FaceNiff for Android Hijacks Facebook Sessions Over WiFi

Engadget reported on a free “research” Android app tool that can intercept web session profiles of computers on a WiFi network.

FaceNiff makes Facebook hacking a portable, one-tap affair (video)

An Android phone needs to be rooted (the Android equivalent of iPhone jailbreaking) in order to use the app. Once installed the app can hijack up to three profiles. A paid unlock code allows it to do more. It is not able to hijack a web session using SSL. However, determining when SSL is used is an interesting question. For example, as of seven months ago, the Facebook for iPhone app used SSL for the login proces but left session cookies unecrypted.

Does the Facebook iPhone app use SSL when logging you in?

You can find more information about FaceNiff at:

http://faceniff.ponury.net/

Related Stories
Mediabistro Course

Social Media 201

Social Media 201Starting October 13Social Media 201 picks up where Social Media 101 left off, to provide you with hands-on instruction for gaining likes, followers, retweets, favorites, pins, and engagement. Social media experts will teach you how to make social media marketing work for your bottom line and achieving your business goals. Register now!