One thing I noticed you can do is logout when you are finished. If you log out the session ends and they cant get into your Facebook. But alot of people dont logout they just close the browser or even put the computer to sleep. Even if you move to a new network and they havent logged out, you can still get to their Facebook page.
@buffelting Thanks for this very clear explanation of a problem I didn't even know I had. Still not 100% sure what I should do though. does this mean that people can hack into basically all and any computers if the internet conncetions aren't secured by a personal password?
All you have to do is fire up ssltrip to get around ssl, so that doesn't help you. Don't do stuff on wifi point's you haven't personally hardened with static arp and wpa2 as well as mac filtering.
What many have not mentioned, is that Firesheep also works with wired Ethernet. If one can monitor packets going through an Ethernet network, like in a hotel. Firesheep will also work for grabbing session cookies from hotel Ethernet networks. Basically hotel Ethernet is not any more secure than open or WEP secured WiFi.
There are different kinds of cookies... Firesheep target session cookies which are only active when u are communicating with a website such as facebook. As soon ad you log out the session is ended .. Firesheep can no longer use those cookies cos u logged out
Oh, but can it sniff cookies from networks with AES or WPA2 ??? :P
XD
Answer: No it cant-
and in the odd case they're already able to get onto a network like that - other users STILL are envrypted by the network
SO if you set up your router, give it a password, then tell yourself and me the password and i go on FB, you wont be getting it despite being able to "access the network"
@tippership I believe you misunderstand WPA2-Personal encryption and have confused it with WPA2-Enterprise. Only Enterprise encrypts each user on the wireless router individually. Therefore, if I have the key to get onto the WPA2 network I also have ALL traffic upon the network unencrypted.
Now, if they are using TLS that is not going to be unencrypted of course, but Firesheep works fine over WPA2 encrypted wireless. If one doesn't have the key, well that's one more step but not that difficult
@samyalley where can we find the firesheep addon? O_o I'm from Macedonia, a bit far from every other place on Earth so... no worries about me abusing it xD
Hi, i was able to install the firesheep addon into the firefox, but when i click on the start capturing button, an error is throw, which reads ---> \\Device\\NPF_GenericDailupAdapter: Error opening adapter: The system cannot find te device specified.(20)
Hi, i was able to install the firesheep addon into the firefox, but when i click on the start capturing button, an error is throw, which reads ---> \\Device\\NPF_GenericDailupAdapter: Error opening adapter: The system cannot find te device specified.(20)
So does this applies to school computers in the com labs? If so, thats kind of scary
Polokpva 1 month ago
What Firefox version did you use in this video?
ohchoue 2 months ago
Comment removed
ohchoue 2 months ago
noooo don't steal my cookies there my choc cookies
spyshocker 10 months ago
thank you!
bahaivideos 1 year ago
11 minutes just to show us 2 plugins that prevent a hijack...
latchomacho 1 year ago
if you go into an incognito window in google chrome or private browsing are you protected as well????
NervsofSteel 1 year ago
fucking douches at university used this today.
gotessakin 1 year ago
Here is the easy-to-use solution against Firesheep: secdrive.com
secdrive 1 year ago
@secdrive Thanks for sharing this, I'm really grateful. The original idea of SecDrive was my father's. So I'm happy to see that people enjoy it.
bogarvirag2312 6 months ago
Their taking my cookies :(
ZezimaXL 1 year ago
Get add-on called Fire Shepard, this blocks FireSheep completely.
13NoHeaRt14 1 year ago 2
get an adon called black sheep, this program detects if someone is using firesheep on the wireless network
Knk082 1 year ago
One thing I noticed you can do is logout when you are finished. If you log out the session ends and they cant get into your Facebook. But alot of people dont logout they just close the browser or even put the computer to sleep. Even if you move to a new network and they havent logged out, you can still get to their Facebook page.
bergi85 1 year ago
So will disabling cookies stop this from happening ?
SilentKiller01 1 year ago
@SilentKiller01 u cant log in without cookies
psp785 1 year ago
@SilentKiller01 Yes but it will also make you unable to login, so it's a pretty crappy solution.
SnoweyMan111 1 year ago
thank you for the clear explanation Samuel. well done video :-)
MegaZephie 1 year ago
@buffelting Thanks for this very clear explanation of a problem I didn't even know I had. Still not 100% sure what I should do though. does this mean that people can hack into basically all and any computers if the internet conncetions aren't secured by a personal password?
2liveinspired 1 year ago
skip to 7:10 <_<
00011theman 1 year ago
All you have to do is fire up ssltrip to get around ssl, so that doesn't help you. Don't do stuff on wifi point's you haven't personally hardened with static arp and wpa2 as well as mac filtering.
