16 ms·
Firesheep: Easy HTTP session hijacking from within Firefox
- deleted 16y ago[deleted]
- chaosmachine 16y ago"Double-click on someone, and you're instantly logged in as them." Ouch. I think it's time to set up that VPN I've been putting off...
- GVRV 16y agoAm I the only one who thinks this is spoon feeding the script kiddies to cause mayhem?
- deleted 16y ago[deleted]
- cdine 16y agoWell, hopefully it will then convince companies to properly secure their websites and actually protect users.
- GVRV 16y agoAgreed, but I still think giving someone else full control is a bit too much. It's not the user's fault (most don't even know this is happening) and they're likely to be the victims here.
- EricButler 16y agoThe script kiddies already have their scripts and already do this. Firesheep will hopefully allow users to see the problem in a way they can clearly understand.
- pageman 16y agobtw, did you use showoff for http://codebutler.github.com/firesheep/tc12/#1 http://codebutler.github.com/firesheep/tc12/#1
- cdine 16y agoThis vulnerability (it hurts to even call it such at this point) has been around for years, and the attack has always been easy for a determined attacker to carry out. How else are we going to convince people to secure their sites and protect their users? People have been presenting on this issue for years (Ferret & Hamster, Blackhat 2007) and companies haven't responded/cared. It's possible to solve this problem (Gmail is all HTTPS, and done correctly, Amazon has a tiered authentication system that properly uses SSL for important things, Wordpress does SSL right for accessing their admin interface) - companies need to step up and address the issue.
- GVRV 16y agoDefinitely, I guess as a uni student, I'm worried about the majority of non-technical students who are going to have their sessions hacked and have no clue what hit them and cannot setup proxies/tunnels. I'm not saying this isn't the site's fault. They definitely need a wake-up call.
- mfukar 16y agoThe problem goes beyond client-website interaction. Improper wifi configuration also plays a big part in what Firesheep can achieve. ;)
- mike-cardwell 16y agoThis was already happening on a massive scale before this new app was released... I honestly don't think it will increase the number of attacks by all that much. It's brilliant as a tool for spreading the word though.
- silvermoonstar3 16y agoIt was happening on a massive scale, but now a huge amount of really lazy people who didn't bother to do this before are. It had 3,000 downloads after 2 hours of release. The thing is, most universities have protection set up. It seems Cisco NAC is actually good for something. I never thought I'd say that. The extension certainly doesn't work on my campus.
- mfukar 16y agoThis is essentially the same argument that comes up with full disclosure. Yes, it's not pretty. Yes, it causes a lot of collateral damage. But it also makes the big players patch things up faster, while letting the knowledge out to the public, which of course consists of not only the script kiddies, but also the unsuspecting legitimate users.
- mike-cardwell 16y agoEven the dumbest script kiddies have been doing this for years anyway. There are plenty of existing tools. This one just lowers the bar so your mum can perform the attack too. It almost makes me angry that websites like Facebook and Twitter don't force all traffic over https. They've got the money and the expertise. They just don't care if your account gets sniffed and taken over at a web cafe.
- uxp 16y agoExactly. I'm not a blackhat and my only "hacking" consists of forcing myself into my own systems which I've stupidly locked myself out of, yet I've managed to do much that this plugin can do. The most un-ethical thing I have done was to take one of the OLPC XO laptops and convert it into a MITM machine, rebroadcasting the SSID it connects to while routing and logging all traffic anyone who connects to it generates. It took a weekend to setup using pre-existing tools and scripts and can be deployed anywhere I want within 2 minutes and run for up to 6 hours hidden in the bottom of my backpack. It was a fun experiment, and surely made me more aware of just how vulnerable I was outside of my home network. Another point of interest, this weekend I hacked on a Minecraft bot for the Alpha version. In order to understand and dissect the connection protocol I needed to recreate, I used wireshark to dump and parse how the client authenticates and connects to the server. Even that transmits your username and password in plaintext.
- a_m_kelly 16y agore: the OLPC, what were you running on it? I have one in my closet and I've been meaning to put something that isn't the stock software on there for a long time.
- deleted 16y ago[deleted]
- ianhawes 16y agoThis looks really cool. I can't wait to try this out. Very nice work, Eric.
- EricButler 16y agoThanks! If you or anyone has any problems, email me (eric@codebutler.com) with the details.
- gilaniali 16y agoOn Mac OS X, it gives an error saying: Run --fix-permissions first. Run with which command? and how?
- xorglorb 16y agoI found the binary "firesheep-backend" in: ~/Library/Application Support/Firefox/Profiles/<profile>.default/extensions/firesheep@codebutler.com/platform/Darwin_x86-gcc3 I ran both: ./firesheep-backend --fix-permissions and sudo ./firesheep-backend --fix-permissions and it still asks me to run it with "--fix-permissions". I guess it's time to go digging around in the source to try and find out what it wants me to do. EDIT: After a bit of digging, I found out that running it with --fix-permissions really just chowns the binary to root then setuid's it. I don't see anything wrong with it on the surface, but I'll keep digging.
