|Operating system||Microsoft Windows and Mac OS X (highly unstable on Linux)|
Firesheep was an extension for the Firefox web browser that used a packet sniffer to intercept unencrypted session cookies from websites such as Facebook and Twitter. The plugin eavesdropped on Wi-Fi communications, listening for session cookies. When it detected a session cookie, the tool used this cookie to obtain the identity belonging to that session. The collected identities (victims) are displayed in a side bar in Firefox. By clicking on a victim's name, the victim's session is taken over by the attacker.
The extension was released October 2010 as a demonstration of the security risk of session hijacking vulnerabilities to users of web sites that only encrypt the login process and not the cookie(s) created during the login process. It has been warned that the use of the extension to capture login details without permission would violate wiretapping laws and/or computer security laws in some countries. Despite the security threat surrounding Firesheep, representatives for Mozilla Add-ons stated initially that it would not use the browser's internal add-on blacklist to disable use of Firesheep, as the blacklist has only been used to disable spyware or add-ons which inadvertently create security vulnerabilities, as opposed to attack tools (which may legitimately be used to test the security of one's own systems). Since then, Firesheep has been removed from the Firefox addon store.
A similar tool called Faceniff was released for Android mobile phones.
- Butler, Eric. "Firesheep – codebutler". Retrieved December 20, 2010. CS1 maint: discouraged parameter (link)
- Steve Gibson, Gibson Research Corporation. "Security Now! Transcript of Episode No. 272". Grc.com. Retrieved November 2, 2010. CS1 maint: discouraged parameter (link)
- "Firesheep Sniffs Out Facebook and Other User Credentials on Wi-Fi Hotspots". Lifehacker. Retrieved October 28, 2010. CS1 maint: discouraged parameter (link)
- Keizer, Gregg. "Mozilla: No 'kill switch' for Firesheep add-on". Computer World. Retrieved October 29, 2010. CS1 maint: discouraged parameter (link)
- "Sniff and intercept web session profiles on Android". Help Net Security. Retrieved June 2, 2011. CS1 maint: discouraged parameter (link)
- Firesheep home page
- Eric Butler
- New York Times article about Firesheep
- Setting up Firesheep on Linux