chenGOD Posted October 25, 2010 Report Share Posted October 25, 2010 On 10/25/2010 at 6:09 PM, chaosmachine said: On 10/25/2010 at 6:04 PM, chenGOD said: well it appears that my school's network is safe.cause i'm not capturing shit. :( I was looking forward to doing some stalking!! i totally didn't try this at starbucks, and didn't manage to get some guy's facebook in about 10 seconds. also, if you're on windows, you need to install winpcap. I'm on Snow leopard latest, and using my school's default network for students, wasn't able to capture anything. I'll try it in a bigger class later on this afternoon. However, I have started using my school's secure network just in case...lol let's hear it for WPA enterprise!! Maybe I'll start using the school's VPN at home....although I don't think that there's anyone else on my network at home. Just to make sure I'm doing this right, I have to be on the same network as others in order to capture right? I mean, hypothetically speaking. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide all signatures 백호야~~~항상에 사랑할거예요.나의 아들. Shout outs to the saracens, musulmen and celestials. Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444233 Share on other sites More sharing options...
chaosmachine Posted October 25, 2010 Author Report Share Posted October 25, 2010 On 10/25/2010 at 7:44 PM, chenGOD said: I'm on Snow leopard latest, and using my school's default network for students, wasn't able to capture anything. I'll try it in a bigger class later on this afternoon. However, I have started using my school's secure network just in case...lol let's hear it for WPA enterprise!! Maybe I'll start using the school's VPN at home....although I don't think that there's anyone else on my network at home. Just to make sure I'm doing this right, I have to be on the same network as others in order to capture right? I mean, hypothetically speaking. i think you have to be on the same access point, too. if you have a phone that uses wifi, that's an easy way to test. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide all signatures WATMM Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444235 Share on other sites More sharing options...
GORDO Posted October 25, 2010 Report Share Posted October 25, 2010 maybe some wireless cards can't do it? much like with air crack that some wifi cards aren't good for it. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide GORDO's signature Hide all signatures ZOMG! Lazerz pew pew pew!!!!11!!1!!!!1!oneone!shift+one!~!!! Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444237 Share on other sites More sharing options...
oscillik Posted October 25, 2010 Report Share Posted October 25, 2010 On 10/25/2010 at 8:00 PM, GORDO said: maybe some wireless cards can't do it? much like with air crack that some wifi cards aren't good for it. it used to be the case that not all 802.11b or 802.11g cards could enter promiscuous mode. not too sure if that's changed now, though Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide oscillik's signature Hide all signatures Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444241 Share on other sites More sharing options...
plstik Posted October 25, 2010 Report Share Posted October 25, 2010 On 10/25/2010 at 6:09 PM, chaosmachine said: On 10/25/2010 at 6:04 PM, chenGOD said: well it appears that my school's network is safe.cause i'm not capturing shit. :( I was looking forward to doing some stalking!! i totally didn't try this at starbucks, and didn't manage to get some guy's facebook in about 10 seconds. also, if you're on windows, you need to install winpcap. been running firesheep for ~2h now and nothing´s on display, winpcap and all. Still... I dont trust no lousy wep-encryption Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444246 Share on other sites More sharing options...
Guest Scrambled Ears Posted October 25, 2010 Report Share Posted October 25, 2010 On 10/25/2010 at 6:35 PM, 24ourange said: what about tucking your penis behind your legs? If i browse with my penis tucked behind my legs will i be safe? Can they get my passwords if my penis is tucked behind my legs? i think you may be on to something Quote Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444255 Share on other sites More sharing options...
baph Posted October 25, 2010 Report Share Posted October 25, 2010 No! Tucking your penis between your legs is actually a guarantee that you're going to get fucked. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444258 Share on other sites More sharing options...
kokoon Posted October 25, 2010 Report Share Posted October 25, 2010 On 10/25/2010 at 7:22 PM, Ego said: Or just set up a SSH daemon on your home network and route your internet traffic over your home line. Ofcourse your speed will be limited to your home connection upload rate. But I can't imagine free VPN providers doing much better. Oh and you'll need some sort of home server ofcourse (although you could do it with router software like DD-WRT.) It's pretty easy to do. Set up daemon, connect with putty, set firefox to use SOCKS5 proxy. this. fortunately. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444264 Share on other sites More sharing options...
chenGOD Posted October 25, 2010 Report Share Posted October 25, 2010 Or you could always use the wonderful extension HTTPS everywhere made by the folks over at the EFF in combination with the tor project. Additionally, if you're concerned about privacy there's a good firefox addon called better privacy which is useful. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide all signatures 백호야~~~항상에 사랑할거예요.나의 아들. Shout outs to the saracens, musulmen and celestials. Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444277 Share on other sites More sharing options...