- leftnode 16y agoI thought the title of this submission was slightly misleading. This is not a security vulnerability from within Firefox, it's a Firefox plugin to reveal security vulnerabilities in a wide range of websites.
- cdine 16y agoSorry if it was misleading somehow, this is definitely not a vulnerability in Firefox. It's a Firefox extension that makes it easy to execute HTTP session hijacking attacks.
- wwortiz 16y agoTo be fair that is exactly what I got out of the title and not that it was using Firefox vulnerabilities.
- StavrosK 16y agoFor what it's worth, I got that it was an extension or other Firefox tool. Your interpretation didn't occur to me.
- gasull 16y agoI couldn't install it on FF 3.6.9 on Windows XP.
- jawngee 16y agoYou need WinPCap installed. Just FYI.
- EricButler 16y agoWhat was the error?
- gasull 16y ago"Firesheep 0.1 could not be installed because it is not compatible with Firefox 3.6.9." And yes, WinPcap is installed. I don't think it should matter, but I'm running Windows XP on a VirtualBox.
- EricButler 16y agoOh, you just need to update to the latest version of Firefox (3.6.11). Your version is out of date and not secure. http://www.mozilla.org/security/known-vulnerabilities/firefox36.html http://www.mozilla.org/security/known-vulnerabilities/firefo...
- gasull 16y agoThanks. It works now with FF 3.6.11. Your extension is amazing.
- linhares 16y agoWhat should happen if you use iPhone tethering? Could it top into the vast people on that network? (I have absolutely no idea). If this is the case, the internet will have a panic attack in 2 days max.
- daten 16y ago
- AlexRodriguez 16y agoWorks for me.
- atomical 16y agoIs there another application besides the FF extension to dump the packets and process them? How does this work? EDIT: Sorry, I asking specifically how this FF extension works.
- EricButler 16y agoWireshark is a very popular open-source tool. http://www.wireshark.org/ http://www.wireshark.org/
- audidude 16y agolibpcap http://github.com/codebutler/firesheep/blob/master/backend/src/http_sniffer.cpp http://github.com/codebutler/firesheep/blob/master/backend/s...
- Groxx 16y agoNice. A solid demonstration to show next time your webmaster doesn't want to set up SSL everywhere. That said, the current cartel-like setup of certificate authorities (protection money and everything!) makes SSL annoying and expensive if you want the browser to not have a fit. Especially for small-scale projects. But there's really no excuse for larger sites.
- StavrosK 16y agoYou can get SSL certificates for free for one domain, and they work with all browsers (except Opera, IIRC). Also, you can use Perspectives for Firefox, which I think is much better than the current system.
- ryan-allen 16y agoI've had a bit of a look on Google, but I'm not 100% sure which provider you mean? Where can you get free SSL certificates that don't upset browsers?
- StavrosK 16y agoAh, I can't remember the name now... Rapidssl? That's probably it. Check historio.us, the ssl cert there is a free one (which is, sadly, why subdomains don't validate). EDIT: I searched and it's actually http://cert.startcom.org/ http://cert.startcom.org/.
- qeorge 16y agoCheck historio.us, the ssl cert there is a free one (which is, sadly, why subdomains don't validate). AFAIK this is common to all certs (free or otherwise). You need a separate one for each subdomain (including www).
- StavrosK 16y agoNo, there are also wildcard certificates that match all subdomains, but are rather more expensive.
- marcuswestin 16y agoThe sidebar is not showing up for me after installing and restarting. Firefox 3.6.11 OS X 10.6 firesheep-0.1-1.xpi
- sandipagr 16y agoview -> sidebar -> firesheep
- marcuswestin 16y agoThanks!
- zemaj 16y agoSame setup. Sidebar shows for me after selecting it from the View -> Sidebar menu, however it pops up with a message that says "Run --fix-permissions first." Not sure where I'm supposed to run this flag.
- gilaniali 16y agoSame error for me. No idea where to run though.
- staktrace 16y agoDitto
- cheungpat 16y agoThere is so many hoops I have to jump to make this work in OS X. $ mv firesheep-backend firesheep-backend.binary $ cat > firesheep-backend #!/bin/sh sudo /path/to/firesheep-backend.binary $@ ^D $ sudo chmod +x firesheep-backend Then restart Firefox and start capture. You need to run sudo once every certain period.
- mrgordon 16y agoIt worked instantly for me on OS X. I installed, restarted the browser, and it opened the side panel.
- meelash 16y agoWow, good work. And pretty scary- imagine what one could do with this on any college campus.
