http://codebutler.com/firesheepQuote
It's extremely common for websites to protect your password by encrypting the initial login, but surprisingly uncommon for websites to encrypt everything else. This leaves the cookie (and the user) vulnerable. HTTP session hijacking (sometimes called "sidejacking") is when an attacker gets a hold of a user's cookie, allowing them to do anything the user can do on a particular website. On an open wireless network, cookies are basically shouted through the air, making these attacks extremely easy.
Today at Toorcon 12 I announced the release of Firesheep, a Firefox extension designed to demonstrate just how serious this problem is.
After installing the extension you'll see a new sidebar. Connect to any busy open wifi network and click the big "Start Capturing" button. Then wait.
As soon as anyone on the network visits an insecure website known to Firesheep, their name and photo will be displayed:
Double-click on someone, and you're instantly logged in as them.
Firesheep is free, open source, and is available now for Mac OS X and Windows. Linux support is on the way.
Quote
ndebord
The following FireFox extensions are supposed to make that browser safe by forcing SSL and HTTPS.
Will they work with K-Meleon?
...
The bad news is that they only work with Firefox.
There are, to the best of my knowledge, no such add-ons for Internet Explorer, Chrome, Safari, or Opera. If anyone knows of some, I’d love to hear about them.
Quote
guenter
Quote
ndebord
The following FireFox extensions are supposed to make that browser safe by forcing SSL and HTTPS.
Will they work with K-Meleon?
...
The bad news is that they only work with Firefox.
There are, to the best of my knowledge, no such add-ons for Internet Explorer, Chrome, Safari, or Opera. If anyone knows of some, I’d love to hear about them.
Nobody here cares if anything is not available for IE and Safari
Who told You they work only on FF? :O
To me the interface of e.g. Force TLS looks pretty much like the self contained XUL-Window type that we use in a number of other K-Meleon ports.
4 K-Meleon: You got to try. Unpack the xpi. Install the software prerequisites...
Quote
guenter
To me the interface of e.g. Force TLS looks pretty much like the self contained XUL-Window type that we use in a number of other K-Meleon ports.