Filed Under: hack facebook , hack twitter
Showing posts with label hack twitter. Show all posts
Showing posts with label hack twitter. Show all posts
Friday, May 10, 2013
How To Get Thousands Of FB/Twitter/Youtubbe Followers Every Hour
How To Get Thousands Of FB/Twitter/Youtubbe Followers Every Hour
2013-05-10T11:56:00-07:00
wildrank
hack facebook
|
hack twitter
|
Comments
Posted by
wildrank
on
Friday, May 10, 2013
The world popular social networking site Facebook, Twitter, Youtube are great places to advertise websites or products.
Facebook, Twitter, Youtube are undoubtedly the best social network sites which if uses wisely can gift you thousands of daily readers and customers to your product or services. Such sites will surely help your brand to grow strongly on Internet / Social Media Marketing. You just need to share your products updates there and your fans, who liked you will get instant update. But if you dont have followrs on such website then these sites are useless for you.
The more Like you get, that much effectively you can drive Facebook,Twitter, Youtube visitors. As whenever you post any update on your Twitter, Youtube Fan Page, It will be visible on all the Twitter, Youtube users’ who have liked your fan page. It will not only visible to them but even their Twitter, Youtube friends can also see your updates.
Filed Under: hack facebook , hack twitter
Thursday, April 25, 2013
Facebook Paypal Hacking Tool 2013 : Istealer : Hack Twitter Password Software
Facebook Paypal Hacking Tool 2013 : Istealer : Hack Twitter Password Software
2013-04-25T11:37:00-07:00
wildrank
hack facebook
|
hack twitter
|
KEYLOGGER
|
Comments
Posted by
wildrank
on
Thursday, April 25, 2013
Istealer is an efficient windows password stealer software used for hacking various email account password such paypal password hacking, facebook password hacking etc. I have already explained about RATs and keyloggers to hack email account passwords, where you have to send your keylogged file to victim. In the same way, Istealer can be used to hack email account password and find passwords of various emails. I have provided link for software download. Using Istealer you can easily hack or steal the password of Twitter account, Facebook Account, Gmail Account, Hotmail Account, Yahoo Accounts and many other account password easily.
Basically, in this trick you create server file which is used to capture the keystrokes of your slave, after creating server file you have to send that file to slave and use a bit of social engineering to get them to click on the server file and run the server file. Once the server file is run, it will start his working like capturing keystrokes etc.
Filed Under: hack facebook , hack twitter , KEYLOGGER
Sunday, April 14, 2013
Hack Twitter | How to Hack a Twitter Password
Hack Twitter | How to Hack a Twitter Password
2013-04-14T12:00:00-07:00
wildrank
hack twitter
|
KEYLOGGER
|
MOBILE HACKS
|
Comments
Posted by
wildrank
on
Sunday, April 14, 2013

There are so many peoples across the globe who wants to hack their girlfriend or boyfriend or someone else facebook password? Well, you’re at the right place my friend! Today in this article I will show you how you can easily hack someone twitter account password in just few simple steps. If you are not computer expert then also fine no problem at all. Today I ll show you some powerfull hacking tools which you can used to hack twitter password and all this hacking tools are user friendly, need only basic knowledge of computer. What do you have to do in order to hack into Twitter accounts password? Read on to find out but don't you dare try it!
Filed Under: hack twitter , KEYLOGGER , MOBILE HACKS
Thursday, February 28, 2013
Remote password hacking software - sniperspy
Remote password hacking software - sniperspy
2013-02-28T09:34:00-08:00
wildrank
hack facebook
|
hack hotmail
|
hack twitter
|
KEYLOGGER
|
Comments
Posted by
wildrank
on
Thursday, February 28, 2013

SniperSpy is the industry leading Remote password hacking software combined with the Remote Install and Remote Viewing feature. Once installed on the remote PC(s) you wish, you only need to login to your own personal SniperSpy account to view activity logs of the remote PC’s! This means that you can view logs of the remote PC’s from anywhere in the world as long as you have internet access! Do you want to Spy on a Remote PC? Expose the truth behind the lies! Unlike the rest, SniperSpy allows you to remotely spy any PC like a television! Watch what happens on the screen LIVE! The only remote PC spy software with a SECURE control panel! This Remote PC Spy software also saves screenshots along with text logs of chats, websites, keystrokes in any language and more. Remotely view everything your child, employee or anyone does while they use your distant PC. Includes LIVE admin and control commands!
