Final Thoughts
The release of Firesheep is more than just a software threat. It highlights an underlying flaw in the way many web applications conduct session management. While there are temporary solutions you can implement to limit the short-term damage done by the release of this tool, it's imperative that the web application community band together and develop long-term solutions that resolve the significant design vulnerabilities which make session hijacking attacks possible. Otherwise, we'll be just as vulnerable when the next tool rolls out.