Firefox add-on Firesheep facilitates hijacking of Facebook, Twitter sessions
A Firefox add-on called "Firesheep" was released by a freelance web application developer over the weekend. Written by Eric Butler, it was specifically designed to demonstrate the vulnerability of using unprotected Wi-Fi access points, a danger that more computer-savvy users are aware of, but which almost everyone ignores.
Firesheep basically adds a sidebar to the Firefox browser that shows when someone on an open network visits sites such as Facebook, Twitter, Facklr, bit.ly, Google (NASDAQ: GOOG) and Amazon. Double-click on the entry, and you're logged in as them. To be clear, the add-on is merely a toolkit that exploits known security problems, and is not revolutionary by itself.
Regardless of this fact, Firesheep has proved to be irresistible to some, and has been downloaded more than 175,000 times at the time of my writing. Users who are interested can download Firesheep here. Note that Windows users will also have to download WinPcap to enable promiscuous mode on their network adapters for it to work.
For more on this story:
- check out this article at Computerworld
- check out this article at PC Mag
Related Articles:
Mozilla issues warning over password-stealing Firefox add-on
Firefox 4 beta shows some noticeable improvements
Adobe warns: Critical Flash flaw under active attack
Microsoft plug-in for Firefox patched




Comments