FaceNiff for Android Hijacks Facebook Sessions Over WiFi

Engadget reported on a free “research” Android app tool that can intercept web session profiles of computers on a WiFi network.

FaceNiff makes Facebook hacking a portable, one-tap affair (video)

An Android phone needs to be rooted (the Android equivalent of iPhone jailbreaking) in order to use the app. Once installed the app can hijack up to three profiles. A paid unlock code allows it to do more. It is not able to hijack a web session using SSL. However, determining when SSL is used is an interesting question. For example, as of seven months ago, the Facebook for iPhone app used SSL for the login proces but left session cookies unecrypted.

Does the Facebook iPhone app use SSL when logging you in?

You can find more information about FaceNiff at:

http://faceniff.ponury.net/

Related Stories
Mediabistro Course

Social Media Metrics

Social Media MetricsStarting September 4, work with a social media manager to monitor, measure and optimize your social media efforts! Danielle Brigida will teach your how to sift through web analytics, Facebook Insights, and Twitter mentions to develop a comprehensive reporting and tracking system for your brand. Register now!