- colonelxc 16y agoA guy I know used to do this in airports (just for fun, didn't do anything malicious) by grabbing webmail logins. Running wireshark with some simple filters and watch the cookies roll in.
- drivebyacct2 16y agoInteresting. I was going to do something similar but keep it limited to Facebook chat. That way you could eavesdrop on conversations in the room and impersonate people, etc. This is actually probably easy to program and more versatile at that.
- dennisgorelik 16y agoOn the other hand, stealing somebody's real life identity is not that hard either. But it does not happen too often, in part because it's illegal. Stealing somebody's cookie on the Internet is a crime just as is stealing somebody's driver's license. Although technical solution to this security hole is desirable, it's not the only solution available.
- muloka 16y agoThanks to the EFF and the Tor Project we need not worry as much thanks to their HTTPS Everywhere project, a plugin for Firefox: http://www.eff.org/https-everywhere/ http://www.eff.org/https-everywhere/ Any questions: http://www.eff.org/https-everywhere/faq http://www.eff.org/https-everywhere/faq
- EricButler 16y agoLogging into insecure sites over Tor is probably not a good idea. It's always good to assume that people running exit nodes are not the most trustworthy. HTTPS Everywhere is good but only works on known sites (and known domains for those sites).
- cdine 16y agoHTTPS Everywhere only works on a select few sites. You're up a creek for anything it doesn't cover. And Tor, there's lots of cases where operators did bad things. Don't trust it for sensitive information. http://blog.ironkey.com/?p=201 http://blog.ironkey.com/?p=201
- flawawa2 16y agoI highly dislike the title of it. It is not HTTPS everywhere, it is "HTTPS on sites we know it is possible on".
- muloka 16y agoI realize I should of put more emphasis on "as much" as yes this only works on only a few popular websites as defined by the plugin. Thanks to reading Techcrunch this morning, I read about this plugin which allows you to manually define which sites you want to force an HTTPS connection on: Force-TLS https://addons.mozilla.org/en-US/firefox/addon/12714/ https://addons.mozilla.org/en-US/firefox/addon/12714/ Mind you for any of these extensions to work the website you're visiting needs to be already accessible via ssl. If the site does not have encryption, these plugins can't force the sites to automagically start using the encryption it never had.
- gregwebs 16y agoWhat can an end user do to minimize this? This exploit is for insecure Wifi networks- so only using encrypted Wi-fi or Ethernet would seem to remove this attack vector. Is there a real risk that someone (besides the government) can see your cookie?
- bluesmoon 16y agovpn/ssh tunnel/encrypted wifi
- chrisbroadfoot 16y agoEncrypted WiFi won't stop clients on the network from sniffing your packets. It will, however, stop unauthorised computers from sniffing any network data.
- gojomo 16y agoI would have expected each wireless client, on an encrypted network, to negotiate its own key with the access point -- so you'd only see neighbors' traffic if the access point chose to rebroadcast it to you. Are you sure that neither WEP nor WPA/WPA2 do it this way?
- chrisbroadfoot 16y agoThe encryption is between your client and the AP. Uaually everything after that is standard IP.
- gojomo 16y agoThat's what I thought -- enough to protect against fellow wireless sharers, but not the hosting establishment or path through their ISP to a website.
- chrisbroadfoot 16y ago
- ElbertF 16y agoWhy don't Facebook and other major sites check the user agent and IP address of client as well, instead of just relying on a cookie? That would solve this problem in 99% of the cases, right?
- sdurkin 16y agoIf you're on the same wireless network as someone, you have the same external IP address.
- spicyj 16y agoAnd of course, if you can see the traffic, you can spoof the same User-Agent as well.
- ElbertF 16y agoI realize that but at least my neighbors won't be able to hijack my session from home. Logging in over a public network always seems risky.
- chrisbroadfoot 16y agoAre your neighbours on your private network? If not, you don't need to worry about them capturing your network data, because they're not on the same network.
- oops 16y agoPlus, your source IP can change from request to request when your ISP transparently pushes you through one of many proxy servers. AOL does (or did) this, as do some large European ISPs whose names escape me.
- modeless 16y agoYet another reason NAT sucks...
- uptown 16y agoThe explanation I've always heard for not using HTTPS 100% of the time is that it puts an substantial load on the server, and for many sites it's overkill. Setting aside the subjective topic of "overkill" ... how much more CPU-intensive is it to serve pages over HTTPS compared to HTTP?
- wizard_2 16y agoThe cpu load can be mitigated with frontend https accelerators or proxies (think nginx as a load balancer doing the https). The real problem is the first connection. Browsers don't fall back to https, if nothing answers on http they'll give an error. If the first connection is over http then a man in the middle attack can succeed.
