Perimeter
Guest Blog // Selected Security Content Provided By Sophos
What's This?
10/26/2010
02:35 PM
Dark Reading
Dark Reading
Security Insights
Connect Directly
RSS
E-Mail
50%
50%

Cookies, Social Media And FireSheep

We've been seeing a lot of interest in FireSheep, the FireFox add-on that lets you spy on websites. How bad is it really?

We've been seeing a lot of interest in FireSheep, the FireFox add-on that lets you spy on websites. How bad is it really?To back the train up, let me explain what the add-in actually does for the benefit of the not-so-technical reader. When you go to a coffee shop or anywhere that has public WiFi, you share that connection with every other person using it. So the traffic all goes out over the same IP address. If a patron logs into most websites, then he or she will get a session ID and a cookie. If one can spy on the contents of that cookie, then the "hacker" can use that ID and the additional info to send traffic as that patron. Yes, usernames and passwords are encrypted on login with https and/or SSL, but then most sites switch back to plain, old unencrypted HTTP. This is generally seen as a VERY BAD THING if you are a privacy advocate.

Now none of this is new, different, or original. There have been sniffing techniques as long as there have been cookies. However, a well-meaning researcher by the name of Eric Butler has changed the game by making this technique extremely simple and accessible to the average person. Now I get what his aim was: He tried to show how insecure websites are. We security folks have been banging the drum on this for ages. I'm hoping sites like Facebook and Twitter will take notice. But will they?

Putting aside the security hat for a moment, let's look at these sites. Social networking sites have a business plan. That plan is to connect people and get them to share ideas, content, photos, etc., as freely as possible. Security and privacy simply are not at the top of the business plan. They now have to skate the line of trying to satisfy security experts and privacy advocates, while still holding to their business plan of allowing the sharing of information. Now does that mean personally identifiable info (PII) should be on display? Not really, but you willingly provide that information when you sign up for these sites (unless you give false information). These sites have a responsibility to protect your PII, but you have the choice of whether to provide it in the first place. Now that said (security hat goes back on), social networks most certainly DO have an obligation to ensure the person logged into the account really is that person and not someone masquerading as him or her. And, yes, they do need to start securing the whole session and not just the logging in portion of the session.

On a side note, someone asked us at Sophos if we think Firefox should start vetting add-ins to prevent them from ever being downloaded. Should they? Probably. Can they? That's a question I can't answer. Being an open community means there is such great range of innovation and tools to help, but at the same time that means any bad guy can easily get in and spoil things.

Beth Jones is a Senior Threat Researcher in SophosLabs North America. She manages the day-to-day research and analysis activities of incoming suspicious malware threats and potentially unwanted applications that arrive in the Lab via Sophos customers, partners, and prospects.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3541
Published: 2014-07-29
The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.

CVE-2014-3542
Published: 2014-07-29
mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) is...

CVE-2014-3543
Published: 2014-07-29
mod/imscp/locallib.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via a package with a manifest file containing an XML external entity declaration in conjunction with an entity referenc...

CVE-2014-3544
Published: 2014-07-29
Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via the Skype ID profile field.

CVE-2014-3545
Published: 2014-07-29
Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to execute arbitrary code via a calculated question in a quiz.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Sara Peters hosts a conversation on Botnets and those who fight them.