Filed Under: hack facebook , hack hotmail , hack twitter , KEYLOGGER
Thursday, February 21, 2013
How To Hack Twitter | Facebook | Gmail Using Doxing
How To Hack Twitter | Facebook | Gmail Using Doxing
2013-02-21T02:21:00-08:00
wildrank
hack facebook
|
HACK GMAIL
|
hack hotmail
|
hack twitter
|
Comments
Posted by
wildrank
on
Thursday, February 21, 2013
As we all know,On WildHacker we have already discussed various hacking method to hack email account password like keylogging, Tabnabbing etc. I have already written article on doxing method ( "Doxing Tutorial : Hack Hotmail and Facebook Account Password" ) But today i am going to write one more article on same Doxing technique which is most useful way to hack different types of email account password. Here is in tutorial I have explained - how to successfully Dox using a certain amount of ways, which are most likely the easiest because you are hardly doing work yourself.
Doxing is the process of gaining information about someone or something by using sources on the Internet and using basic deduction skills. Its name is derived from “Documents” and in short it is the retrieval of “Documents” on a person or company.
Filed Under: hack facebook , HACK GMAIL , hack hotmail , hack twitter
Monday, February 11, 2013
Get Unlimited Subscribers Or Likes For Facebook | Twitter | Youtube | Google+
Get Unlimited Subscribers Or Likes For Facebook | Twitter | Youtube | Google+
2013-02-11T11:17:00-08:00
wildrank
hack facebook
|
hack twitter
|
hack youtube
|
Comments
Posted by
wildrank
on
Monday, February 11, 2013
How to increase youtube, Google+, Pinterest, SoundCloud, Twitter views or Facebook - Likes / Subscribers / Shares and how to increase youtube, Google+, Pinterest, SoundCloud, Twitter subscribers??? This is the first question comes in everyone's mind when they start advertising their product or website through such social websites video. Today in this article I am going to show you how to get unlimited subscribers/likes for youtube, Google+, Pinterest, SoundCloud, Twitter and facebook.
Filed Under: hack facebook , hack twitter , hack youtube
Saturday, February 9, 2013
Hack Facebook Account Using FUD / Undectable MAC Keylogger 2013
Hack Facebook Account Using FUD / Undectable MAC Keylogger 2013
2013-02-09T10:53:00-08:00
wildrank
hack facebook
|
HACK GMAIL
|
hack twitter
|
KEYLOGGER
|
Comments
Posted by
wildrank
on
Saturday, February 09, 2013
Now days Facebook is the biggest and most popular social networking website as compare to Twitter website. However along with the growing popularity of Facebook, Facebook is also gaining a wide attention of black and gray hat hackers as well.
There are lots of Password Hacking tools are available on internet which you can use to hack victim account password. Keylogger or Spyware hacking tool is one of them and it is the best password hacking tool as compare to other email hacking software, because normal users who are not computer expert can also easily use it. But most of those hacking tools only support Windows operating system, only few hacking tool support MAC Operating system.