- kijinbear 16y ago> If the first connection is over http then a man in the middle attack can succeed. There are ways to work around this, if the non-https site immediately redirects to the https version and a "secure cookie" (https-only) is exchanged afterwards.
- tswicegood 16y agoSomeone correct me if I'm wrong, but that's the exact vector point for a man-in-the-middle attack. First request over HTTP gets hijacked, redirected to a "secure" server, then you (the user) see the lock and go to town, secure in the knowledge that you're communications with this server are protected because they're encrypted.
- kijinbear 16y agoIsn't that exactly why HTTPS sites are supposed to have expensive certificates issued by big companies? Otherwise the browser will display a big red warning message. If you ignore that warning, you deserve to be hacked. If the request gets redirected to a HTTPS proxy site that the attacker has set up, that's a different story. But again, you should be checking what's in your address bar. No security system can rescue you if you can't tell the difference between "mail.google.com" and "mail.google.haxxor.com". But for those of us who actually read what's in the address bar, HTTPS is pretty good security.
- deleted 16y ago[deleted]
- deleted 16y ago[deleted]
- carbon8 16y agoThis is kind of a big deal. Not a whole lot of people are aware of this vulnerability and among those who are it's likely only a small subset that knew how to exploit it until now. I suspect all of the coffee shops in the college town where I live will have people using this starting tomorrow. I've personally been working from cafes and tunneling everything through SSH for years, but in my experience almost no one else does this.
- petercooper 16y agoI've personally been working from cafes and tunneling everything through SSH for years To where? I suspect it's to a server, VPS, or similar, and the connection is unencrypted from there to its endpoint. This being the case, could someone with a server on the same subnet be running a browser remotely (or even just tcpdump) and doing a similar thing with your logins? (This is just some thinking out loud and I may be totally wrong - correct me ;-))
- jmreid 16y agoIf you control the remote network, it's a lot safer than having all your traffic unencrypted on the Starbucks Wifi.
- kijinbear 16y agoIt depends on how secure the remote network is. If it's just another coffee shop, you're screwed. If it's your own Linode in one of those well managed datacenters, it would be pretty difficult for anyone to snoop that traffic.
- azim 16y agoVirtually no modern wired networks use hubs anymore, they're for the most part switched. Unlike wireless networks where packets are broadcast freely in to the air, the switch checks the destination address and sends the packets only to the endpoint. There are some attacks like arp-spoofing and flooding which can defeat this, but they don't work well against modern enterprise-grade switches like you would find in a data center.
- amanuel 16y agoYou can slightly reduce the dangers stated here by logging out immediately after you are done doing whatever it is you are doing. This will make the captured session useless. The best solution is of course to get a VPN acct and use it when you are at free/open wifi spots. I use WiTopia (www.witopia.net)
- josto 16y agoOr just get a mac mini server that will run vpn 24/7
- kijinbear 16y agoBe careful when trying this out. You could be breaking a law or two...
- jorgem 16y agoAlso don't web-mail your friends to tell them about the new accounts you just broke into :) At least not on that open wireless connection.
- chrisbroadfoot 16y agoGood thing GMail has SSL enabled by default ;)
- cdine 16y agoYup, they're one of our examples of a "good" setup. However, Google leaks iGoogle and some other things (Latitude, address book, reader, ...)
- itsnotvalid 16y agoHowever they don't share the same session cookie for different service as far as I know (which they negotiate that through TLS protected link) Likewise they have also made several other services TLS only (e.g. calendar, docs)
- jmreid 16y agoMakes a strong case for everyone to start tunneling their traffic back to a trusted network. I've been trying out sshutttle <http://github.com/apenwarr/sshuttle> http://github.com/apenwarr/sshuttle>. It only tunnels TCP traffic, so you still have DNS and UDP traffic on the local network.
- chrisbroadfoot 16y agoHas anyone checked the source code to check that the passwords aren't sent to the author's website? :)
- cdine 16y agoIt's 100% open source! Please feel free to review it. http://github.com/codebutler/firesheep http://github.com/codebutler/firesheep It doesn't currently do anything with passwords, it's only pulling out cookies from HTTP Response headers. But it would be trivial to also get passwords in non-HTTPS requests for logins with the same method.
- chrisbroadfoot 16y agoIndeed. Sorry if I implied that you were doing evil things. People should also be aware of the security implications of installing various software on their system. :)
- staktrace 16y agoAgain, not assuming you're evil, but it's possible that the compiled binary (.xpi) was not created from the source posted on the github account :)
- phamilton 16y agoPasswords are not a part of this... It's the session cookie, which is an entirely different matter. It's unique to the login process, so one compromised account isn't able to lead to compromising other websites. It's also time sensitive (generally) and so that hijacked cookie will expire. If he were collecting all this information, he wouldn't be able to do much with it.
