Firefox add-on makes hacking your friend's Facebook a breeze

rudeguy

Lifer
Dec 27, 2001
47,351
14
61
I support this only if all you do is change their profile pics to that of sheep.
 

rudeguy

Lifer
Dec 27, 2001
47,351
14
61
Wow, I could have some fun with this ;)

one of my buddies is a complete idiot and leaves his phone laying around at his job. At least once a week his status is something along the lines of "I like the cock".

While I don't doubt that he does like the cock, I don't think he'd advertise it on purpose.
 

TheVrolok

Lifer
Dec 11, 2000
24,254
4,092
136
This would work on open public networks? If so, they is going to own A LOT of people. :p Personally, I never type in any sort of password on a public network. :p
 

KingGheedora

Diamond Member
Jun 24, 2006
3,248
1
81
Insane. Are we in danger if we use our email accounts, etc, at work, and in cafes then ? I guess gmail is safe because it's ssl.
 
Last edited:

Leros

Lifer
Jul 11, 2004
21,867
7
81
one of my buddies is a complete idiot and leaves his phone laying around at his job. At least once a week his status is something along the lines of "I like the cock".

While I don't doubt that he does like the cock, I don't think he'd advertise it on purpose.

I bet I know how you can find out :eek:
 

thescreensavers

Diamond Member
Aug 3, 2005
9,916
2
81
seems you need to plug into Ethernet for it to work, at least for me.

and oh the fire sheep side bar never popped up for me.

Edit: doh View>Sidebar>Firesheep
 
Last edited:

BillGates

Diamond Member
Nov 30, 2001
7,388
2
81
Figured it out - it was flaky to install on my PC but went fine on my laptop. Didn't seem to pick up much though. Someone else stole my Internets, I guess.
 

Crusty

Lifer
Sep 30, 2001
12,684
2
81
How does this work? And would it work on a non-wifi network?

If you are directly connected to a HUB then yes. This really has nothing to do with facebook, just the fact that they don't use SSL by default. Session hijacks are nothing new.

Any website that uses a simple cookie for authorization that does not use ssl is susceptible to this attack.

You might send your password over an encrypted SSL connection, but as long as your authorization cookie is sent in plain-text over a network that can be sniffed easily you're fucked.

If a website is really smart and resourceful they will encrypt every transaction to their servers; non SSL HTTP is insecure by nature and should not be trusted.
 

zinfamous

No Lifer
Jul 12, 2006
111,863
31,354
146
one of my buddies is a complete idiot and leaves his phone laying around at his job. At least once a week his status is something along the lines of "I like the cock".

While I don't doubt that he does like the cock, I don't think he'd advertise it on purpose.

well....good for his co-workers for keeping him honest.