Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

meelash

macrumors member
Original poster
Aug 7, 2008
56
0
http://codebutler.com/firesheep

Easy, one click HTTP Session hijacking from within firefox.

Step 1: Go to public wireless access point (coffee shop, student center, etc.)
Step 2: Have open, one-click access to people's facebook, twitter, etc.


Yup, it's really that easy.:eek:
 

meelash

macrumors member
Original poster
Aug 7, 2008
56
0
Seriously, you guys don't find this an interesting topic of discussion?? I can't believe that no one here is not regularly using unsecured, free wireless at coffee shops and university campuses. You aren't surprised by how easy this is?


Obviously (I hope), the how to be a stalker thing was tongue-in-cheek.
 

184550

Guest
May 8, 2008
1,980
2
I don't think many people realized this was in the news yesterday.

Perhaps you should have posted a link to facilitate the discussion.
 

*LTD*

macrumors G4
Feb 5, 2009
10,703
1
Canada
Seriously, you guys don't find this an interesting topic of discussion?? I can't believe that no one here is not regularly using unsecured, free wireless at coffee shops and university campuses.

Some of us have a data plan. ;)
 

benhollberg

macrumors 68020
Mar 8, 2010
2,170
7
Seriously, you guys don't find this an interesting topic of discussion?? I can't believe that no one here is not regularly using unsecured, free wireless at coffee shops and university campuses. You aren't surprised by how easy this is?


Obviously (I hope), the how to be a stalker thing was tongue-in-cheek.

I have tried it at my school, the University of Utah, and the school has blocked certain ports. It says it cannot access some port and therefore won't work. However on the school's unsecured open network it does work.
 

Melrose

Suspended
Dec 12, 2007
7,806
399
I downloaded this and installed it. Note, it needs the latest build of Firefox to work.

I find this type of thing very interesting, and I certainly hope it forces Big Website to implement necessary changes. That said, I'm never on public networks doing things I need to have locked down tight, so it's no skin off my nose. Still, one of these days I'll take my MBP to the library and try it out. :D

Although, there are legal ramifications if you get caught. This type of covert espionage - however white-hat or yokel it may be - is illegal.
 

belvdr

macrumors 603
Aug 15, 2005
5,945
1,372
One thing to note is it does not work on encrypted networks regardless of whether you have the key.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.