- chrisbroadfoot 16y agoJust because the user interface only exposes cookies, doesn't mean that passwords aren't captured and sent somewhere. It's very possible, given that the extension seemingly captures HTTP requests/responses. If passwords are sent or received in plaintext, then they can be captured.
- jayphelps 16y agoDoesn't work in 3.6.4, even if you override install it or change the minVersion (which is 3.6.10) Once I upgraded to 3.6.10 worked awesome.
- dacort 16y agoWow, I've been wanting to do this for a while to raise awareness. Great implementation by plugging it into Firefox - well done.
- flexterra 16y agoHere is a simple tutorial on how to set up an SSH Tunnel for Mac OS X http://bit.ly/cffjOY http://bit.ly/cffjOY This way all your communication is encrypted
- cdine 16y agoI love SSH tunnels, but in regards to this particular problem, it really just pushes the problem off to wherever you ssh tunnel terminates. Do you trust you server operator? ISP? This is addressed in our presentation, here (VPN's are essentially doing the same thing): http://codebutler.github.com/firesheep/tc12/#20 http://codebutler.github.com/firesheep/tc12/#20
- Dornkirk 16y agoThanks for the link! I'm going to be traveling for a while pretty soon and using a lot of internet cafes and other free wi-fi spots so I should probably get this set up - I'm worried someone will be able to grab my password while logging in to check mail.
- jdunck 16y agoTo be clear, that tutorial was made in 2007, so is a bit dated. Also, it shows how to set up FF to use the proxy, but the idea of a tunnel is not FF-specific, nor is this vulnerability. One big issue with SSH-tunnel as a solution is that anything not set up to use the proxy still works, it's just quietly vulnerable. Any suggestions on making TCP traffic which doesn't go through the proxy totally fail?
- mcmc 16y agoIt seems fine to just enable SSL everywhere. But indulge me for a second in thinking of alternate solutions. Instead of sending a cookie, send a piece of javascript code (as part of the SSL-cloaked login handshake) that generates a new cookie for each request, and consider each new cookie in this sequence a "one time use" token. You can turn off SSL for subsequent requests and just use one of these new cookies each time to verify identity because an attacker won't have your cookie generator. This javascript is really just an encryption key and algorithm, and if you implement it correctly, it should take quite some time for snoopers to reverse engineer the encryption key based on a sequence of one-time-use cookies. Logistically, I suppose you would run into some trouble setting a new cookie for each request depending on how the page is loaded. For instance, if the user pastes a url into a new tab manually, then this system wouldn't have a chance to set the new cookie first. However, I think you could architect a system that solves this. For instance, put the javascript token generator source in local storage. If a new page loads with an invalid key, that new page can just get the cookie generator code out of local storage and manually refresh the page's content by making a request with a valid token. This should be quick enough for most users not to notice, in the rare case that they circumvent the site's usual navigation. A downside is obviously that the content itself is still not safe, but at least the account would be. Any thoughts?
- Groxx 16y agoI think all cookies are sent with every request, so cookies can't be used to (securely) pass data to the next page. It'd work just fine on the login page, but every page after that would have to renegotiate to generate a new cookie, meaning you basically just created SSL everywhere. Local storage, however, could probably be used to do just such a thing, as it exists only locally. In which case you could just have the login page generate an RSA key pair, receive the server's public key in the response, and use that for any kind of secure communication on each page load. The server would have to remember sessions => encryption keys, but that's not too hard.
- swolchok 16y agoHaven't thought too hard about passive attacks, but you're not secure against an active MITM like airpwn (http://airpwn.sourceforge.net/Airpwn.html http://airpwn.sourceforge.net/Airpwn.html), because the MITM can inject JS into the unencrypted content that steals your JS security scheme's secrets. Effectively, an active MITM allows XSS on plain ol' HTTP sites.
- gaoshan 16y agoFor anyone who has SSH access to a server (but not VPN) and is wondering what to do when you need some security in a pinch, here is a quick fix... Open an ssh connection to a server you have access to using something like the following: ssh -ND 8887 -p 22 rufus@12.120.186.8 where 8887 is the port on your laptop that you will tunnel through, -p 22 is the port the ssh server is on (22 is the default but I use a different port so I am used to specifying this) and the rest is your username and the address of the server Set your network to point to the proxy. On a Mac that would be… ... Open Network Preferences… ... Click Advanced… ... Click Proxies… ... Check the SOCKS Proxy box then in the SOCKS Proxy Server field enter localhost and the port you used (8887) ... OK and Apply and you are done! Now you can surf safely.
- chrisbroadfoot 16y agoAnd, make sure you already have the key in your known_hosts, otherwise you could be subject to a MITM attack :)
- alanstorm 16y agoAlso, remember that some programs don't respect the system's proxy settings and instead use their own. Firefox is one of those, you can find its proxy settings in "Advanced -> Network -> Settings"
- mfukar 16y agoAfter Firefox 3.6.4, the default proxy selection policy is to use the system default, instead of no proxy.
