FaceNiff for Android Hijacks Facebook Sessions Over WiFi

Engadget reported on a free “research” Android app tool that can intercept web session profiles of computers on a WiFi network.

FaceNiff makes Facebook hacking a portable, one-tap affair (video)

An Android phone needs to be rooted (the Android equivalent of iPhone jailbreaking) in order to use the app. Once installed the app can hijack up to three profiles. A paid unlock code allows it to do more. It is not able to hijack a web session using SSL. However, determining when SSL is used is an interesting question. For example, as of seven months ago, the Facebook for iPhone app used SSL for the login proces but left session cookies unecrypted.

Does the Facebook iPhone app use SSL when logging you in?

You can find more information about FaceNiff at:

http://faceniff.ponury.net/

Related Stories
Mediabistro Course

Creative Social Branding

Creative Social BrandingLearn how to create social buzz for your brand! Starting November 24, the VP of content strategy at DBA will teach you how to speak and write to different audiences on social platforms, identify and engage with current trends and influencers, and build an excellent social strategy to amplify your numbers and rate engagement. Register now!