Firefox extension makes Facebook 'sidejacking' easy

therickster90 said:
I just tried it. I'm sitting here at school on an unsecured connection with 20 people on laptops around me and the only thing it is picking up is my gmail login, which is https. hmmm...at least I don't have facebook anymore.

Same here. Except I am trying it on my home network (WPA-PSK). I use my roommates computer (with her permission) to log into her Facebook and click random links. Nothing shows up.

It does, however, pick up my own credentials.

Thanks Firesheep!
 
Old news to anyone that uses tcpdump/Wireshark or any other network sniffer if you know how to find the "session keys". Any unencrypted(or poorly encrypted) data can be intercepted for "bad" purposes. IE iPhones will send/receive all of their local bookmarks in plain text when they sync with the server. This doesn't even take into consideration "man in the middle" attacks.

For the comments along the lines of "don't put anything important and it isn't a problem." You are quite simply wrong if anyone on your friends list trusts that you are you. I could steal your FB account(and even better if I got access to your FB email account at the same time) and then pretend I was stranded somewhere you had mentioned traveling to recently, or as was the case in a recent FB chat exploit scam claim I was in London. And along with the notice, ask for money since I need to pay off some fee or another.
 
AppleFanboy said:
This is why I use Safari.;)

Which does you no good. This isn't a FF problem. It's a combination of using a public WiFi service and websites not encrypting your sessions. His FireFox extension would show all your Safari sessions too.
 
Its always better and safer to visit such private sites from your most secured location called HOME. I never try to access my emails and other pvt accounts outside of home network.
 
Back