Nutopia Forum Index
Bay Area Forum for Asians
Log in to check your private messages
Advanced Search traditional simplified
star FAQ Search Memberlist Usergroups Register Log in star
青鳥   聖域回音 (全)   回音(全)   洛克人小說   寵物貼圖   Bay Area Happenings   素菜食譜   Free Medical Info   Random things   每日一女   牆紙桌布下載   流行音樂  
家常食譜   簡易微波爐食譜   小電影   免費軟硬電腦教學   IBM Content Manager  
Username:    Password:    Log me on automatically each visit   
                                                      
Nutopia Forum Index
Nutopia Forum Index 免費軟硬電腦教學 Firesheep vs Blacksheep. Stealing facebook, amazon passwords
View previous topic :: View next topic
Post new topic     Reply to topic Page 1 of 1
Firesheep vs Blacksheep. Stealing facebook, amazon passwords Mon Nov 22, 2010 2:24 am
Author Message
blah
國際巨星
國際巨星

Joined: 24 Jul 2006
Posts: 939
Reply with quote

Post subject: Firesheep vs Blacksheep. Stealing facebook, amazon passwords

Bookmark and Share
URL
Embed
Link
BBCode


Firesheep vs Blacksheep. Stealing facebook, amazon passwords




You've probably all heard of Firesheep by now, a Firefox add-on which lets anyone hijack a user's session to various popular web applications when they're using an open wireless network. While sniffing/stealing session credentials is nothing new, Firesheep exposes this capability to the masses by automating the process so that absolutely no technical know-how is required. Unfortunately, it is actually quite difficult to defend against Firesheep because most sites only permit SSL connections during the initial login, not while surfing other pages. As such, while your username and password are encrypted, your session ID is available to all other machines on the same network.

In a previous post, Mike showed how to detect the use of Firesheep on a local network by using Wireshark and Scapy. Well, today, we're releasing a new Firefox add-on which makes the detection of FireSheep available to everyone and we're calling it BlackSheep!

BlackSheep installed

BlackSheep is a Firefox add-on which warns users if someone is using Firesheep on their network. It also indicates the IP address of the machine that is spying on you.

BlackSheep warns that someone is using FireSheep

Install BlackSheep add-on for Firefox 3.x

How BlackSheep works

To understand how BlackSheep works, we first need to understand the details of FireSheep. FireSheep listens to the HTTP traffic on port 80. When it identifies a transaction to a known site (Facebook, Google, Yahoo!, etc.), it looks for specific cookie values which are then used to identify a specific user. This phase of the attack cannot be detected as it is done passively.

When FireSheep identifies a user session, it then makes a request to the same site using the user's cookie values in order to retrieve user information such as their name, picture, etc. This active network activity is however visible to others on the local network.

BlackSheep detects the active connection made by Firesheep. It does this by making HTTP requests to random sites handled by FireSheep every 5 minutes (configurable) with fake values. BlackSheep then listens to all HTTP requests on the network to detect if somebody else is using the same fake values.

Use Firesheep to combat.... Firesheep!

BlackSheep is based on the FireSheep source code. It reuses the same network listening back-end and the list of sites and corresponding cookies, etc. This ensures that the fake traffic generated by BlackSheep is what Firesheep is expecting.

BlackSheep in action

First, install BlackSheep here. If you already have FireSheep installed, make sure it is disabled, otherwise BlackSheep will detect that you are using FireSheep.

Then select the correct network interface in the options menu (same as FireSheep).

BlackSheep preferences menu

By default, BlackSheep generates fake traffic every 5 minutes. You can change this value in the option settings.

If Firesheep is detected, you will see the following warning in your current browser tab.

BlackSheep notification


Finally, here is a video of BlackSheep in action.
View user's profile Send private message
Back to top
Firesheep vs Blacksheep. Stealing facebook, amazon passwords Mon Nov 22, 2010 2:24 am
Author Message
Special Offers!
國際巨星
國際巨星

Joined: 24 Jul 2006
Posts: 939
Reply with quote

Post subject:


Medical Info Blog








Firesheep vs Blacksheep. Stealing facebook, amazon passwords





Firesheep vs Blacksheep. Stealing facebook, amazon passwords

同學的超美腿母親 ?版咕寮?棣ㄧ?? ? http://stv.166dvd.com/ ?????借?茶??? 春暖花开论坛公告区 
美幼专区 ??韬??уゴ ?虫??? 717hh.com 陈小珍 qvod 纪念若妻左山爱 
淫乱的王村 rio 柚木天娜 bleeding heart Funny Girl Wallpaper 最美的OL-松宫アンナ 
??BeppinSchool?? 秋吉智子快播 欧美无码500m [亚洲/无码]~无限9月新作~超可爱娃娃脸白晰皮肤 Egals Vol.18[699... oumeiyinnv 
福下惠美 种子 av 佐藤江梨花 林若亞 由爱可奈无码种子 花井美纱 
sexinsex.nex 美臀快播 春暖花开性吧有你 亚洲无码 美女 性感 内射 http://www.soomm.com/hot/ 
柚木彩华 潘晓婷luozhao 白虎美女12p www.jijitu. 王雅娟 ed2k torrent 下载 
李玟#pn21 ?ㄩ?﹁???ㄨ8 滝ありさ sex8 二宫亚季 生屄 
?借?插ぉ棣???????绱?浜 ????????(kanako) 东热 身材超劲爆的白嫩吸人魅丽妹妹 少妇狩猎第一部——贞妇程媛 性吧有你 春暖花开 性感睡衣 
????? 寰?甯? 刘可颍 A4U 梅露露比思 林志玲 yazhouxingai 
View user's profile Send private message
Back to top
Post new topic     Reply to topic Page 1 of 1
Display posts from previous:
Back to top
Related Links:

Firesheep vs Blacksheep. Stealing facebook, amazon passwords Firesheep vs Blacksheep. Stealing facebook, amazon passwords Firesheep vs Blacksheep. Stealing facebook, amazon passwords Firesheep vs Blacksheep. Stealing facebook, amazon passwords Firesheep vs Blacksheep. Stealing facebook, amazon passwords Firesheep vs Blacksheep. Stealing facebook, amazon passwords Firesheep vs Blacksheep. Stealing facebook, amazon passwords

All times are GMT + 8 Hours