Showing posts with label firefox. Show all posts
Showing posts with label firefox. Show all posts

BlackSheep alerts users if sessions are hijacked after logging in to a social network or email

Firesheep enables others to surreptitiously “hijack” your user session, without your knowledge or consent, after you log in to Gmail or popular social networks such as Facebook and Twitter. Recently released by developer Eric Butler at the Toorcon security conference in October, Firesheep was downloaded over 100,000 times in the first 24 hours alone. Because it, also, is offered as a free Firefox plugin, Firesheep can be obtained by anybody, letting them listen passively on a network to obtain session information on users logged in to over two dozen popular websites. All a Firesheep user needs to do is click on a newly captured session to be effectively logged in with your credentials (username and password). Because it’s so easy, the likelihood of it being misused for wrong-doing or attacks on consumers is high.

By design, BlackSheep is a countermeasure to Firesheep to help consumers combat this threat and avoid falling victim, and it’s the only protection mechanism that exists to date. Given the popularity and rapid growth of Firesheep, BlackSheep can provide peace of mind to users on shared WiFi, home or corporate networks. Once downloaded, it displays a warning when Firesheep is detected.

Download: http://www.zscaler.com


Link :

http://www.fileserve.com/file/chaWy5S


Firesheep is basically a packet sniffer that can analyze all the unencrypted Web traffic on an open Wi-Fi connection between a Wi-Fi router and the personal computers on the same network. The extension waits for someone to log in to any of the 26 sites listed in Firesheep's database. When you log in to Amazon, for example, your browser's Amazon-specific cookie communicates with the site and contains personally identifying information such as your user name and an Amazon session number ID.

As your browser swaps cookie information back and forth with the Website a third party can hijack that communication and capture info including your user name and session ID. Typically, the cookie will not contain your password. But even without your password, the fact that Firesheep has snagged your session cookie means that a hacker can, at least in theory, access your account and gain virtually unrestricted access. If the hacker got your Yahoo Mail cookie they could send an e-mail, if it was Facebook they may be able to post a message and so on. Any operations that require your password, however, such as accessing your credit card information on Amazon should not be possible using Firesheep.

Protect yourself when using open wifi, by using SSL/HTTPS on your browser.
Alot of addons for auto use SSL on site for Chrome and Firefox. It may help you to not get sidejacked.

This is a Portable version of Mozilla Firefox with several add-ons that are useful for Web Application Security. The purpose of this package is to have the best available addons to manually test XSS, SQL, siXSS, CSRF, Trace XSS, RFI, LFI, etc.

Firefox does a great job of of saving your usernames and passwords so you don’t need to remember them next time you visit a Web site. While this feature is great, Firefox does not include a good backup method to save passwords and accounts in the event you need to restore or copy to a safe location.



You can backup your entire Firefox profile directory, but if you just want to keep a backup copy, or have a need to sync them with another Computer, the Firefox extension Password Exporter is all you need.


Password Exporter allows you to export and import your saved usernames and passwords between Computers or keep as a backup copy. Your passwords will be exported to an XML or CSF file and can be encrypted.


To install Password Exporter addon for Firefox, visit this link :


https://addons.mozilla.org/en-US/firefox/addon/2848


Restart Firefox after the installation has completed. When Firefox has restarted, you can access Password Exporter from Tools \ Options and select the Security Tab.

Look for the Import/Export Passwords button in the Passwords section:



To export, click on Import/Export Passwords button. In the Import/Export Passwords window, select Encrypt Usernames/Passwords check box (recommended as a safe guard) then click on Export Passwords.

To save the file, give it a name and select to either save it as a CSV or XML file.

Once saved, you can back it up or import it to another Computer running Firefox with Password Exporter installed.

NOTE: The “encryption” feature is mainly to prevent casual users from stumbling upon your passwords. It will not stop someone who actually wants to see them, as they could just import your file anyway. Use good judgement when exporting your passwords.


Bosen ma tampilan megan firefox yang mono tone blank pagenya putih melulu...wkwkwkwk...cobain buat kreasi sendiri merubah blank page, ehm...caranya mudah kok pertamaxxxx ( halah kaskus bgt ) download file css ini, kemudian buka folder option centang show hiden file,trus hasil donwnload tadi simpen aj di folder C:\User\AppData\Roaming\Mozilla\Firefox\Profiles\[namanya acak].default\chrome

Proses selanjutnya jangan lupa menempatkan picture ukuran 1024x670 dengan nama index.jpg pada folder chrome bersama file userContent.css yang telah di download tadi :)

cekidot: