FaceNiff 2.x FINAL release thread

Post Reply
TymmyDee
Posts: 6
Joined: Mon Oct 03, 2011 5:41 pm

Re: FaceNiff 2.x FINAL release thread

Post by TymmyDee » Thu Dec 01, 2011 12:52 pm

Would it be possible to show the password or part password without the SSL strip for users that are not using SSL?
Would this also capture password on the fly?
Just an idea. Haven't had much luck with using the SSL strip. Users are normally already logged in when log on.
Thanks.


User avatar
ponury
Posts: 1199
Joined: Fri Sep 23, 2011 11:19 pm
Location: Poland
Contact:

Re: FaceNiff 2.x FINAL release thread

Post by ponury » Thu Dec 01, 2011 6:57 pm

TymmyDee wrote:Would it be possible to show the password or part password without the SSL strip for users that are not using SSL?
Would this also capture password on the fly?
Just an idea. Haven't had much luck with using the SSL strip. Users are normally already logged in when log on.
Thanks.
No, the password is sent only upon login and only via SSL (users preferences doesn't matter here)

User avatar
xXdeadshotXx
Posts: 6
Joined: Sat Sep 24, 2011 4:52 pm

Re: FaceNiff 2.x FINAL release thread

Post by xXdeadshotXx » Thu Dec 01, 2011 8:13 pm

ponury wrote:WIthout the original password you are not able to change the password to something new. So you can't steal the account. You can only modify it's content but with password you could deny the user access to his own profile. With weak passwords you'll guess what the password is either way.
^^ That! :D

raymund160
Posts: 4
Joined: Wed Oct 12, 2011 9:56 am

Re: FaceNiff 2.x FINAL release thread

Post by raymund160 » Sat Dec 03, 2011 12:40 am

javipkt wrote:Hi,

I have two suggestions:

1 - When Faceniif capture a Tuenti session, the browser redirects to the website for PC, which makes it very difficult to enter the site at times. Would be better if the browser redirects to the mobile version.

2 - Could you implement a generic mode as Droidsheep? --> [Cutcutcut, marketing]

Thanks!
Generic mode would be awesome :lol:

k4p741nkrunch
Posts: 1
Joined: Tue Dec 13, 2011 10:13 pm

Re: FaceNiff 2.x FINAL release thread

Post by k4p741nkrunch » Tue Dec 13, 2011 10:25 pm

Hey Ponury!

Just wanted to stop back in and tell you great work on the final release. Just picked it up today. The interface is smooth, and the automatic request of the key really makes it easy! I'm constantly swapping roms and changing kernels and that device ID was always a pain. Now it's right there in front of you! Thanks! I tested out the SSLstrip and it's working great. Awesome implementation. Just wanted to stop by and show my appreciation for your work. I've been a paid user of the app since I first heard about it, but I think a few words can be worth more.

Cheers!
~k4p741n

User avatar
ponury
Posts: 1199
Joined: Fri Sep 23, 2011 11:19 pm
Location: Poland
Contact:

Re: FaceNiff 2.x FINAL release thread

Post by ponury » Tue Dec 13, 2011 11:29 pm

k4p741nkrunch wrote:Hey Ponury!

Just wanted to stop back in and tell you great work on the final release. Just picked it up today. The interface is smooth, and the automatic request of the key really makes it easy! I'm constantly swapping roms and changing kernels and that device ID was always a pain. Now it's right there in front of you! Thanks! I tested out the SSLstrip and it's working great. Awesome implementation. Just wanted to stop by and show my appreciation for your work. I've been a paid user of the app since I first heard about it, but I think a few words can be worth more.

Cheers!
~k4p741n
Thanks :D I'll start working on a new release soon...

Rosa Elefant
Posts: 35
Joined: Fri Sep 30, 2011 8:13 am

Re: FaceNiff 2.x FINAL release thread

Post by Rosa Elefant » Sat Dec 17, 2011 7:55 pm

Weird: SchuelerVZ.net sessions are not detected. DroidSheep does.

User avatar
ponury
Posts: 1199
Joined: Fri Sep 23, 2011 11:19 pm
Location: Poland
Contact:

Re: FaceNiff 2.x FINAL release thread

Post by ponury » Sat Dec 17, 2011 8:06 pm

Rosa Elefant wrote:Weird: SchuelerVZ.net sessions are not detected. DroidSheep does.
Not on domain list. Maybe I'll add generic mode when I have more time :-)

Rosa Elefant
Posts: 35
Joined: Fri Sep 30, 2011 8:13 am

Re: FaceNiff 2.x FINAL release thread

Post by Rosa Elefant » Sat Dec 17, 2011 8:17 pm

Ahh, that's why. Thought it was on back in the days. Sorry!

retnuo
Posts: 3
Joined: Thu Dec 01, 2011 8:48 am

Re: FaceNiff 2.x FINAL release thread

Post by retnuo » Tue Dec 20, 2011 3:27 am

Ponury, thank you for a fantastic app. It gives me an added edge for implementing more secure measures for my employers network. Plus, giving me an idea of who's working and who's playing :) More people are using their mobile devices to access facebook, etc. more often though. I saw it mentioned in a past post, but will you be adding a way to read the default SSL from mobile devices in a future build?

Post Reply