Filed Under: hack facebook , HACK GMAIL , hack twitter , KEYLOGGER
Friday, February 1, 2013
FUD Keylogger | Hack Facebook | Hack Password | Computer Hacking | Hack Twitter
FUD Keylogger | Hack Facebook | Hack Password | Computer Hacking | Hack Twitter
2013-02-01T11:12:00-08:00
wildrank
hack facebook
|
hack twitter
|
KEYLOGGER
|
Comments
Posted by
wildrank
on
Friday, February 01, 2013
There are lots of Password Hacking tools are available on internet which you can use to hack victim account password. Keylogger or Spyware hacking tool is one of them and it is the best password hacking tool as compare to other email hacking software, because normal users who are not computer expert can also easily use it.
Keylogger or Spyware software has the capability to record keystroke/captures Screen Shots and can sent it to your email account or on FTP account. Captures every key pressed on the computer viewed by the unauthorized user. Key logger software can record instant messages, e-mail and any information you type at any time on your keyboard. The log file created by the key logger can then be saved to a specific location or mailed to the concerned person. The software will also record any e-mail address you use and Website URLs visited by you.
Some advance Keylogger with its more powerful features and advanced technology captures the Desktop snapshots at regular interval of time and records the keyboard typed activities in a hidden password protected and encrypted log file.
Some advance Keylogger with its more powerful features and advanced technology captures the Desktop snapshots at regular interval of time and records the keyboard typed activities in a hidden password protected and encrypted log file.
Filed Under: hack facebook , hack twitter , KEYLOGGER
Saturday, January 26, 2013
Istealer Tutorial : Password Stealer To Hack Twitter / Facebook Account Password
Istealer Tutorial : Password Stealer To Hack Twitter / Facebook Account Password
2013-01-26T09:52:00-08:00
wildrank
hack facebook
|
hack twitter
|
KEYLOGGER
|
Comments
Posted by
wildrank
on
Saturday, January 26, 2013
Istealer is an efficient windows password stealer software used for hacking various email account password such paypal password hacking, facebook password hacking etc. I have already explained about RATs and keyloggers to hack email account passwords, where you have to send your keylogged file to victim. In the same way, Istealer can be used to hack email account password and find passwords of various emails. I have provided link for software download. Using Istealer you can easily hack or steal the password of Twitter account, Facebook Account, Gmail Account, Hotmail Account, Yahoo Accounts and many other account password easily.
Basically, in this trick you create server file which is used to capture the keystrokes of your slave, after creating server file you have to send that file to slave and use a bit of social engineering to get them to click on the server file and run the server file. Once the server file is run, it will start his working like capturing keystrokes etc.
You might be interested in some of our other articles:
Basically, in this trick you create server file which is used to capture the keystrokes of your slave, after creating server file you have to send that file to slave and use a bit of social engineering to get them to click on the server file and run the server file. Once the server file is run, it will start his working like capturing keystrokes etc.
You might be interested in some of our other articles:
- Hack Facebook : Facebook Hacking Course Released
- Facebook, Hotmail, Gmail Passowrd hacking through Winspy Keylogger
- Remote Password Hacking Software - Sniperspy keylogger
- How To Hack Password Through Mobile
Istealer Password stealer - hack email passwords:
Follow the following steps to setup Istealer to hack email account password,Filed Under: hack facebook , hack twitter , KEYLOGGER
Sunday, January 13, 2013
Hack Password : Hack Paypal, Facebook, Hotmail Password Using URL
Hack Password : Hack Paypal, Facebook, Hotmail Password Using URL
2013-01-13T11:13:00-08:00
wildrank
hack facebook
|
hack hotmail
|
hack twitter
|
Comments
Posted by
wildrank
on
Sunday, January 13, 2013
Hello guys..today i am going to share one of the best and simple trick to hack or steal the password of Facebook Account, Gmail Account, Hotmail Account, Yahoo Accounts etc which are stored in browser using Remote Windows Stealer via URL, You do not need to install any software in victim computer, Just need to send the URL to a slave, use a bit of social engineering to get them to click on the link and run the applet program.
But this Remote Windows Stealer has some limitation, like it only works for Windows Vista / 7, not XP and works on the following browsers: Firefox, Google Chrome, and Internet Explorer.