- imurray 16y agoAlso Firefox doesn't put DNS through a socks proxy by default, which has some security implications and doesn't allow you to reach internal-only names. In about:config set: network.proxy.socks_remote_dns to True.
- subbu 16y agohttp://lifehacker.com/237227/geek-to-live--encrypt-your-web-browsing-session-with-an-ssh-socks-proxy http://lifehacker.com/237227/geek-to-live--encrypt-your-web-... That link has screenshots to help you configure Firefox to use the ssh proxy.
- deleted 16y ago[deleted]
- bluesmoon 16y agoWell, whatever... encrypt all you like, $5 will still crack your session: http://xkcd.com/538/ http://xkcd.com/538/
- bluesmoon 16y agowow, -1. HN readers sure left their senses of humour at home today. I shall call this experiment a success.
- AndyKelley 16y agoLinux installation needs work. README is empty, and the INSTALL says use ./configure which doesn't exist. ./autogen.sh complains about needing xulrunner-sdk path, which is isn't something normal for linux. Edit: Oops! Linux support is "on the way." I guess I assumed since linux is the easiest platform to get your driver to go into monitor mode.
- thought_alarm 16y agoDoes this kind of wi-fi sniffing work with WEP or WPA encrypted networks? What about 802.1x?
- pmorici 16y agoYes, assuming you know the password to connect to the network. Otherwise no.
- thought_alarm 16y agoAre you sure? It's not working on my WPA2 network.
- pmorici 16y agono, I'm not familiar with WPA2.
- InclinedPlane 16y agoThis is incorrect. Traffic on an access point using WPA2 + AES is not sniffable without significant cryptanalysis or use of exploits.
- oasisbob 16y agoMind providing more information on this? eg, what about WPA2+TKIP? I'm trying to wrap my head around how WPA2 could still provide protection with a shared key... I'm sure I'm not the only geek who feels like their knowledge of WiFi protocols goes stale every six months or so.
- InclinedPlane 16y agoTKIP is much more vulnerable. In theory it requires "work" to crack WPA2+TKIP but it's comparatively trivial with modern hardware. With WPA2+AES you basically open a public/private key encrypted connection to the router (similar to SSL) and exchange the PSK in order to authorize the client. This traffic isn't any more sniffable, in principle, than https traffic. However, depending on configuration it can be vulnerable to man in the middle attacks and such-like.
- charlesshonston 16y agoSo wait... this works regardless of wireless card? I've tried to use BackTrack on my mac before and it failed due to the card not being able to run in passive mode.
- mrgordon 16y agoYes, I believe it should work on any wireless card because you're not doing packet injection.
- robhu 16y agoIt doesn't work on my late 2009 MBP (sniffs sessions from other browsers on my laptop but not other laptops on our wifi).
- phamilton 16y agoare you sure you aren't on a WPA encrypted network? My understanding is that it doesn't work over WPA. WEP apparently does work though.
- zombocom 16y agoI'm on an open network (no security) and I too am only seeing traffic from the computer I'm running it on. I have two Macs on the same wifi network, but no luck so far =/
- icode 16y agoIt states that it works for "open networks". What does that mean? All networks that you have access to? Including those in Cafes where they give you a key to log in? Or just networks that are completely open? And why does it work at all? I thought the wlan access point would encrypt the communication between itself and the computer. Would be interesting, which protocols are vulnurable to this and which are not. I guess the logging of raw wlan packets is a one-liner under linux? Does anybody know it?
- s3graham 16y agoSSL requires a unique IP per hostname, correct? Maybe this will be what actually ends up getting IPv6 going... :)
- rubinelli 16y agoIt used to be so, but newer servers can now serve more than one HTTPS domain using the same IP. For more details, check out http://serverfault.com/questions/109800/multiple-ssl-domains-on-the-same-ip-address-and-same-port http://serverfault.com/questions/109800/multiple-ssl-domains...
- amalcon 16y agoNewer servers can serve more than one HTTPS domain using the same IP... to users who are not using IE/Chrome/Safari under Windows XP. If you depend on SNI, you're leaving out something like a third of your user base.
- rubinelli 16y agoThanks. There really isn't anything more dangerous than just a bit of knowledge.
