Sites you can pwn using Firesheep:
- Flickr
- Yahoo! Mail
- Windows Live
- Hotmail
- Google.com (not GMail)
- Slashdot
- Amazon
- Newegg
- Home Depot
- United Airlines
- Office Max
- Wordpress (when not using their optional SSL)
- More coming soon!
In truth, Wireshark did this ages ago via the little-known-method of copy/paste :) Turn the clock back to the beginnings of 802.11, war-driving, wep-cracking, and this type of attack was still valid. Why all the discussion now? Because instead of copy/paste, you get a nice little GUI and employ the uber-powerful double-click!
What does all this mean? Whenever an attack gets easier, it tends to become more popular. You can bet top dollar that going forward, at Starbucks, Safeways, Hotels, or wherever there is free open wifi, there will be someone running Firesheep. Hint: look for the script kiddie, social outcast, or the dude laughing so hard he looks like he may shit himself.
Few words of caution if you intend on "testing" this out in your neighborhood:
- People are already doing this, so you're behind the times (see above link)
- Most owners of open-wifi at commercial establishments have ToS (terms of service), you are likely violating those terms of service. However, those ToS also go both ways, informing users that there can be no expectation of privacy, or liability for the store/wifi owner, should damage occur.
- In many countries/states/counties/cities, it is illegal to sniff networks for user information unless said users authorize the action. Check your local laws. IANAL
- POP3 Mail
- SMTP Mail
- IMAP Mail
- FTP
Looking forward to part 3, beating Firesheep is something I have more use for than using Firesheep.
ReplyDeletewow, didn't know that it could be so easy. Great blog, you've got a new follower!
ReplyDeleteThis is sweet!
ReplyDeletevery nice post man, great job
ReplyDeleteI love the illustrative pics in ur blog. Makes me giggle.
ReplyDeletecan't wait for the next post
ReplyDeleteyeah keep it coming!
ReplyDeletenice post bro!
ReplyDeleteGreat info, keeping an eye out for part 3!
ReplyDeletenice post. Followed.
ReplyDeletehaha those images were funny
ReplyDeletewow, that's some great text mixed with great image. nice post, keep up the good work man !
ReplyDeleteInteresting stuff
ReplyDeleteGreat images, and interesting content, you have a new follower here as well!
ReplyDeleteyup i been using it for awhile i like it lol change my friends sex to female alot....
ReplyDeleteThis is great, I love it!
ReplyDeleteMan, this is crazy... now if only I cared about hacking someone's facebook...
ReplyDeleteawesome! waiting for updates..
ReplyDeleteToo bad I don't have anything to hack, or this would be really useful.
ReplyDeletethis will come in handy..
ReplyDeleteNice stuff, liking the layout of your blog, suits your content well
ReplyDeletesadly this dosnt work on my campus's wifi, damn they are smart|:
ReplyDelete