Slashdot Log In
Man-in-the-Middle Attack on MySpace with Cain
Posted by
CmdrTaco
on Saturday March 15, @09:00AM
from the caught-with-yer-pants-down dept.
from the caught-with-yer-pants-down dept.
Slimjim100 writes "Last year at ChicagoCon 2007, Brian Wilson gave a great talk entitled "Cain & Abel: Windows Can Hack, Too!" Although the presentation and audio recording of the talk can be downloaded from the ChicagoCon site at Library, I had totally forgotten to publish his videos. Just in case things didn't go as planned during the live event or his laptop crapped out on him, Brian made a video of the MITM attack he demonstrated using Cain. You get to see how Myspace and other social networking sites are not designed with security in mind."
Related Stories
Firehose:Man-in-the-Middle Attack on MySpace with Cain by Anonymous Coward
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading ... Please wait.

Brian Wilson (Score:3, Funny)
Re: (Score:1)
Security? (Score:5, Insightful)
Duh.... (Score:1)
And if they used https? (Score:5, Insightful)
Re: (Score:2)
Also, https means it is actually possible to be secure -- you check
Re: (Score:3, Informative)
Re: (Score:2)
Last week: http://www.theregister.co.uk/2008/03/10/hsbc_cert_glitch/ [theregister.co.uk]
Fortunately, it was not a problem, as people would recognize the site as legitimate anyway. (Well, that's what t
Re: (Score:2)
And you know what, they HEED my advice. They now have a
This is not new (Score:5, Insightful)
What did the notice to Myspace/google etc consist of? I can break things on my local LAN, so fix your site?
If he did this in my office he'd get a tireiron to the head because I could walk over to him and do it.
Re: (Score:2, Interesting)
The point is that, as you observe, it's trivial on many switched LANs to ARP poison and steal session credentials. (It's all about the session, dummy, not the data.) Pinch a Gmail password from a co-worker and you probably own their domain pa
Re: (Score:2)
Re: (Score:2)
When "my local LAN" is some random wifi hotspot, it would be nice to have it not be broken there.
And "fix your site" is as simple as sticking https in front of it. Google has this as an option, anyway.
Do I understand this correctly? (Score:5, Insightful)
How is this a big deal? This does not allow someone to get anyone's password that isn't on their same network. There are easier ways to get someone's password if you're on the same network as them, starting with slapping them until they give you their password. But it all comes back to - if the site matters, it's using HTTPs.
Re: (Score:2)
Cain and Abel aren't new. (Score:4, Informative)
Re: (Score:3, Informative)
Cain has actually progressed by ridiculous leaps and b
Don't use MySpace! (Score:5, Insightful)
But even if they were to use HTTPS, that still wouldn't solve MySpace's issues. A lot of the people on my Friends List were not very tech savvy (like a lot of users), and, since most of them were teens, they easily fell for phishing scams and hacks. And then I get punished for their poor security practices by having my message board filled with ads for the "free, HoTtEsT ringtones!!!!" and "see girls naked!!!!" (btw all of those sites had viruses or malware on them). I stopped using MySpace after 2 months, I got tired of all the insecurity.
If I were to run this attack on the computers at my high school, I could cripple a lot of kid's social lives (and get expelled when the admins see
Kids these days are just not educated enough on good security practices, or show a lack of common sense with this stuff...
Re: (Score:2)
Surprised?? (Score:3, Insightful)
Re: (Score:2)
Let's say I discovered you had logged on to Facebook with the username of "fluch" and a password of "blather". The next thing I'm going to try is to log on to gmail and try signing on as "fluch@gmail.com" with
It gets better (Score:5, Insightful)
Re: (Score:2)
banks. (Score:2)
Take the Chase.com [chase.com] homepage. It's got a login form right there (it doesn't matter if it's secure or not). If you were a victim of a man in the mi
Re: (Score:2)