When sharing an internet connection, be it office or public wi-fi, take note that your login online to eg. Facebook may be compromised by this thing called FireSheep.
It sniffs on the local data packets ... So beware!
I'm Insan4IT reminding just in case you forgot ! ;)
More Information:
Firesheep, the "new" tool used to grab login IDs, passwords and other important information isn't all that new and any hacker or a decent network admin have been able to sniff Wi-Fi data packet for years now. The only difference Firesheep does is making it easier.
Did a test sitting outside a coffeeshop and started scanning for Wi-Fi Access Points (AP). Took me almost an hour to find about 12 APs and "break" into about 7. Am not a good network admin or hacker but this is child's play as people have no clue on how to secure their wireless networks.
2 AP used the default passwords for their wireless routers and APs and 1 of those didn’t have any security, the other 1 were using, WEP! 1 used WPA TKIP security protocol. Used a rainbow table to open APs almost as quickly as I could open up a Heaven & Earth Lemon Tea bottle. Managed also to open a pair of routers using WPA2 with TKIP using rainbow table.
If you really want to secure a Wi-Fi network in 2010 you must use WPA2 with CCMP, aka AES. If you don’t, trust me, if someone really wanted your important information out of your business network they’ve already got it and they only need a baby cracker tool like Firesheep to do it.
The worry ? Not that someone from a local Wi-Fi hotspots getting your Facebook password but your office itself !
So, I guess, should thank Firesheep. Maybe it will finally make it clear to people that network security is important.
What am I saying? Most people, not even many network administrators, ever learn these lessons. Maybe a few people will start taking security seriously. I live in hope.
Wednesday, October 27, 2010
FaceBookers ! Beware of FireSheep!
Posted by Insan4IT at 14:29 0 comments
Subscribe to:
Posts (Atom)