Football Fans: Download the 2012 Schedule App from Google Play!


Go Back   Android Forums > Android Discussion > Android Applications

Android Applications All the information you could ever want about Android Applications. Learn about apps and get help with them... all here! New apps can be found and announced in the Applications Announcements forum linked below.



Closed Thread
 
LinkBack Thread Tools
Old April 18th, 2011, 04:11 PM   #1 (permalink)
New Member
 
Join Date: Jun 2010
Posts: 9
 
Device(s):
Thanks: 0
Thanked 1 Time in 1 Post
Surprised Facebook session hijacker

Hi there, I've written an app that allows hijacking facebook sessions over WiFi.

It works only with accounts not using SSL, and it doesn't work with WPA-EAP. It can break internet connection and a lot of other stuff so use on your own risk.

It can and probably will use a LOT of CPU since it diverts all network traffic through your device and analyses every packet (not completely true).

*** ROOT IS REQUIRED ***

I have a confirmation it works on Desire, Desire HD and Galaxy S. I personally use it on Desire with CM7.

It has few bugs and if something breaks or not work please let me know I'll try to fix it.

The app is limited to switch between only 3 profiles. If you need more you can get activation key from paypal when asked for.

Okey the link to app is here: \

DISCLAIMER: I am not responsible for any damage you would make with this app. It's completely up to you.

ponury is offline  
Last edited by woop; April 20th, 2011 at 02:34 AM.
The Following User Says Thank You to ponury For This Useful Post:
steslatt (April 21st, 2011)
Sponsors
Old April 18th, 2011, 04:19 PM   #2 (permalink)
 
Join Date: Apr 2010
Posts: 5,873
 
Device(s):
Thanks: 0
Thanked 626 Times in 534 Posts
Default

Wow, this sounds REAL legal...
sitlet is offline  
Old April 18th, 2011, 04:23 PM   #3 (permalink)
New Member
 
Join Date: Jun 2010
Posts: 9
 
Device(s):
Thanks: 0
Thanked 1 Time in 1 Post
Default

Quote:
Originally Posted by sitlet View Post
Wow, this sounds REAL legal...
I'm not forcing you to use it. Maybe this way people will start using SSL or at least facebook will switch it on by default.
ponury is offline  
Old April 18th, 2011, 04:44 PM   #4 (permalink)
Member
 
AmneonX's Avatar
 
Join Date: Jun 2010
Location: Michigan
Posts: 343
 
Device(s): Samsung Galaxy Nexus, Samsung Galaxy Tab on CM9, Motorola Droid X(Retired), Sony Ericcson Xperia Pla
Thanks: 23
Thanked 34 Times in 27 Posts
mgilland87@gmail.com
Default

I can see how this would be useful. Use this to show what can happen on a public network.
AmneonX is offline  
Last edited by AmneonX; April 18th, 2011 at 04:46 PM. Reason: spelling
Old April 18th, 2011, 05:15 PM   #5 (permalink)
New Member
 
Join Date: Jun 2010
Posts: 9
 
Device(s):
Thanks: 0
Thanked 1 Time in 1 Post
Default

Quote:
Originally Posted by AmneonX View Post
I can see how this would be useful. Use this to show what can happen on a public network.
Exactly! People are completely unaware that public internet is totally unsafe. FB isn't better they've added SSL option but still only a few people know what it does and why to use it. They should enable it for everyone.
ponury is offline  
Last edited by ponury; April 18th, 2011 at 06:14 PM.
Old April 18th, 2011, 06:34 PM   #6 (permalink)
Member
 
AmneonX's Avatar
 
Join Date: Jun 2010
Location: Michigan
Posts: 343
 
Device(s): Samsung Galaxy Nexus, Samsung Galaxy Tab on CM9, Motorola Droid X(Retired), Sony Ericcson Xperia Pla
Thanks: 23
Thanked 34 Times in 27 Posts
mgilland87@gmail.com
Default

However it wouldnt work for me. I tried it on my moms network.
AmneonX is offline  
Old April 19th, 2011, 12:28 AM   #7 (permalink)
Member
 
ambientdroid's Avatar
 
Join Date: Jan 2011
Location: Japan
Posts: 248
 
Device(s): Toshiba Regza T-01C (Docomo Network)
Thanks: 14
Thanked 9 Times in 9 Posts
Default

Quote:
Originally Posted by ponury View Post
Exactly! People are completely unaware that public internet is totally unsafe. FB isn't better they've added SSL option but still only a few people know what it does and why to use it. They should enable it for everyone.
OH! so you're not encouraging illegal activity; you're providing a public service!