Joyrex Posted October 25, 2010 Report Share Posted October 25, 2010 What about WiFi that uses MAC address authentication? I know you can 'spoof' MAC addresses, but I would imagine this can pick up the packets regardless... I would imagine the only 'safe' option is not use WiFi on your personal network. More and more homes are setting up WiFi (I can see about 7-8 networks in my general area, and I would imagine most of those that have 'NONE' listed as the security really are 'NONE' - no MAC addresses, nothing. What if you use OpenDNS? Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide all signatures Follow WATMM on Twitter: @WATMMOfficial Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444284 Share on other sites More sharing options...
Guest the anonymous forumite Posted October 25, 2010 Report Share Posted October 25, 2010 how do you install this .xpi file ? Quote Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444289 Share on other sites More sharing options...
GORDO Posted October 25, 2010 Report Share Posted October 25, 2010 all a dns does is resolve domains to ip, right? i don't see how it could help. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide GORDO's signature Hide all signatures ZOMG! Lazerz pew pew pew!!!!11!!1!!!!1!oneone!shift+one!~!!! Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444290 Share on other sites More sharing options...
Guest Deep Fried Everything Posted October 25, 2010 Report Share Posted October 25, 2010 (edited) On 10/25/2010 at 9:24 PM, Joy Rex said: What about WiFi that uses MAC address authentication? I know you can 'spoof' MAC addresses, but I would imagine this can pick up the packets regardless... I would imagine the only 'safe' option is not use WiFi on your personal network. More and more homes are setting up WiFi (I can see about 7-8 networks in my general area, and I would imagine most of those that have 'NONE' listed as the security really are 'NONE' - no MAC addresses, nothing. What if you use OpenDNS? edit: nm, chaos already covered this. nothing to see here, move along now! Edited October 25, 2010 by Deep Fried Everything Quote Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444291 Share on other sites More sharing options...
Guest the anonymous forumite Posted October 25, 2010 Report Share Posted October 25, 2010 my browser says firesheep 1.1 i not compatible with firefox 3.6 Quote Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444293 Share on other sites More sharing options...
mcbpete Posted October 25, 2010 Report Share Posted October 25, 2010 On 10/25/2010 at 9:27 PM, the anonymous forumite said: how do you install this .xpi file ? You, erm, click on it ! .xpi installs generally get blocked as default though, you'll probably see a bar has added to the top of the page saying Firefox has prevented this site from installing software. Just click the allow button. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide all signatures I haven't eaten a Wagon Wheel since 07/11/07... ilovecubus.co.uk - 25ml of mp3 taken twice daily. Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444298 Share on other sites More sharing options...
chaosmachine Posted October 25, 2010 Author Report Share Posted October 25, 2010 On 10/25/2010 at 9:13 PM, chenGOD said: Or you could always use the wonderful extension HTTPS everywhere made by the folks over at the EFF in combination with the tor project. Additionally, if you're concerned about privacy there's a good firefox addon called better privacy which is useful. "https everywhere" only works on sites that provide https support on all pages. most don't, unfortunately. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide all signatures WATMM Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444300 Share on other sites More sharing options...
Guest the anonymous forumite Posted October 25, 2010 Report Share Posted October 25, 2010 On 10/25/2010 at 9:35 PM, mcbpete said: On 10/25/2010 at 9:27 PM, the anonymous forumite said: how do you install this .xpi file ? You, erm, click on it ! .xpi installs generally get blocked as default though, you'll probably see a bar has added to the top of the page saying Firefox has prevented this site from installing software. Just click the allow button. Yeah I eventually figured this out but now, when the firefox modules dialog box appears, it says that it's not compatible firefox 3.6 Quote Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444303 Share on other sites More sharing options...
