Pages: [1]
Print
Author Topic: Test yoself before you wreck yoself  (Read 228 times)
Thomphoolery
Constable Thomas Van Hoolery
Guild Member


Posts: 3951
429.00g

View Inventory
Send Money to Thomphoolery


View Profile
« on: October 25, 2010, 07:32:39 AM »

http://codebutler.com/firesheep

Interesting tool.

-j
Logged
Djfurball
The title changer
Guild Member


Posts: 3792
14713.00g

View Inventory
Send Money to Djfurball

Multivitamin Addict


View Profile
« Reply #1 on: October 25, 2010, 07:42:20 AM »

Yikes.
Logged

Varg:  I wanged some dude in the head with a turkey bone two years ago at pgh ren fest.
Omegaman
I <3 Chompers.


Posts: 1791
6870.00g

View Inventory
Send Money to Omegaman

It will!


View Profile
« Reply #2 on: October 25, 2010, 08:54:31 AM »

<a href="http://www.youtube.com/v/chNc7nGhQ4M" target="_blank">http://www.youtube.com/v/chNc7nGhQ4M</a>

What he meant to say was... "Keaton always said, 'I don't believe in God, but I'm afraid of him.' Well I believe in God, and the only thing that scares me is Evercookie."

Evercookie

Brought to you buy the same person who created the Samy Worm attack on MySpace years ago.
Logged

snarky - adj. A witty mannerism, personality, or behavior that is a combination of sarcasm and cynicism. Usually accepted as a complimentary term. Snark is sometimes mistaken for a snotty or arrogant attitude.
Skuld
Skuldamus Prime


Posts: 239
101.00g

View Inventory
Send Money to Skuld

meow. =^.^=


View Profile WWW
« Reply #3 on: October 25, 2010, 08:59:08 AM »

I know that quote (with out the Evercookie =^.^=)!!! Usual Suspects is one of my fav movies... Saddly at work I can't check that video file... >.> Will watch on my phone instead!
Logged

You have been meowed.
Falaenx
Frumptious
Guild Member


Posts: 2059
22331.00g

View Inventory
Send Money to Falaenx

Pedofal


View Profile
« Reply #4 on: October 25, 2010, 09:21:01 AM »

This should produce some decent entertainment for me today at the university.
Logged

Nazgrax
Puppetmaster
Guild Member


Posts: 1192
5383.00g

View Inventory
Send Money to Nazgrax

Herald of the AFK


View Profile
« Reply #5 on: October 25, 2010, 03:44:08 PM »

This should produce some decent entertainment for me today at the university.
Logged

My vehicle interior is constructed from a crosswork of reptilian origin, and although manufactured by Chevrolet it is of such ridiculous size as to best be compared to a cinema.
Omegaman
I <3 Chompers.


Posts: 1791
6870.00g

View Inventory
Send Money to Omegaman

It will!


View Profile
« Reply #6 on: October 27, 2010, 01:45:49 PM »


From TechCrunch...a how to guide on installing a Firefox plugin to help circumvent what Firesheep attempts to exploit.  I haven't tested these yet, and I'm not certain the plugins work on all Firefox versions.  You will probably have to keep yourself updated on this.  This isn't an end all, be all fix, and you have to manually type in the sites you want to ensure get forced to HTTPS, but it's better than nothing.  Understand, this isn't a browser exploit, this is simply the website's problem, swapping you back to nonSSL after the login session and only authenticating you with an insecure cookie which gets sent back and forth during the entire session on those sites.

Current websites vulnerable by Firesheep: Amazon, Basecamp, bit.ly, Enom, FaceBook, FourSquare, Github, Google, Hacker News, Harvest, The New York Times, Pivotal Tracker, Twitter, ToorCon, Evernote, Dropbox, Windows Live, Cisco, Slicehost, Gowalla, Flickr

Sites potentially soon to be supported by Firesheep:  Yahoo, eBay, Linkedin, Digg, Reddit, Wikipedia, Blogger, GoDaddy, Posterous, Tumbr, Netflix, YouTube, SlashDot, MobileMe, PayPal, Salesforce, Craigslist, MySpace, Match, AOL

As I've said many times, please try to avoid logging in to any site over a wifi or unprotected/unsecure internet connection. 

There still exist programs like Cain&Abel for password sniffing over networks and raw data dumps.  I think there are even mobile apps now that piggy back Cain&Abel and Wireshark

As Thom said, "Test yoself before you wreck yoself."
Logged

snarky - adj. A witty mannerism, personality, or behavior that is a combination of sarcasm and cynicism. Usually accepted as a complimentary term. Snark is sometimes mistaken for a snotty or arrogant attitude.
Thomphoolery
Constable Thomas Van Hoolery
Guild Member


Posts: 3951
429.00g

View Inventory
Send Money to Thomphoolery


View Profile
« Reply #7 on: October 27, 2010, 01:51:46 PM »

Current websites vulnerable by Firesheep: Amazon, Basecamp, bit.ly, Enom, FaceBook, FourSquare, Github, Google, Hacker News, Harvest, The New York Times, Pivotal Tracker, Twitter, ToorCon, Evernote, Dropbox, Windows Live, Cisco, Slicehost, Gowalla, Flickr

Sites potentially soon to be supported by Firesheep:  Yahoo, eBay, Linkedin, Digg, Reddit, Wikipedia, Blogger, GoDaddy, Posterous, Tumbr, Netflix, YouTube, SlashDot, MobileMe, PayPal, Salesforce, Craigslist, MySpace, Match, AOL

For those who don't want to install a Firefox plugin, you can simply make sure you use the https version instead of the http version in most cases. For instance, https://www.google.com/* instead of http://www.google.com/

-j
Logged
Djfurball
The title changer
Guild Member


Posts: 3792
14713.00g

View Inventory
Send Money to Djfurball

Multivitamin Addict


View Profile
« Reply #8 on: October 28, 2010, 06:11:49 AM »

http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html

Never knew that Flash had its own cookies, and that you can remove them from that page.

TMYK
Logged

Varg:  I wanged some dude in the head with a turkey bone two years ago at pgh ren fest.
Pages: [1]
Print
Jump to: