Educause Security Discussion mailing list archives
Re: Firesheep/Cain& Able
From: Isac Balder <piis8 () YAHOO COM>
Date: Mon, 1 Nov 2010 09:39:09 -0700
If you like to fight fire with fire there is fireshepherd.http://notendur.hi.is/~gas15/FireShepherd/ What should be routing best practices, disable arp poisoning. (or at least detect and mitigate against)On Cisco 'ip arp inspection vlan 1'http://www.enterprisenetworkingplanet.com/netsecur/article.php/3462211/Configure-Your-Catalyst-for-a-More-Secure-Layer-2.htm Inform and educate users of sites that allow CSRF, XSS, etc. I.B. "top posting cause yahoo makes me..." --- On Mon, 11/1/10, Hudson, Edward <ewhudson () CSUCHICO EDU> wrote: From: Hudson, Edward <ewhudson () CSUCHICO EDU> Subject: [SECURITY] Firesheep/Cain& Able To: SECURITY () LISTSERV EDUCAUSE EDU Date: Monday, November 1, 2010, 10:40 AM In light of the recent attention to “Firesheep” I am wondering if anyone is having issues and how they are addressing? When used in conjunction with “Cain&Able” it appears able to sniff both wired and wireless traffic for login credentials and execute ARP Poisoning. TIA EH Ed Hudson, CISM Information Security Office California State University, Chico www.csuchico.edu/ires/security Office: (530) 898-6307 Cell: 707-799-3250 ewhudson () csuchico edu
Current thread:
- Firesheep/Cain& Able Hudson, Edward (Nov 01)
- Re: Firesheep/Cain& Able SCHALIP, MICHAEL (Nov 01)
- Re: Firesheep/Cain& Able Michael Horne (Nov 01)
- Re: Firesheep/Cain& Able Isac Balder (Nov 01)
- Re: Firesheep/Cain& Able Valdis Kletnieks (Nov 01)
- Re: Firesheep/Cain& Able David Gillett (Nov 03)
- Re: Firesheep/Cain& Able Foerst, Daniel P. (Nov 02)
- Re: Firesheep/Cain& Able Webb, Justin (Nov 02)
- Re: Firesheep/Cain& Able Greg Williams (Nov 02)
- Re: Firesheep/Cain& Able Alex Keller (Nov 02)
- Re: Firesheep/Cain& Able Valdis Kletnieks (Nov 01)
- <Possible follow-ups>
- Re: Firesheep/Cain& Able John Ladwig (Nov 01)
- Re: Firesheep/Cain& Able John Ladwig (Nov 02)
- Re: Firesheep/Cain& Able Matt Giannetto (Nov 03)
