<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; extension</title>
	<atom:link href="http://hackaday.com/tag/extension/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 11:18:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; extension</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>Firesheep: Promoting privacy in a scary way</title>
		<link>http://hackaday.com/2010/10/25/firesheep-promoting-privacy-in-a-scary-way/</link>
		<comments>http://hackaday.com/2010/10/25/firesheep-promoting-privacy-in-a-scary-way/#comments</comments>
		<pubDate>Mon, 25 Oct 2010 20:00:39 +0000</pubDate>
		<dc:creator>James Munns</dc:creator>
				<category><![CDATA[security hacks]]></category>
		<category><![CDATA[software hacks]]></category>
		<category><![CDATA[extension]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[firesheep]]></category>
		<category><![CDATA[flickr]]></category>
		<category><![CDATA[plugin]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=29698</guid>
		<description><![CDATA[Often, software hackers are the activists that push software giants towards updating vulnerable applications. In todays example, [Eric Butler] is pushing Facebook, Twitter, Flickr, and more all at the same time. By creating a user script-kiddie friendly extension for Firefox, he has allowed just about anyone to sniff unsecured connections on public Wi-Fi access points [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=29698&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-29699" title="three" src="http://hackadaycom.files.wordpress.com/2010/10/three.png" alt="" width="470" height="267" /></p>
<p>Often, software hackers are the activists that push software giants towards updating vulnerable applications. In todays example, [Eric Butler] is <a href="http://codebutler.com/firesheep">pushing Facebook, Twitter, Flickr, and more</a> all at the same time. By creating a <span style="text-decoration:line-through;">user</span> script-kiddie friendly extension for Firefox, he has allowed just about anyone to sniff unsecured connections on public Wi-Fi access points and log into these unprotected accounts.</p>
<p>Right now <a href="http://codebutler.github.com/firesheep">the extension</a> is available for Windows and Mac, with a Linux port coming soon. Temporarily, the best way for a user to avoid getting taken advantage of would be to not use these social networking sites on a public connection, or to implement a secure proxy for these connections that would keep your data safe. Hopefully these websites will have a quick rebuttal that allows for security without workarounds. With all of the bad press they are recieving, they certainly have incentive to.</p>
<p>Are there any software or security buffs out there? We would love to see someone port this to an iPhone or <a href="http://hackaday.com/2010/07/12/android-development-101-%e2%80%93-a-tutorial-series/">Android app</a> that could check and log open Wi-Fi points. We&#8217;ll leave the foot work to the experts out there, but do be sure to give us a heads up if anyone manages to make it happen, okay?</p>
<br />Filed under: <a href='http://hackaday.com/category/security-hacks/'>security hacks</a>, <a href='http://hackaday.com/category/software-hacks/'>software hacks</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/29698/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/29698/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/29698/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/29698/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/29698/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/29698/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/29698/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/29698/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/29698/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/29698/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/29698/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/29698/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/29698/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/29698/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=29698&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2010/10/25/firesheep-promoting-privacy-in-a-scary-way/feed/</wfw:commentRss>
		<slash:comments>48</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">jahmez</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2010/10/three.png" medium="image">
			<media:title type="html">three</media:title>
		</media:content>
	</item>
		<item>
		<title>Exploit-Me Firefox XSS and SQL scanning addon</title>
		<link>http://hackaday.com/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/</link>
		<comments>http://hackaday.com/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/#comments</comments>
		<pubDate>Sat, 14 Jun 2008 09:40:00 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[cons]]></category>
		<category><![CDATA[firefox hacks]]></category>
		<category><![CDATA[addon]]></category>
		<category><![CDATA[crosssitescripting]]></category>
		<category><![CDATA[dansinclair]]></category>
		<category><![CDATA[extension]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[layerone]]></category>
		<category><![CDATA[layerone2008]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[securitycompass]]></category>
		<category><![CDATA[sql]]></category>
		<category><![CDATA[sqlinjection]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/</guid>
		<description><![CDATA[One of the best tools we saw at LayerOne was the Exploit-Me series presented by [Dan Sinclair]. Security Compass created these tools to help developers easily identify cross site scripting (XSS) and SQL injection vulnerabilities. XSS-Me is a Firefox add-on that loads in the sidebar. It identifies all the input fields on a page and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=1998&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span style="text-align:center; display: block;"><a href="http://hackaday.com/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/"><img src="http://img.youtube.com/vi/RbL2ptbjoSA/2.jpg" alt="" /></a></span><br />One of the best tools we saw at <a href="http://layerone.info/">LayerOne</a> was the <a href="http://www.securitycompass.com/exploitme.shtml">Exploit-Me series</a> presented by [Dan Sinclair]. Security Compass created these tools to help developers easily identify cross site scripting (XSS) and SQL injection vulnerabilities.</p>
<p><span id="more-1998"></span></p>
<p>XSS-Me is a Firefox add-on that loads in the sidebar. It identifies all the input fields on a page and iterates through a user provided <a href="http://ha.ckers.org/xss.html">list of XSS strings</a>: opening new tabs and checking the results. When this process completes you get a report of what attacks got through, what didn&#8217;t, and what might have. The upcoming 0.3 version will use heuristics to determine what characters can be used and automatically skip attack strings that won&#8217;t get through.</p>
<p>The SQL Inject-Me works almost exactly the same way. It does require a little planning though: you need to tell it what you expect the results page to look like when an attack gets through.</p>
<p>The newest tool, Access-Me, surfs along with you while you&#8217;re authenticated to a website and checks whether you can see the same page unauthenticated.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/1998/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/1998/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/1998/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/1998/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/1998/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/1998/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/1998/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/1998/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/1998/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/1998/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/1998/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/1998/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/1998/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/1998/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/1998/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/1998/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=1998&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>
	</item>
	</channel>
</rss>
