Social Icons

Pages

Kamis, 18 November 2010

Blacksheep Countermeasure for Firesheep




there's another tools to countermeasure this type of attack. A free Firefox plugin called BlackSheep, which serves as a counter-measure. BlackSheep combats Firesheep by monitoring traffic and then alerting users if Firesheep is being used on the network.

BlackSheep does this by dropping ‘fake’ session ID information on the wire and then monitors traffic to see if it has been hijacked.

It is this request that BlackSheep identifies in order to detect the presence of Firesheep on the network. When identified, the user will be receive the following warning message:

Blacksheep Countermeasure for Firesheep

Firesheep and BlackSheep cannot be installed on the same Firefox instance as they share much of the same code base. If you want to run both Firesheep and BlackSheep on the same machine, they should be installed in separate Firefox profiles.

So if you feel not safe browsing in a public network such as hotspot, you can run this tools to guide you along your browsing time. If there;s some alert in your network, don't be panic, just logout your account such as : facebook, wordpress, amazon, etc. and your account should be safe, but it will be a little annoying…it's better to try :-)

Firesheep HTTP Session Hijacking




Firesheep is a firefox extension to do the session hijacking. I was very surprised that this tools can hijack Facebook, Twitter, WordPress, Amazon, etc from the valid user. The most important thing that this tools is very easy to configure and to launch an attack. Just a few step : 1. Download Firesheep 2. Sit on a unencrypted wireless network 3. Turn on your wireless card and join the network 4. Start capturing with firesheep 5. Just waiting until some user authenticate at the facebook, twitter, etc.

Step by step :

1. The picture below is the interface of firesheep and you can click the red circle for preferences Firesheep Interface

2. In this picture you should choose which interface you want to capture the data. for example when you're in a wireless network, you should activate the wireless adapter. Firesheep Choose Network Adapter

3. This picture below tells you which website session can hijacked handle by this addons, Firesheep Website supported

4. Usually when capturing data, will use TCP port 80, because if it's 443 I think will be encrypted, but I still didn't try for another port :-) . Choose port to capture data

5. When you finish, click the "Start Capturing" and wait until someone authenticate some website on the website list. Data captured using firesheep

Prevention:

1. You can use Blacksheep,

2. You can tunnel your internet connection,

3. Don't use "Remember Me" feature in public internet area(Hotspot), and logout after you finish use the internet.

That's it. I hope you can use this tutorials in a good way