Remote Windows Stealer is one of the easiest stealers you will ever use. Along with a little social engineering, you can decrypt hundreds of passwords in no time! Luckily, the average many users does not have much knowledge of computers so a little of social engineering should do the trick. It uses vulnerabilities of Windows that I have discovered myself. Just follow a few simple steps and it will decrypt all of the stored passwords from the internet browsers and sends the notification to your email! It is 100% Full Undetectable by ALL anti-viruses because there is nothing downloaded onto the slave's computer.
Basically, in this trick you register your email, pick a theme and it will give you a URL. Send the URL to a slave, use a bit of social engineering to get them to click on the link and run the applet. Once the applet is run, they will get a fake error message and the decrypted stored passwords and cookie files will be sent to your email. It is 100% FUD. All the decryption is done through the applet so it is not JDB and no files are downloaded to the slave's computer hence wont trigger Anti Viruses.
You might be interested in some of our other articles:
Follow the following steps to hack or steal password of Facebook Account, Twitter Account, Hotmail Account, Paypal Account which are stored in browser using Remote Windows Stealer via URL
But this Remote Windows Stealer has some limitation, like it only works for Windows Vista / 7, not XP and works on the following browsers: Firefox, Google Chrome, and Internet Explorer.
Remote Windows Stealer is one of the easiest stealers you will ever use. Along with a little social engineering, you can decrypt hundreds of passwords in no time! Luckily, the average many users does not have much knowledge of computers so a little of social engineering should do the trick. It uses vulnerabilities of Windows that I have discovered myself. Just follow a few simple steps and it will decrypt all of the stored passwords from the internet browsers and sends the notification to your email! It is 100% Full Undetectable by ALL anti-viruses because there is nothing downloaded onto the slave's computer.
Basically, in this trick you register your email, pick a theme and it will give you a URL. Send the URL to a slave, use a bit of social engineering to get them to click on the link and run the applet. Once the applet is run, they will get a fake error message and the decrypted stored passwords and cookie files will be sent to your email. It is 100% FUD. All the decryption is done through the applet so it is not JDB and no files are downloaded to the slave's computer hence wont trigger Anti Viruses.
You might be interested in some of our other articles:
- How to Hack Facebook Account Password Using Tabnabbing
- Doxing Tutorial : Hack Hotmail and Facebook Account Password
- Facebook, Hotmail, Gmail Passowrd hacking through Winspy Keylogger
- Remote Password Hacking Software - Sniperspy keylogger
- How To Hack Password Through Mobile
Hack Twitter Account and Facebook Account Password In One Click
Follow the following steps to hack or steal password of Facebook Account, Twitter Account, Hotmail Account, Paypal Account which are stored in browser using Remote Windows Stealer via URL
Filed Under: hack facebook , hack hotmail , hack twitter
Wednesday, October 5, 2011
Hacking Passwords Using MITM (Man In The Middle) Attack On BackTrack 5
Hacking Passwords Using MITM (Man In The Middle) Attack On BackTrack 5
2011-10-05T11:13:00-07:00
wildrank
hack facebook
|
hack hotmail
|
hack twitter
|
HACKING SOFTWARES
|
Comments
Posted by
wildrank
on
Wednesday, October 05, 2011
Today in this article I will be showing you how to HACK Gmail credentials and gaining information such as passwords,user ids etc or any other SSL(secured socket layer) site's credentials in a network, using MITM(man in the middle ) attack with Backtrack 5.
Concept :-
It is nothing but an attacker who sits in between the two user in an network. Normally the two person will be the user and the router(gateway) in an network. The attacker will try to do few trick and replace the roll of router and he sits in his position. This is done by doing DNS spoofing, ARP poisoning, IP spoofing and few more other method. In this attack the user will not come to know that, his traffic is been forwarded through the attacker in the network. The attacker can simply gather information about the user and use it later or attacker can try to do active attack to the user.
