Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Forum Rules Members List Calendar Search Today's Posts Advertise Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 04-22-2011, 12:15 AM
Shadow
Guest
 
Posts: n/a
Default Question about firesheep

Curious. What does it work on, the data (cookies) the browser
sends to the server or the data sent from the server to the browser ?
TIA

Reply With Quote
  #2 (permalink)  
Old 04-22-2011, 12:50 AM
David H. Lipman
Guest
 
Posts: n/a
Default Re: Question about firesheep

From: "Shadow" <Sh@dow.br>

> Curious. What does it work on, the data (cookies) the browser
> sends to the server or the data sent from the server to the browser ?
> TIA


http://en.wikipedia.org/wiki/Firesheep


--
Dave
Multi-AV Scanning Tool - http://www.pctipp.ch/downloads/dl/35905.asp



Reply With Quote
  #3 (permalink)  
Old 04-22-2011, 04:30 PM
Shadow
Guest
 
Posts: n/a
Default Re: Question about firesheep

On Thu, 21 Apr 2011 20:50:07 -0400, "David H. Lipman"
<DLipman~nospam~@Verizon.Net> wrote:

>From: "Shadow" <Sh@dow.br>
>
>> Curious. What does it work on, the data (cookies) the browser
>> sends to the server or the data sent from the server to the browser ?
>> TIA

>
>http://en.wikipedia.org/wiki/Firesheep

Thanks, so as I see it Firesheep just takes the cookies sent
by the webpage, and does not perform session cookie hijack ?

http://en.wikipedia.org/wiki/Firesheep
"The extension uses a packet sniffer to intercept unencrypted
cookies from certain websites"
---> FROM the website, so no point in a directional antenna
on the victims PC, as the WISP server will be radiating these cookies
in a (probably) 180 degree direction.

http://en.wikipedia.org/wiki/Session_hijacking
"Session sidejacking, where the attacker uses packet sniffing
to read network traffic between two parties to steal the session
cookie. Many web sites use SSL encryption for login pages to prevent
attackers from seeing the password, but do not use encryption for the
rest of the site once authenticated. This allows attackers that can
read the network traffic to intercept all the data that is submitted
to the server or web pages viewed by the client. Since this data
includes the session cookie, it allows him to impersonate the victim,
even if the password itself is not compromised. Unsecured Wi-Fi
hotspots are particularly vulnerable, as anyone sharing the network
will generally be able to read most of the web traffic between other
nodes and the access point."
---> Our WISP here is secured by MAC address (or in other
words, is unsecured). In this case, a very directional antenna would
diminish the area an interceptor could capture these cookies. But from
what I understood, firesheep uses only cookies from the server, so
these antennas would be of no use.
[]'s
PS every other "hacker" here in town has firesheep on his
laptop. Most local social websites are unencrypted. ( I live in
Brazil).



Reply With Quote
  #4 (permalink)  
Old 04-22-2011, 09:22 PM
David H. Lipman
Guest
 
Posts: n/a
Default Re: Question about firesheep

From: "Shadow" <Sh@dow.br>

> On Thu, 21 Apr 2011 20:50:07 -0400, "David H. Lipman"
> <DLipman~nospam~@Verizon.Net> wrote:
>
>> From: "Shadow" <Sh@dow.br>
>>
>>> Curious. What does it work on, the data (cookies) the browser
>>> sends to the server or the data sent from the server to the browser ?
>>> TIA

>>
>> http://en.wikipedia.org/wiki/Firesheep

> Thanks, so as I see it Firesheep just takes the cookies sent
> by the webpage, and does not perform session cookie hijack ?
>
> http://en.wikipedia.org/wiki/Firesheep
> "The extension uses a packet sniffer to intercept unencrypted
> cookies from certain websites"
> ---> FROM the website, so no point in a directional antenna
> on the victims PC, as the WISP server will be radiating these cookies
> in a (probably) 180 degree direction.
>
> http://en.wikipedia.org/wiki/Session_hijacking
> "Session sidejacking, where the attacker uses packet sniffing
> to read network traffic between two parties to steal the session
> cookie. Many web sites use SSL encryption for login pages to prevent
> attackers from seeing the password, but do not use encryption for the
> rest of the site once authenticated. This allows attackers that can
> read the network traffic to intercept all the data that is submitted
> to the server or web pages viewed by the client. Since this data
> includes the session cookie, it allows him to impersonate the victim,
> even if the password itself is not compromised. Unsecured Wi-Fi
> hotspots are particularly vulnerable, as anyone sharing the network
> will generally be able to read most of the web traffic between other
> nodes and the access point."
> ---> Our WISP here is secured by MAC address (or in other
> words, is unsecured). In this case, a very directional antenna would
> diminish the area an interceptor could capture these cookies. But from
> what I understood, firesheep uses only cookies from the server, so
> these antennas would be of no use.
> []'s
> PS every other "hacker" here in town has firesheep on his
> laptop. Most local social websites are unencrypted. ( I live in
> Brazil).
>


I haven't used FireSheep, just read a few articles on it but that WiKi seemed to rool it
all into a good summation.


--
Dave
Multi-AV Scanning Tool - http://www.pctipp.ch/downloads/dl/35905.asp



Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Question about long range wireless xactionbobx Wireless Networking Discussion 0 08-17-2009 07:43 PM
Memory Question.. Uncle Vinnie alt.comp.hardware 2 12-16-2006 01:37 PM
Router Security Question... spooker Network Troubleshooting 3 10-11-2006 12:29 PM
Memory Question Jack Bruss alt.comp.hardware 3 10-09-2006 10:50 PM
Dell case cooling fan for XPS B-series ... rant and question The poster formerly known as Colleyville Alan alt.comp.hardware 16 10-07-2006 08:52 PM


All times are GMT. The time now is 10:59 AM.



Powered by vBulletin® Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 PL2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45