![]() |
|
|
#1 (permalink) |
|
Senior Member
Join Date: Sep 2010
Location: Planet X
Posts: 487
|
http://lifehacker.com/#!5672313/snif...with-firesheep
Firesheep is a proof-of-concept Firefox extension created by Eric Butler to show how leaky the security many popular web sites (like Facebook, Flickr, Amazon.com, Dropbox, Evernote, and more) employ is. The problem, as Firesheep shockingly demonstrates, is that many web sites only encrypt your login. Once you are logged in they use an unsecured connection with a simple cookie check. Anyone from your IP address (that of the Wi-Fi hotspot) with that cookie can be you. When using Firesheep on a public hot spot any session it can intercept is displayed in the Firesheep pane with the user's name and photograph (when available). Simply click on their name to intercept the session and start browsing the website as though you are them. |
|
|
|
|
|
#2 (permalink) |
|
Editor
Join Date: Jul 2010
Posts: 202
|
See the recent tip on using HTTPS.
|
|
|
|
|
|
#3 (permalink) |
|
Senior Member
Join Date: Sep 2010
Location: Planet X
Posts: 487
|
yep lol i know about https, its just that the am i secure thread reminded me of firesheep.
and since it's different topic, i figured if people didnt know about why using https and such is important, this thread might help that |
|
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|