You might be interested in some of our other articles:
Tools:
All these tools are installed in backtrack 5..
Step 1: First we need to setup ip forwarding using fragrouter. open a shell and type the command...
Code:
fragrouter -B1
This is to forward packets between the slave and its gateway while spoofing .... minimize the shell..
Step 2: Now we need to arp spoof the slave , open a new shell and type the command.
Code:
arpspoof -t [target ip] [default gateway ip]
example :
arpspoof -t 192.168.1.7 192.168.1.1
then minimize the shell .... now we have begin to arpspoof the slave...
Step 3: then for dns spoofing open a new shell and type
Code:
dnsspoof
then minimize the shell.... now all the DNS request from the slave will be redirected to us..
Step 4: To give proxy for these DNS requests ,we have to start up Webmitm open a new shell and type.
Code:
webmitm -d
if you were starting Webmitm for the first time it will ask you some details to create fake SSL certificate and private key ... just fill something in it...if you fill everything,then it will say " webmitm relaying transparently "
ok its done, minimize the shell..
Step 5: Now we need to capture the traffic using wireshark
Code:
applications ->backtrack -> information gathering ->network analysis ->network traffic analysis ->wireshark
Step 6: In wireshark select
Code:
capture -> interfaces -> start (cick start button near eth0 )
that's it
since the Dns has been spoofed, we can see the nslookup for gmail in slave computer shows attacker's ip :
In our case slave opens "gmail.com" in browser .He will be redirected to webmitm , which will issue the 'gmail page' with fake ssl certificate ,then our slave well log into "gmail" using his credentials... now all the traffic will be captured by wireshark ...then just stop the wireshark and save the captured traffic to root folder ... for example, i will save it as "test"..
In the root folder there will be another file called "webmitm.crt"..it is the fake ssl certificate generated by webmitm...
Now we have captured ssl packets and our own fake ssl certificate..
now to decrypt the captured packets...
open another new shell and type :
Code:
ssldump -r test -k webmitm.crt -d > finaloutput
were,
test -->captured packets
webmitm.crt --> SSL certificate
finaloutput --> decrypted output file
now open a shell and type :
Code:
cat finaloutput | grep Email
it will show you the decrypted username and password .
So friends, I hope you have enjoyed reading the aricle.if you have any doubts, please mention it in comments.
Enjoy HaCkInG...
Concept :-
It is nothing but an attacker who sits in between the two user in an network. Normally the two person will be the user and the router(gateway) in an network. The attacker will try to do few trick and replace the roll of router and he sits in his position. This is done by doing DNS spoofing, ARP poisoning, IP spoofing and few more other method. In this attack the user will not come to know that, his traffic is been forwarded through the attacker in the network. The attacker can simply gather information about the user and use it later or attacker can try to do active attack to the user.
You might be interested in some of our other articles:
- Download Free 100% FUD Crypter To Bypass Antivirus Detection
- Doxing Tutorial : Hack Hotmail and Facebook Account Password
- Facebook, Hotmail, Gmail Passowrd hacking through Winspy Keylogger
- Remote Password Hacking Software - Sniperspy keylogger
- How To Hack Password Through Mobile
Hacking Passwords Using MITM (Man In The Middle) Attack
Definitons :- SSL : Secure Sockets Layer, a computing protocol that ensures the security of data sent via the Internet by using encryption . With SSL, client and server computers exchange public keys, allowing them to encode and decode their communication. So any attacker tries to sniff traffic between them will only get encrypted garbage values... the web servers which use SSL are denoted by HTTPS ...
- ARP : Address Resolution Protocol is a network layer protocol used to convert an IP address into a physical address such as an Ethernet address( MAC address ). A host wishing to obtain a physical address broadcasts an ARP request onto the TCP/IP network. The host on the network that has the IP address in the request then replies with its physical hardware address.