Thanks makes it ok then.

ambientdroid is offline  
Old April 19th, 2011, 03:08 AM   #8 (permalink)
New Member
 
Join Date: Jun 2010
Posts: 9
 
Device(s):
Thanks: 0
Thanked 1 Time in 1 Post
Default

Quote:
Originally Posted by ambientdroid View Post
OH! so you're not encouraging illegal activity; you're providing a public service!

Thanks makes it ok then.

Yes... and you didn't just now enabled SSL on your account right? And did it also on your's girlfriend/roommate pc.
ponury is offline  
Old April 19th, 2011, 06:35 AM   #9 (permalink)
Member
 
ambientdroid's Avatar
 
Join Date: Jan 2011
Location: Japan
Posts: 248
 
Device(s): Toshiba Regza T-01C (Docomo Network)
Thanks: 14
Thanked 9 Times in 9 Posts
Default

Quote:
Originally Posted by ponury View Post
Yes... and you didn't just now enabled SSL on your account right? And did it also on your's girlfriend/roommate pc.
If only there were more people like you!!!1!

you've given me a great idea: I think more people should upgrade their old door locks to newer, safer ones that are more resistant to being picked. So, I'm going to make a bunch of skeleton keys for the old locks and give them away for free!
Disclaimer: I'm not responsible for any illegal raping and killing you might do.
ambientdroid is offline  
Old April 19th, 2011, 07:04 AM   #10 (permalink)
Member
 
AmneonX's Avatar
 
Join Date: Jun 2010
Location: Michigan
Posts: 343
 
Device(s): Samsung Galaxy Nexus, Samsung Galaxy Tab on CM9, Motorola Droid X(Retired), Sony Ericcson Xperia Pla
Thanks: 23
Thanked 34 Times in 27 Posts
mgilland87@gmail.com
Default

Now in all fairness this is a good idea. I was going to hold a seminar on home network security this summer, and if I was able to use this to show more dangers of unprotected networks I feel it would be a better experience for everyone.

I kept getting an access denied error though. When I first powered the app on. That could've been the encryption though, forgot about that part.
AmneonX is offline  
Last edited by AmneonX; April 19th, 2011 at 07:08 AM.
Sponsors
Old April 19th, 2011, 09:17 AM   #11 (permalink)
New Member
 
Join Date: Jun 2010
Posts: 9
 
Device(s):
Thanks: 0
Thanked 1 Time in 1 Post
Default

Quote:
Originally Posted by ambientdroid View Post
If only there were more people like you!!!1!

you've given me a great idea: I think more people should upgrade their old door locks to newer, safer ones that are more resistant to being picked. So, I'm going to make a bunch of skeleton keys for the old locks and give them away for free!
Disclaimer: I'm not responsible for any illegal raping and killing you might do.
You know this technique is few years old at least. I'm not inventing anything here. And if someone could tell you: "hey click here - it's free - and you'll be safe because now anyone could break into your house" wouldn't you want that? That's how the progress is made you know. A long time ago some Neanderthal came to another and said: "dude, look if you don't put this stone in front of your cave a bear can get there and eat you!". But that caveman was You! And you said: "You asshole you just want to get me killed by saying that my open door is unsafe!" And that's exactly why we don't see Neanderthal people around here these days.


Quote:
Originally Posted by AmneonX View Post
Now in all fairness this is a good idea. I was going to hold a seminar on home network security this summer, and if I was able to use this to show more dangers of unprotected networks I feel it would be a better experience for everyone.

