[+] Wayc0de's Blog[+]

29/07/11

FaceNiff – Taking FireSheep Mobile – Sniff & Intercept Web Sessions With Android

FaceNiff is an Android app that allows you to sniff and intercept web session profiles over the WiFi that your mobile is connected to.

It is possible to hijack sessions only when WiFi is not using EAP, but it should work over any private networks (Open/WEP/WPA-PSK/WPA2-PSK)
It's kind of like Firesheep for android. Maybe a bit easier to use (and it works on WPA2!).

*** ROOTED PHONE ***
is required. Please note that if webuser uses SSL this application won't work.
This application due to its nature is very phone-dependant so please let me know if it won't work for You

Use with stock browser (might not work with other)

Legal notice: this application is for educational purposes only. Do not try to use it if it's not legal in your country.
 
I do not take any responsibility for anything you do using this application. Use at your own risk

This apk is limited to use only 3 hijacked profiles, if you want more - you will need activation code - contact me if you're interested.

DONATIONS/ACTIVATION CODES CAN BE BOUGHT USING BITCOIN - 1Lp9C3NXiR7tF28rTN8t31xmKLBPaThXLG


NEW 2.0 RELEASE: FaceNiff-2.0-alpha9.apk

OLD RELEASE: FaceNiff-1.9.4.apk


Any questions? - Look at forum here: http://faceniff.freeforums.org How to secure yourself: LINK
UPDATES
  • 03-06-2011 (v1.9.4): fixed a bug when the app crashed network on some roms
  • 03-06-2011 (v1.9.3): bugfix release if the app works for you - don't upgrade. If the app isn't working you should uninstall the old one and use this.
  • 02-06-2011 (v1.9.2): *** UNINSTALL OLD APK ***
    • Amazon.com support
    • Sniffing all supported services at the same time!
    • Added option to clear list of sniffed profiles
    • fixed name resolving for Nasza-Klasa
    • a lot of bugfixes
  • 25-05-2011 (v1.9.1): way too many updates!, fixed a bug when unlocked app wasn't working, sorry for all that trouble...
  • 25-05-2011 (v1.9): added stealth mode which tries to bypass router anti-arpspoof protection,
    use it only when you don't see any profiles appearing in the profile list (stealth mode is much much slower) (thanks goto: karololszak)
  • 25-05-2011 (v1.8.2): fixed bug when some devices couldn't buy app, added Nasza-Klasa support
  • 24-05-2011 (v1.8.1): fixed twitter support, redesigned ui, added YouTube support
  • 24-05-2011 (v1.8): *** UNINSTALL OLD APP FIRST *** So much changed I skipped a number!
    • total code rewrite! more reliable, more stable and most of all - new updates will be easier for me to code
    • now app works as a service so only explicit poweroff will shut it down
    • wakelock - phone won't go off when sniffing for profiles
    • fixed a bug when profiles showed up as "Unknown"
    • support for twitter! (unlocked version only) - please send me request for other services I'll add them ASAP
    • browse profiles from PC! (unlocked version only) - you can now use your PC at home to log onto sniffed profiles
  • 20-05-2011 (v1.6.1): fixed FC when switching screens (thanks Matt!)
  • 20-05-2011 (v1.6): code cleanup + when wifi disconnects you will get a message about it (that was annoying)
  • 07-05-2011 (v1.5b): during update somehow Permission Denied bug reappeared, this update fixes it (I hope)
  • 02-05-2011 (v1.5): fixed a bug when some devices couldn't buy an app from PP, if you encounter any problems please uninstall, *re-download* and install again
  • 30-04-2011 (v1.4): *** UNINSTALL OLD APP FIRST ***
    • fixed arp bug now hijacking should be more continuous and reliable.
    • fixed name resolving problem that occur if hijacked invalid session
  • 19-04-2011 (v1.3): lowered cpu usage + few bug fixes. (you will need to reinstall)
  • 18-04-2011 (v1.2): fixed Permission Denied bug (thanks G.)

Thanks to Lukasz You can see how it works here: http://www.youtube.com/watch?v=3bgwVM7t_s4


Supported services: (new coming soon)
  • FaceBook
  • Twitter
  • Youtube
  • Amazon
  • VKontakte
  • Tumblr
  • MySpace
  • Tuenti
  • MeinVZ/StudiVZ
  • blogger
  • Nasza-Klasa
Confirmed to work on:
If you have any questions please look at the forum first: http://faceniff.freeforums.org
  If you want to contact me look here: http://ponury.net/contact
 
If you didn't get the Key for the app after buying please check spam, if it's not there then click "Buy" again - it will redirect you to a page with your key. In case everything fails - contact me we'll figure this out


video tutorial 

nb : darknet

1 komentar:

  1. Hey Everybody,

    Below are the most recommended bitcoin exchange services (Bitcoin for CASH):
    Coinbase: $1 min. exchange
    CoinMama

    Get free BITCOINS with the best Bitcoin faucet rotator:
    BTC Faucet Rotator

    BalasHapus