What Are Cookies ? And What Is The Use Of Stealing Cookies ?
Cookies are small files that stored on users computer by websites when a user visits them. The stored Cookies are used by the web server to identify and authenticate the user .For example when a user logins in Facebook a unique string is generated and one copy of it is saved on the server and other is saved on the users browser as Cookies. Both are matched every time the user does any thing in his account
So if we steal the victims cookie and
inject them in our browser we will be able to imitate the victims
identity to the web server and thus we will be able to login is his
account . This is called as Side jacking .The best thing about this is
that we need not no the victims id or password all we need is the victims cookie.
What is Fire Sheep?
Fire sheep is an extension
developed by Eric Butler for the Firefox web browser. The extension uses
a packet sniffer to intercept unencrypted cookies from certain websites (such as Facebook and Twitter)
as the cookies are transmitted over networks, exploiting session
hijacking vulnerabilities. It shows the discovered identities on a
sidebar displayed in the browser, and allows the user to instantly take
on the log-in credentials of the user by double-clicking on the victim’s
name
Hack Facebook / Twitter accounts using Fire SheepThing we Need :
1. Firefox Browser
2. Fire sheep Firefox plugin
Procedure :
1. First Download and install Firefox browser and Fire sheep add on
2. Open Firefox , Now click the (1) view button then select (2) side bar finally click(3) fire sheep or simply press ( ctrl + shift +s ) to open fire sheep
3. Now you can see fire sheep has opened up in the side bar Now select your interface by
going to preferences
4. Now click on start capture button and wait for a while ,
5. Now you can see different pre- authenticated sessions on the side bar select the session which you want
6. Now you will be automatically logged in the victims account . You can use this tool to hack Facebook/Twitter accounts
This Hack works only when computers are in a LAN or WiFi
No comments:
Post a Comment