- DNS : Domain Name System is a database system that translates a domain name into an IP address. for example if you type gmail.com in your browser , your DNS will reply with gmail's ip so that,your router can connect to gmail's server using its IP....for better understanding type -->" nslookup " in your cmd or konsole and then type "gmail.com" ,you will see your DNS replies you with gmail's ip addresses .
- ARP Spoofing : ARP spoofing is a technique in which a host in a LAN can "poison" the ARP table of another host by forging fake ARP requests and replies , causing it to send packets to the wrong destination. The attacker can modify the traffic in the network such a way that it will redirect all traffic to go through it. ARP Spoofing will allow an attacker to sniff data frames.
- DNS Spoofing : DNS spoofing is similar to arp spoofing ,it is based on the presentation of false or fake DNS information to the slave in a response to their DNS request and as a result forcing them to visit a site which is not the real one.
- MITM : Man in the middle attack means intercepting a communication between two systems ,both ARP Spoofing and DNS Spoofing are types of MITM attack..
- IP Forwarding : IP forwarding enables one host to sit on two LANs and to act as a gateway forwarding IP packets from one LAN to another.
Tools:
- Fragrouter - tool used to for ip forwarding between slave and its destination host.
- Arpspoof - to arp spoof slave machine and its host
- Dnsspoof - to dns spoof slave machine and its host
- Webmitm - its a tool which transparently proxies and sniffs HTTP / HTTPS traffic redirected by dnsspoof, capturing most "secure" SSL-encrypted webmail logins and form submissions...
- Wireshark - it is a network protocol analyzer . here its used to capture ssl encrypted traffic between slave and webmitm...
- Ssldump - decrypts ssl packets using private key
All these tools are installed in backtrack 5..
Hacking Gmail Passwords using MITM attack on backtrack 5
Step 1: First we need to setup ip forwarding using fragrouter. open a shell and type the command...
Code:
fragrouter -B1
This is to forward packets between the slave and its gateway while spoofing .... minimize the shell..
Step 2: Now we need to arp spoof the slave , open a new shell and type the command.
Code:
arpspoof -t [target ip] [default gateway ip]
example :
arpspoof -t 192.168.1.7 192.168.1.1
then minimize the shell .... now we have begin to arpspoof the slave...
Step 3: then for dns spoofing open a new shell and type
Code:
dnsspoof
then minimize the shell.... now all the DNS request from the slave will be redirected to us..
Step 4: To give proxy for these DNS requests ,we have to start up Webmitm open a new shell and type.
Code:
webmitm -d
if you were starting Webmitm for the first time it will ask you some details to create fake SSL certificate and private key ... just fill something in it...if you fill everything,then it will say " webmitm relaying transparently "
ok its done, minimize the shell..
Step 5: Now we need to capture the traffic using wireshark
Code:
applications ->backtrack -> information gathering ->network analysis ->network traffic analysis ->wireshark
Step 6: In wireshark select
Code:
capture -> interfaces -> start (cick start button near eth0 )
that's it
since the Dns has been spoofed, we can see the nslookup for gmail in slave computer shows attacker's ip :
In our case slave opens "gmail.com" in browser .He will be redirected to webmitm , which will issue the 'gmail page' with fake ssl certificate ,then our slave well log into "gmail" using his credentials... now all the traffic will be captured by wireshark ...then just stop the wireshark and save the captured traffic to root folder ... for example, i will save it as "test"..
In the root folder there will be another file called "webmitm.crt"..it is the fake ssl certificate generated by webmitm...
Now we have captured ssl packets and our own fake ssl certificate..
now to decrypt the captured packets...
open another new shell and type :
Code:
ssldump -r test -k webmitm.crt -d > finaloutput
were,
test -->captured packets
webmitm.crt --> SSL certificate
finaloutput --> decrypted output file
now open a shell and type :
Code:
cat finaloutput | grep Email
it will show you the decrypted username and password .
So friends, I hope you have enjoyed reading the aricle.if you have any doubts, please mention it in comments.