- ramanujan 16y agoThere are probably going to be a lot of people negatively affected by this for quite some time to come. One thing to point out is that there are grades of things. There is "public", and then there is "top hit on Google". Similarly, there is "insecure" and then there is "simple doubleclick tool to facilitate identity theft". How many millions of dollars and man hours is it going to take to lock down every access point? How many new servers are going to be needed now that https is used for everything and requests can't be cached? America was a better place when people could keep their doors unlocked, and when someone's first response to a break-in was to blame the criminal. By contrast it's fashionable among a certain set (no doubt including the author of this mess, Mr. Butler himself) to hold that the real culprits are the door manufacturers. What said facile analysis excludes, of course is that there is always a greater level of security possible. The level we currently employ reflects our tradeoffs between the available threats and the cost/convenience loss of bolting our doors and putting finials on our gates. Butler has simply raised the threat level for everyone. He did not invent a new lock or close a hole. He's now forcing lots of people to live up to his level of security. Congratulations to the new Jason Fortuny.
- zecg 16y agoThis is IMO a completely wrong approach to security. Butler has not raised the threat level, he has merely illuminated the existing threat level.
- bsaunder 16y agoIllumination is one thing. Enabling a ten year old to do malicious stuff with a few clicks and poorly considered actions is entirely another.
- evilduck 16y agoIf it can be that easily scripted, 10 year olds were already doing it. Suppressing knowledge, especially knowledge of a flawed system, doesn't make the system safer. In terms of severity, computing has overcome worse exploits; this is a problem awaiting an answer, which sounds like opportunity to me.
- al_james 16y agoWhat does this mean for HTTP basic authentication? How about digest access authentication?
- pornel 16y agoBasic is useless - sends password in the clear. Digest authentication is safe against passive sniffing (it doesn't exchange any password/token in the clear and uses nonces), but it doesn't protect against active attacker who could modify server headers and replace "Digest" with "Basic" to reveal password.
- al_james 16y agoOk, so digest authentication is safe against this new firefox extension? If so, why don't facebook et al. switch to digest based authentication? Surely its better than unencrypted cookie based logins. Is it just that its ugly (the browser login popup)?
- pornel 16y agoYes, Digest is safe in this case, but one could write a more advanced (packet-injecting) tool/Firefox extension that breaks Digest too. Terribly bad UI and lack of standard way to log out are dealbreakers for HTTP auth. There's also no reliable way to customize UI to offer help, password reminders, branding or anything like that. There has been proposal to improve this in 1999: http://www.w3.org/TR/NOTE-authentform http://www.w3.org/TR/NOTE-authentform and recently discussed in HTML5 WG, but the conclusion was Digest and countless JS tricks proposed in its place are only partial solutions, cookies have unstoppable momentum, so it's better if everyone just switches to SSL.
- robhu 16y agoOn my Macbook Pro (purchased 1 year ago) it doesn't seem to be able to capture traffic on my wifi. It can see sessions originating from another browser on the same Mac, but not other macs on the wifi network. Is there a way of debugging what's going on?
- dekz 16y agoWhich sites are you using this on? It only works on a few select sites (and you can add more with some more javascript code). It worked for me on my MBP on the main sites, twitter some igoogle.
- robhu 16y agoI tried it on Facebook. I have a WPA2 protected Wifi network. Two laptops (a MB and a MBP) on it. I run it on the MBP, on the MB I refresh a logged in Facebook page, and nothing appears as captured on the MBP. If on the MBP I refresh Facebook in another browser it appears.
- jonknee 16y agoTry on an open wireless network.
- robhu 16y agoWhy? It should work on a WPA encrypted network as long as I have the network key - from the perspective of my network interface nothing is encrypted. This indicates that the card has not properly been put in to listening mode, which means the plugin is not operating my card correctly.
- rfugger 16y agoIt would help a bit if there was a way to automatically encrypt sessions on an open wifi access point without requiring a password to connect.
- mike_esspe 16y agoAlways use encryption, while using open wifi. I use openvpn ( http://openvpn.net/ http://openvpn.net/ ) for this.
- kogir 16y agoThis is one of many reasons Loopt has used SSL for all[1] traffic from the very beginning. At least WiFi has fairly limited range. Cell networks[2] (and satellite internet[3]) can be sniffed miles away. In addition to making session hijacking harder, using SSL keeps crappy proxies from caching private data. Remember when some AT&T users were getting logged in as other users on Facebook's mobile site? The cause was a mis-configured caching proxy. Raising awareness of issues like this gets them fixed. Until a service's users demand SSL, it won't be offered. Unless the service is Loopt :) It's not a noticeable computational burden, but it does increase latency and cost money (for certs). 1. Not images 2. Older GSM crypto can be hacked in real time with rainbow tables now 3. Usually not encrypted at all
- cdine 16y agoIndeed, Loopt appears to be one of the few high-profile sites to have done this right. SSL for everything, and cookies that are relevant to login sessions are marked secure. This is what we need everywhere!
- brlewis 16y agoI'm proud of http://ourdoings.com/ http://ourdoings.com/ having done this since 2004.
