A new add-on for the Mozilla Firefox web browser has been introduced, named BlackSheep. Last month, a computer security expert presented another add-on for Mozilla Firefox, called FireSheep, at the ToorCon conference.
This add-on exploits security vulnerabilities related to establishing secure communication with well-known web services such as Facebook and Twitter if the user is connected to an unsecured wireless network. FireSheep intercepts communication to these well-known services and steals cookies, thereby allowing an attacker to take over the communication session. This type of attack has long been known, but with the arrival of the FireSheep tool, it has become accessible even to those with little technical knowledge. The BlackSheep add-on serves to detect the FireSheep add-on on the network and disables its proper functioning by sending fake cookies to the network that FireSheep then unsuccessfully attempts to exploit. Security experts have long recommended that all communication with client computers be secured, not just the part when entering user credentials as is currently standard, but web service owners have not reacted positively to these recommendations since such an approach requires greater computing resources. (www.cert.hr)