Enjoy HaCkInG...
Filed Under: hack facebook , hack hotmail , hack twitter , HACKING SOFTWARES
Tuesday, November 2, 2010
Hack Facebook/Twitter Or Any Email Account With Session Hijacking
Hack Facebook/Twitter Or Any Email Account With Session Hijacking
2010-11-02T05:50:00-07:00
wildrank
hack facebook
|
hack twitter
|
Comments
Posted by
wildrank
on
Tuesday, November 02, 2010
When logging into a website you usually start by submitting your username and password. The server then checks to see if an account matching this information exists and if so, replies back to you with a "cookie" which is used by your browser for all subsequent requests.
It's extremely common for websites to protect your password by encrypting the initial login, but surprisingly uncommon for websites to encrypt everything else. This leaves the cookie (and the user) vulnerable. HTTP session hijacking (sometimes called "sidejacking") is when an attacker gets a hold of a user's cookie, allowing them to do anything the user can do on a particular website. On an open wireless network, cookies are basically shouted through the air, making these attacks extremely easy.
This is a widely known problem that has been talked about to death, yet very popular websites continue to fail at protecting their users. The only effective fix for this problem is full end-to-end encryption, known on the web as HTTPS or SSL.
Facebook is constantly rolling out new "privacy" features in an endless attempt to quell the screams of unhappy users, but what's the point when someone can just take over an account entirely?
Twitter forced all third party developers to use OAuth then immediately released (and promoted) a new version of their insecure website. When it comes to user privacy, SSL is the elephant in the room.
Firesheep, a Firefox extension designed to demonstrate just how serious this problem is.
After installing the extension you'll see a new sidebar. Connect to any busy open wifi network and click the big "Start Capturing" button. Then wait.
As soon as anyone on the network visits an insecure website known to Firesheep, their name and photo will be displayed:
Double-click on someone, and you're instantly logged in as them.
That's it.
Firesheep is free, open source, and is available now for Mac OS X and Windows. Linux support is on the way.
Websites have a responsibility to protect the people who depend on their services. They've been ignoring this responsibility for too long, and it's time for everyone to demand a more secure web. My hope is that Firesheep will help the users win.
By Codebutler..
It's extremely common for websites to protect your password by encrypting the initial login, but surprisingly uncommon for websites to encrypt everything else. This leaves the cookie (and the user) vulnerable. HTTP session hijacking (sometimes called "sidejacking") is when an attacker gets a hold of a user's cookie, allowing them to do anything the user can do on a particular website. On an open wireless network, cookies are basically shouted through the air, making these attacks extremely easy.
This is a widely known problem that has been talked about to death, yet very popular websites continue to fail at protecting their users. The only effective fix for this problem is full end-to-end encryption, known on the web as HTTPS or SSL.
Facebook is constantly rolling out new "privacy" features in an endless attempt to quell the screams of unhappy users, but what's the point when someone can just take over an account entirely?
Twitter forced all third party developers to use OAuth then immediately released (and promoted) a new version of their insecure website. When it comes to user privacy, SSL is the elephant in the room.
Firesheep, a Firefox extension designed to demonstrate just how serious this problem is.
After installing the extension you'll see a new sidebar. Connect to any busy open wifi network and click the big "Start Capturing" button. Then wait.
As soon as anyone on the network visits an insecure website known to Firesheep, their name and photo will be displayed:
Double-click on someone, and you're instantly logged in as them.
That's it.
Firesheep is free, open source, and is available now for Mac OS X and Windows. Linux support is on the way.
Websites have a responsibility to protect the people who depend on their services. They've been ignoring this responsibility for too long, and it's time for everyone to demand a more secure web. My hope is that Firesheep will help the users win.
By Codebutler..
Filed Under: hack facebook , hack twitter
Subscribe to:
Posts
(
Atom
)




















