2 ms·
This security-hole is for people surfing unencrypted networks. There are warnings you get from windows when you connect to such a network. I can assume OSX does
by Steve0 16y ago
This security-hole is for people surfing unencrypted networks. There are warnings you get from windows when you connect to such a network. I can assume OSX does the same.
The ferret and hamster tools did the same thing, just not packaged as an extension for firefox, and that was over three years ago. Just needed to find the cmd windows, run two programs, change your proxy and you're set.
See: http://erratasec.blogspot.com/2007/08/sidejacking-with-hamster_05.html http://erratasec.blogspot.com/2007/08/sidejacking-with-hamst...
Also how would you warn the right users? You don't know which of them are affected or at risk for this issue. Maybe promote http://hotspotshield.com/ http://hotspotshield.com/ or a similar product.
Lastly, if your on a unencrypted wifi network you're vulnerable to a lot more attacks than the firesheep one. So please don't assume that just using ssl is enough to protect you. One example: http://forums.remote-exploit.org/tutorials-guides/3157-ssl-sniffing-using-ssldump-webmitm-arpspoof.html http://forums.remote-exploit.org/tutorials-guides/3157-ssl-s...
- shock 16y ago"This security-hole is for people surfing unencrypted networks." I wish that was correct; however, according to http://www.airtightnetworks.com/WPA2-Hole196 http://www.airtightnetworks.com/WPA2-Hole196 even WPA2 is vulnerable. It states: "AirTight Networks uncovered a weakness in the WPA2 protocol, which was documented but buried on the last line on page 196 of the 1232-page IEEE 802.11 Standard (Revision, 2007). Thus, the moniker "Hole196". [...] Exploiting the vulnerability, an insider (authorized user) can sniff and decrypt data from other authorized users as well as scan their Wi-Fi devices for vulnerabilities, install malware and possibly compromise those devices. In short, this vulnerability means that inter-user data privacy among authorized users is inherently absent over the air in a WPA2-secured network." The only prerequisite is for the attacker to be same WPA secured wireless network as the victim. There are ways to accomplish that even for private WiFi. WEP has been cracked a long time ago. So, no actual security over WiFi alone. Need to use SSL, VPN, etc. for everything.