Now lets understand how Firesheep actually works. When you provide your username and password in login forms of different website and submit it, the browser first encrypts the password and then sends it over the network. The corresponding website compares the information against its internal database and if they match, it sends a cookie(a small text file) to your browser. The browser saves this cookie and uses it to authenticate the user on the website every time the user opens a different page of the website. When the user logs out of his account the browser just deletes the cookie. Now the problem is that this cookies are not encrypted before sending over the network, due to this a hacker can capture this cookies and using them authenticate himself as the user from whom the cookie was stolen.
Now lets see how to use Firesheep.
Step 1) First download and install WinPcap (WinPcap in Windows is used for capturing network traffic.)
You can use Pcap in libPcap library for unix like systems.
Step 2) Download and open Firesheep in Firefox, it will automatically install it. Or just drag it and place it
over Firefox shortcut (Firesheep at this instant is not supporting Firefox 4 ).
Step 3) After it is installed, in Firefox go to View -->Sidebar --> Firesheep. A side bar will appear in the
browser with a button "start capturing", press it and sit back. In few seconds you will see account
details with photos of the target. Click on one of it and you will directly enter in his account. Simple
Warning::-All information provided for educational purposes only.
The site is no way responsible for any misuse of the information.