underground reservoir is scrubbing up well
  • Go-ahead for 63km Lincolnshire pipeline
  • Anglian Water statement on water bills for 2012 / 13
  • Endangered dormice move to Alton Water
more

SANS Newsbites

  • FBI Says Social Network Monitoring Plan Will Abide By Privacy Rules (February 14, 2012)
  • EU Court of Justice Says Social Networks Cannot be Forced to Filter for Piracy (February 16, 2012)
  • Apple Will Require Apps to Obtain User Permission Before Accessing Contact Data (February 15, 2012)
  • Cyber Security Legislation Meets With Criticism From Many Angles (February 16, 2012)
  • Adobe Issues Out of Cycle Fix for Flash (February 16, 2012)
more

Trout Fishing

  • Open Invitation
  • The Rutland Youth Fly Fishing Day Secures Funding
more

Tags in Trout

Pitsford Water Rutland Water Rutland Grafham Water Trout Fishing Pitsford Ravensthorpe Reservoir Trout Bank Fly Fishing For Reservoir Trout - A New Dawn - Part Three Brown Trout Recipes
Home » Blogs » GaryV's blog

Firesheep exposes weaknesses of open wireless networks

Submitted by GaryV on Thu, 28/10/2010 - 09:41

Firesheep is a Firefox extension that captures user names and passwords of any person utilizing the same open wireless network. To show people how vulnerable they're on public wi-fi, Firesheeps designer created the extension to exploit the validation cookies used by social networks and other websites. Firesheep can be thwarted, nevertheless, with Firefox extensions designed for additional amounts of encryption.

Source of article - Firesheep Firefox extension - sidejacking made easy makes a point by Personal Money Store.

Firesheep makes it so you are able to hack social networks easily

Anyone can walk into a coffee shop and start hacking others' lives with Firesheep. There is only one thing making it so Firesheep can word. There's a cookie the server replies with when a user submits a user name and password to log into something which will let the user continue on with authentication. According to Eric Butler, who developed Firesheep, on the open wireless network in that coffee shop, cookies are being shouted through the air. Websites commonly protect user names and passwords by encrypting the login. However, in the interests of expediency, the cookie is not protected. On an open wireless network, sidejacking, or HTTP session hacking, is like shooting fish in a barrel.

Utilizing Firesheep

Firesheep is available on Mac OS X and Windows. It's free too. A new sidebar will appear on your Firefox browser after you've installed Firesheep. Go to the coffee shop, go to its open wireless network. The "Start Capturing" button is all you have to click. Anyone using the network logged into Facebook, or any other insecure website acknowledged by Firesheep will show up. The sidebar will display their name and photo. Firesheep will log into their private account as soon as you double-click on the photo. Firesheep sidejackers can do whichever they feel like after that.

How to stop Firesheep

You do not have to let Firesheep in. There is something you can do. According to TechCrunch, Firesheep works because most social websites, after encrypting login details, default to the HTTP protocol. "Force-TLS" is a Firefox extension that causes online websites to use the HTTPS protocol. That is the only reason why Firesheep can detect cookies. Users can change HTTP to HTTPS on websites with the Firefox Add On "Preferences" menu which is done with the Force-TLS Firefox expansion. HTTPS encrypts all user data so Firesheep can't read it. Facebook, Twitter and Google all allow HTTPS connections. Most major web sites will. Amazon doesn't right now though.

Data from

Code Butler

codebutler.com/firesheep

The Register

theregister.co.uk/2010/10/25/firesheep_cookie_capture_peril/

Tech Crunch

techcrunch.com/2010/10/25/firesheep/

  • GaryV's blog
  • share
  • Subscribe to: This post
  • Subscribe to: Posts of type Blog Entry
  • Printer-friendly version
  • Send to friend
  • PDF version

No responses to "Firesheep exposes weaknesses of open wireless networks"

Post new comment

The content of this field is kept private and will not be shown publicly.
Input format
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Each email address will be obfuscated in a human readable fashion or (if JavaScript is enabled) replaced with a spamproof clickable link.
  • Twitter-style @usersnames are linked to their Twitter account pages.
  • Twitter-style #hashtags are linked to search.twitter.com.

More information about formatting options

Subscriptions (0)
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Enter the characters shown in the image.
By submitting this form, you accept the Mollom privacy policy.

Syndicate

Syndicate content

Contact Menu

  • Contact Us

Tag Cloud

Trout Fishing Rutland Events Trout Pitsford Pitsford Grafham Ravensthorpe Trout Grafham Rutland Pitsford Water Rick Barlows Trout Flies Freely Licensed Sheeva Plug Security Rick Barlows Trout Wordpress Linux Weather Tackle Ravensthorpe Drupal W3C
more tags

Twitterings

  • Our internet safety obsession is bad for children > too true http://t.co/CDF6qHuX — 1 day 3 hours ago
  • Potential repeat of '76 #drought http://t.co/HhUaRIdN rain dance time! — 2 days 12 hours ago
  • @jlballinteriors Will do. Talked to John Seaton many times the last few seasons and he is always very helpfull. — 3 days 37 min ago
  • @FishRutland Wonder if AW will see these ideas or action any of them? Probably do a review in a years time see if any come to fruition :) — 3 days 1 hour ago
  • Poll Who is the most despicable female character in A Song of Ice and Fire? http://t.co/Wmcd1Vh4 #asongoficeandfire — 3 days 1 hour ago
  •  
  • 1 of 20
  • ››

Follow Me On Twitter

Follow @stevecrowder

Poll

Who is the most despicable female character in A Song of Ice and Fire?:

Recent comments

  • surprise
    30 weeks 19 hours ago
  • Would it be okay with you if
    32 weeks 3 days ago
  • Gravalax
    37 weeks 3 days ago
  • Mums Swedish Fish Stew
    45 weeks 2 days ago
  • "I want to experiment with
    1 year 1 day ago
  • re:
    1 year 10 weeks ago
  • re:
    1 year 20 weeks ago
  • best boat seat material
    1 year 21 weeks ago
  • Vegetable mashed potatoes with fish under marinade
    1 year 24 weeks ago
  • Orvis
    1 year 25 weeks ago

Google Ads

Tags in Image Galleries

Rutland Trout Pitsford Grafham Ravensthorpe Freely Licensed Rick Barlows Trout Sheeva Plug Rick Barlows Trout Flies New Zealand

Latest image

Hemimysis anomala GLERL 4

Random image

Rutland 6lb 2oz Rainbow Trout 18-11-2011 Boatseat

Angling News

  • Sea Angling 2012 Project Update
  • Angling Trust says drought is a wake up call for England's shrinking rivers
  • BBC Report: Fish Legal serve notice on the Environment Agency on behalf of Llyfni Angling Society
  • Out and About: Cob House Fisheries
  • Statement from the Angling Trust about Alleged Cheating Attempt in Sea Angling Competition
more

Most printed

  • BlackBerry Internet Service Over The Air Calendar Sync to Gmail
  • Sheeva Plug Computer Setup
  • Hardy and Greys Customer Service

Most emailed

  • Pitsford Water: A History
  • Hello World!
  • Rutland Boat Seat Merlin Products - Product Review
I love Smashing Magazine!

Copyright © crowdersblog.com 2012. All rights reserved. | Privacy Policy

Privacy Policy

Fervens Drupal theme by Leow Kah Thong. Designed by Design Disease and brought to you by Smashing Magazine.