majithia23 Posted March 20, 2011 Share Posted March 20, 2011 what is Firesheep ?Firesheep allowsany user to seamlessly hijack the web session of another user on the same local network. Although such attacks are not new, the ease of use presented by Firesheep brings session hijacking to the masses.Session hijacking is nothing new. Web sites typically use SSL connections for initial login pages, but revert to non-encrypted traffic for all subsequent communication. As such, while a user's username and password may be protected, once they are authenticated, any user on the same network can simply sniff network traffic, obtain a user's session ID and then hijack their session for a given website. Although this has always been a serious risk, especially on insecure networks such as public wifi hot spots, some degree of technical knowledge was required to accomplish the attack. Firesheep, opens such attacks to the masses as it turns session hijacking into a point and click exercise. Unless websites mandate SSL for all traffic on the site, session hijacking will always remain a threat. Fortunately, BlackSheep can be used to let you know if someone is running Firesheep on the same network.Blacksheep --BlackSheep, also a Firefox plugin is designed to combat Firesheep. BlackSheep does this by dropping 'fake' session ID information on the wire and then monitors traffic to see if it has been hijacked. While Firesheep is largely passive, once it identifies session information for a targeted domain, it then makes a subsequent request to that same domain, using the hijacked session information in order to obtain the name of the hijacked user along with an image of the person, if available. It is this request that BlackSheep identifies in order to detect the presence of Firesheep on the network. When identified, the user will be receive the following warning message: It should be noted that Firesheep and BlackSheep cannot be installed on the same Firefox instance as they share much of the same code base. If you want to run both Firesheep and BlackSheep on the same machine, they should be installed in separate Firefox profiles.BlackSheep options can be accessed by navigating to Tools > Add-ons within Firefox. Once there, under the Extensions tab, select the Preferences button for BlackSheep.Check Interval: BlackSheep will continually drop fake session information onto the wire and then listen for another IP address re-submitting this same information, as this will indicate the presence of Firesheep on the network. The Check Interval identifies the number of minutes between checks. Interface: Allows the user to configure the network interface that BlackSheep should listen on.Blacksheep Link to comment Share on other sites More sharing options...
hellohello Posted March 21, 2011 Share Posted March 21, 2011 Wow I never know about firesheep, bad thought come into my mind.Oh well, I am not sure how many others bad thought on me lol. Time to get blacksheep Link to comment Share on other sites More sharing options...
katanga Posted March 27, 2011 Share Posted March 27, 2011 Remember Firesheep about Facebook account. Link to comment Share on other sites More sharing options...
avmad Posted March 27, 2011 Share Posted March 27, 2011 Says to install WinPcap before blacksheep. What is it? Ok i've seen what it is but is it safe and needed? Link to comment Share on other sites More sharing options...
Administrator DKT27 Posted March 27, 2011 Administrator Share Posted March 27, 2011 Says to install WinPcap before blacksheep. What is it? Ok i've seen what it is but is it safe and needed?Winpcap is trustable. Many softwares need it. Most of them include it in the software installer, but this is a addon so... Link to comment Share on other sites More sharing options...
avmad Posted March 27, 2011 Share Posted March 27, 2011 Just didn't want to leave anything open to attack. :o I'll try it out. Link to comment Share on other sites More sharing options...
Patrick Posted April 3, 2011 Share Posted April 3, 2011 I always have this on my FF, set scanning every minute, since I know a couple of douchebags that has Firesheep for 24/7 on our connection. Link to comment Share on other sites More sharing options...
Silver90 Posted April 8, 2011 Share Posted April 8, 2011 Firesheep still works? Haven facebook patched their system or something? Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.