Kamek437 1 year ago
Comment removed
Kamek437 1 year ago
What many have not mentioned, is that Firesheep also works with wired Ethernet. If one can monitor packets going through an Ethernet network, like in a hotel. Firesheep will also work for grabbing session cookies from hotel Ethernet networks. Basically hotel Ethernet is not any more secure than open or WEP secured WiFi.
mukatuna 1 year ago
Is there an Add-on for google chrome similar to force tls? Firefox caused my system to crash several times.
firelordkataang 1 year ago
Thanks for sharing your knowledge Sam, it was a very clear explanation
yxamyxam 1 year ago
@yxamyxam you are very welcome.
samyalley 1 year ago
Are you from Wisconsin?
eatingacookie 1 year ago
There are different kinds of cookies... Firesheep target session cookies which are only active when u are communicating with a website such as facebook. As soon ad you log out the session is ended .. Firesheep can no longer use those cookies cos u logged out
samyalley 1 year ago
wat about protecting ur mobile browsing on a smart phone running android is there a way besides not using wifi lol?
commalTl 1 year ago
Comment removed
commalTl 1 year ago
can you session still be hijacked even if you log out?
esepablo19 1 year ago
@esepablo19 no because you kill the session thats what logging out does
samyalley 1 year ago
does firesheep also work on private wifi
mainiac67 1 year ago 2
STEAL YOU COOKIES.
Alixandah 1 year ago 2
I don't even see an extension called Firesheep. Just a theme.
SBPStudio 1 year ago
@SBPStudio Firefox doesn't publish this extension in its catalogs. You need to go download and install
samyalley 1 year ago
if i use google chrome can someone still see what im doing??? or is it only firefox2firefox??
importspeed9161981 1 year ago
@importspeed9161981 it doesn't matter what you use, they can still see your web traffic when you use an open network.
mooserman911 1 year ago
@mooserman911
Oh, but can it sniff cookies from networks with AES or WPA2 ??? :P
XD
Answer: No it cant-
and in the odd case they're already able to get onto a network like that - other users STILL are envrypted by the network
SO if you set up your router, give it a password, then tell yourself and me the password and i go on FB, you wont be getting it despite being able to "access the network"
tippership 1 year ago
@tippership I believe you misunderstand WPA2-Personal encryption and have confused it with WPA2-Enterprise. Only Enterprise encrypts each user on the wireless router individually. Therefore, if I have the key to get onto the WPA2 network I also have ALL traffic upon the network unencrypted.
Now, if they are using TLS that is not going to be unencrypted of course, but Firesheep works fine over WPA2 encrypted wireless. If one doesn't have the key, well that's one more step but not that difficult
jamestparshall 1 year ago
@tippership Yep and that is what people should use at thier house.
mooserman911 1 year ago
@importspeed9161981 every browser uses session cookies.
samyalley 1 year ago
This has been flagged as spam show
When I press "Start Capturing" and then access my facebook and hotmail accounts nothing is shown in the sidebar , help plzzz
AdelBibi93 1 year ago
Comment removed
AdelBibi93 1 year ago
no one is stealing my cookies or i will cry :)
willsgotbeer 1 year ago
@samyalley where can we find the firesheep addon? O_o I'm from Macedonia, a bit far from every other place on Earth so... no worries about me abusing it xD
gomadzevik 1 year ago
other than than GREAT VIDEO
gomadzevik 1 year ago
@gomadzevik here.. nosecare.110mb.com/download/firesheep-0.1-1.xpi
No virus!
Nicolai577 1 year ago
Why your OS is at 2009 ? Did you make this video year ago? =P
Dexu666 1 year ago
@Dexu666 i am a fortune teller, i knew about firesheep even before it was made . Just kidding my clock was just jacked up.
samyalley 1 year ago
Hi, i was able to install the firesheep addon into the firefox, but when i click on the start capturing button, an error is throw, which reads ---> \\Device\\NPF_GenericDailupAdapter: Error opening adapter: The system cannot find te device specified.(20)
How do i fix this issue???? plz help
niravconnects 1 year ago
Hi, i was able to install the firesheep addon into the firefox, but when i click on the start capturing button, an error is throw, which reads ---> \\Device\\NPF_GenericDailupAdapter: Error opening adapter: The system cannot find te device specified.(20)
How do i fix this issue???? plz help
niravconnects 1 year ago
Great video, showing everything in an easy way.
Sjookvist 1 year ago
where can i download this '?
negerboy1337 1 year ago