I kept getting an access denied error though. When I first powered the app on. That could've been the encryption though, forgot about that part.
I am positive that it works on CM7. You need exec on /data and "iptables" and "su" installed. But somehow it isn't working on darkys 10rc4 rom. Also it won't work if moved/installed to SD (giving mount -o remount,exec /sdcard could help though). Try mount -o remount,exec /data and you could send me logcat of this. About encryption if you are referring to wifi encryption it only doesn't work on enterprise networks (WPA-EAP) and switches that have static arp table (very uncommon).
ponury is offline  
Old April 19th, 2011, 06:01 PM   #12 (permalink)
Member
 
HJAcevedo's Avatar
 
Join Date: Mar 2011
Location: Brooklyn, NY
Posts: 232
 
Device(s): Samsung Galaxy S II, Xoom, mytouch4g (rooted/retired)
Thanks: 37
Thanked 17 Times in 12 Posts
HectorJesusAcevedo
Default

Quote:
Originally Posted by ponury View Post
You know this technique is few years old at least. I'm not inventing anything here. And if someone could tell you: "hey click here - it's free - and you'll be safe because now anyone could break into your house" wouldn't you want that? That's how the progress is made you know. A long time ago some Neanderthal came to another and said: "dude, look if you don't put this stone in front of your cave a bear can get there and eat you!". But that caveman was You! And you said: "You asshole you just want to get me killed by saying that my open door is unsafe!" And that's exactly why we don't see Neanderthal people around here these days.

I'm...not quite sure that's the same thing here. You're not only telling the people "hey if you don't put a stone on your door a bear will eat you", you're bringing the bear TO the opening to let the bear do the killing in the first place.

Either way this analogy is ridiculous. The argument is ridiculous. If I'm understanding this correctly this is basically an app where you can access someone elses personal information. I hope I'm wrong here because if no one sees something wrong with that then HOT DAMN what is society coming to today?
HJAcevedo is offline  
Old April 19th, 2011, 06:10 PM   #13 (permalink)
New Member
 
Join Date: Jun 2010
Posts: 9
 
Device(s):
Thanks: 0
Thanked 1 Time in 1 Post
Default

From my point of view I would prefer to be warned by a friend or some prankster that would leave "I'm stupid" on my wall then be "hacked" by some advertising company that would just set a guy with a laptop that would grab all my personal info and use it to spam me and do other potentially more harmful things. When I told my girlfriend to enable ssl she didn't because "some of the fb apps don't work with it". But after I showed her how easily someone could just read her messages the apps somehow didn't matter. I'm not going to say "yey! it's only for good" of course it's not. It depends on you how you use it.
ponury is offline  
Old April 19th, 2011, 07:51 PM   #14 (permalink)
Member
 
HJAcevedo's Avatar
 
Join Date: Mar 2011
Location: Brooklyn, NY
Posts: 232
 
Device(s): Samsung Galaxy S II, Xoom, mytouch4g (rooted/retired)
Thanks: 37
Thanked 17 Times in 12 Posts
HectorJesusAcevedo
Default

That's great if your friend is the one doing it. I'm sure some people will grab this app and sit somewhere just waiting for the chance to log into someones facebook.
HJAcevedo is offline  
Old April 19th, 2011, 08:11 PM   #15 (permalink)
Senior Member
 
amlothi's Avatar
 
Join Date: Jul 2010
Posts: 1,170
 
Device(s):
Thanks: 33
Thanked 189 Times in 149 Posts
Default

An app that demonstrates the lack of security in a responsible manner, without actually enabling full access to someone else's account, would be a public service.


This is a tool for illegal activity, attempting to masquerade as public service. Don't let yourself be mislead.
__________________
Please search the forums.
Need Tasker Help?
Having Battery problems?
amlothi is offline  
Old April 19th, 2011, 11:05 PM   #16 (permalink)
novacane (OFWGKTA)
 
woop's Avatar
 
Join Date: Feb 2010
Location: The land of palm trees, sunny skies, and sandy beaches
Posts: 5,172
 
Device(s): HTC Droid Incredible
Thanks: 790
Thanked 1,559 Times in 782 Posts
Default

Due to the malicious possibility of this application (and the fact that this thread has basically derailed and essentially is just arguing) I'm closing this
__________________
GOOD posts:
BAD posts:



PLEASE READ ME!
woop is offline  
The Following User Says Thank You to woop For This Useful Post:
Intruder (April 20th, 2011)
Closed Thread

Bookmarks

Tags
facebook, hack, hijack, sniff


Go Back   Android Forums > Android Discussion > Android Applications User CP
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -5. The time now is 11:49 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Custom vBulletin Skins by: Relivo