chaosmachine Posted October 25, 2010 Author Report Share Posted October 25, 2010 On 10/25/2010 at 9:24 PM, Joy Rex said: What about WiFi that uses MAC address authentication? I know you can 'spoof' MAC addresses, but I would imagine this can pick up the packets regardless... I would imagine the only 'safe' option is not use WiFi on your personal network. More and more homes are setting up WiFi (I can see about 7-8 networks in my general area, and I would imagine most of those that have 'NONE' listed as the security really are 'NONE' - no MAC addresses, nothing. What if you use OpenDNS? opendns won't help. mac filtering won't help, either. basically, you're reasonably safe using WPA, if you're using a strong passphrase and a unique ssid (ie: "joyrex98765" not "james"). everything else can be bruteforced or pulled out of a precomputed table, and once they have the key, they can read your traffic and steal your sessions. mostly, though, i'd worry a lot more about unencrypted public connections, like starbucks, than i would about someone bruteforcing your home network. if you don't use public wifi, you probably don't need a vpn. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide all signatures WATMM Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444304 Share on other sites More sharing options...
Joyrex Posted October 25, 2010 Report Share Posted October 25, 2010 I wonder if/what Firesheep 'phones home' to it's creator? I'm not installing it, but I bet Little Snitch (Mac) would light up like a Christmas tree with it... Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide all signatures Follow WATMM on Twitter: @WATMMOfficial Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444308 Share on other sites More sharing options...
plstik Posted October 25, 2010 Report Share Posted October 25, 2010 On 10/25/2010 at 9:44 PM, the anonymous forumite said: On 10/25/2010 at 9:35 PM, mcbpete said: On 10/25/2010 at 9:27 PM, the anonymous forumite said: how do you install this .xpi file ? You, erm, click on it ! .xpi installs generally get blocked as default though, you'll probably see a bar has added to the top of the page saying Firefox has prevented this site from installing software. Just click the allow button. Yeah I eventually figured this out but now, when the firefox modules dialog box appears, it says that it's not compatible firefox 3.6 i´ve got firefox 3.6(windows 7) and it installed just fine Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444323 Share on other sites More sharing options...
Guest Babar Posted October 25, 2010 Report Share Posted October 25, 2010 On 10/25/2010 at 8:04 PM, oscillik said: On 10/25/2010 at 8:00 PM, GORDO said: maybe some wireless cards can't do it? much like with air crack that some wifi cards aren't good for it. it used to be the case that not all 802.11b or 802.11g cards could enter promiscuous mode. not too sure if that's changed now, though In my understanding promiscuous mode works on the ip level by redirecting frames that are not destined to your computer to the rest of the system. Monitor mode is similar except that it works on a the wifi protocol level, allowing frames that are not destined to your computer, to be processed further by the ip-level and its pals. As for chen's macbook: your card need to support these modes, which is not the case for all airport cards. So I installed the beast, a nice "firesheep" window/tab showed up but I closed it and now i'm unable to find where it is in the menu. Seriousl ! someone help me. Quote Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444361 Share on other sites More sharing options...
plstik Posted October 25, 2010 Report Share Posted October 25, 2010 (edited) view - sidebar or strg+shift+s Edited October 25, 2010 by plstik Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444363 Share on other sites More sharing options...
Guest Scrambled Ears Posted October 25, 2010 Report Share Posted October 25, 2010 view -> sidebar -> firesheep for me... Quote Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444366 Share on other sites More sharing options...
Guest Babar Posted October 25, 2010 Report Share Posted October 25, 2010 On 10/25/2010 at 9:27 PM, the anonymous forumite said: how do you install this .xpi file ? I couldn't just click on it (i'm on osx), so i opened it from firefox (file>open etc...) And i wasn't able to grab anything interesting. Imo it's because my interface's flags as shown by ifconfig are (when firesheep is running) flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500 while they should read as flags=48943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST,MONITOR> mtu 1500 So no, chengod, you won't be able to steal cookies via passive wifi sniffing because airport's hardware doesn't support it. You can still download backtrack 4, launch it via vmware and use a wifi dongle : it comes with wifizoo preinstalled (=firesheep+). Quote Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444383 Share on other sites More sharing options...
chenGOD Posted October 25, 2010 Report Share Posted October 25, 2010 well thats just gay. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide all signatures 백호야~~~항상에 사랑할거예요.나의 아들. Shout outs to the saracens, musulmen and celestials. Link to comment https://forum.watmm.com/topic/60873-its-not-safe-to-use-public-wifi-without-a-vpn/page/3/#findComment-1444392 Share on other sites More sharing options...
Recommended Posts