- mmaro 16y agoThere are antennas[1] that let you sniff wifi from ~4 miles way. Some routers can be configured to drop clients more than N meters away, though. [1] http://www.radiolabs.com/products/antennas/2.4gig/long-range-wifi-kit.php http://www.radiolabs.com/products/antennas/2.4gig/long-range...
- patio11 16y agoThanks for posting this. It convinced me to upgrade SSL support from "something that would be nice to implement if I was bored someday" (BCC is not exactly security critical -- except, on reflection, the admin pages) to "drop everything and get it done."
- euroclydon 16y agoYou're saying that the BCC server doesn't have even a self-signed SSL cert installed? Or something else?
- patio11 16y agoI had a SSL certificate for a while, but actually using it throughout the site without showing users Big Scary Error Messages is not quite trivial. The activation energy for digging through several hours of edge cases was lacking... until today. ("Whoops, while you don't know you're doing it, you pull an unnecessary CSS file into the cached CSS for the registration page which references a background image on an absolute http:// http:// URL. Your registration page now throws an error on IE. You lose." "You have approximately 150 images on the site linked as handcoded img tags rather than through Rails' image_tag helper, because when you were a Rails newbie you did not know that existed. You now get to rewrite all of them so that they can use SSL asset caching magic." etc, etc)
- euroclydon 16y agoI've seen some sites which figure out a way to force the user in and out of SSL for certain URLs. You might be able to implement a fix which forces SSL for the admin section and non-SSL for everything else.
- patio11 16y agoThat doesn't help, because my all-powerful admin session is as secure as the least secure page I access (or can be made to access) while on a compromised network.
- ddrager 16y agoI think this should be a call to arms to network, web and system admins everywhere. This is a problem that everyone knows about but nobody wants to do anything about since it requires additional setup. Usually the barrier is a technical issue that the end user can't figure out. However since submitting forms via SSL is something the developer can do without impacting the end user at all, this is a simple fix for just about any website. You need a static IP and an SSL certificate, and they are both cheap. Running out of IPv4 space is an issue in this regard, but hopefully with more people wanting SSL it will push providers to IPv6 quicker. Nicely done EricButler!
- pilom 16y agoAnyone going to get HN on HTTPS? I'm very partial to my kharma points and don't want anyone to log in as me!
- jdunck 16y agoTitle is a bit misleading. This is a front-end to libpcap, and can be used for hijacking any token-based-auth, not just HTTP. It just happens that they released w/ support for social networks as a demonstration.
- eapen 16y agoSites that are tracked: amazon basecamp bitly cisco cnet dropbox enom evernote facebook flickr foursquare github google gowalla hackernews harvest live nytimes pivotal sandiego_toorcon slicemanager tumblr twitter wordpress yahoo yelp
- DJN 16y agoThe main problem will be with SaaS apps that allow custom domains names (i.e. mywebsite.com instead of mywebsite.mysaasprovider.com). I made an early decision to enable SSL everywhere in Trafficspaces with the obvious downside being that I need to allocate a dedicated IP address each time someone requests a custom domain name. I used to get worried that perhaps it would have been better to only provide SSL in specific stages (such as sign-in and payment) and only through a generic domain name. Not any more. Firesheep clearly vindicates that decision.
- danudey 16y agoWouldn't it be easier to get a wildcard SSL certificate for *.mysaasprovider.com? That way you can serve all subdomains off a single IP address, since the name will always match.
- DJN 16y agoThat's what we are currently doing now. I was referring to cases where the account holder wants to use an custom domain name e.g. ads.mywebsite.com, instead of the generic mywebsite.mysaasprovider.com. In that case, we'll need to host their certificate within our Pound load balancer and get it to listen on a dedicated IP.
- petenixey 16y agoWhat a shame. There are going to be so many kids whose Facebook accounts get broken into and abused this week as a result of this.
- JshWright 16y agoIt's an interesting assortment of sites that are "supported" out of the box. Some of them are pretty harmless (bit.ly, Flickr), some could cause some pretty serious hassles (Google, Amazon), and some could be absolutely devastating (Deleting someone's Slicehost account? Ouch...).
- linhares 16y agoplease don't tell 4chan
- pberry 16y agoOn a positive note, at least a lot of people will be updating to the latest secure version of Firefox to run it.
- geuis 16y agoI just tried this here in a coffee shop. This is fucking evil.
- jawee 16y agoI'm eagerly waiting trying this out once a Linux version becomes available.. looks very nice! Unfortunately I don't have a Windows or OS X installation available to me at the moment.
- freefire4629 16y agowhat version of firefox do you need to have to run it? i can't get it to work.
- Ripst 16y agoPHP session_regenerate_id(true) http://www.php.net/manual/en/function.session-regenerate-id.php http://www.php.net/manual/en/function.session-regenerate-id....
- mattermortel 16y agoIsin't this extension great ? =D