FireShepherd is the antidote for Firesheep hacking mania
borntechie.com
borntechie.com
(But looking at the code, all this thing does is reimplement wget poorly. It sends an HTTP request to a hard-coded "random facebook server" with a confusingly-long Facebook cookie. That's it, that's all it does. Firesheep may have an input validation issue in the current version, but that is a correctness issue that will be fixed immediately. Then this thing does nothing.)
Has no one told them the importance of using contextual links rather than links like <a href="#">Click here</a> to download awesome-crap-0.0.1.zip. This is almost as annoying as when they have links that just link to a self-site-search for the term.
Ugh.
Your position is laughable at best - you're saying "but think of the users" (you're lagging their connections) and "think of the facebook" (you're wasting their resources) when your own software treats both parties far worse at least in the short term.
Suggesting that an HTTP GET set twice a second to a server that will return a 404 will somehow have a measurable effect on the performance of a public network like a starbucks hotspot is beyond ridiculous. Since a days worth of that traffic would be dwarfed by a single user playing a single 5 second low quality youtube clip - the evidence suggests you either lack a fundamental understanding of practical networking or you're simply trying to trick people into disliking a tool (that attacks your tool).
As far as your concern about facebook's resources, it seems highly disingenuous in light of the fact that your tool automatically makes a series of two or more http requests (that generate real, dynamic responses) to any site (including facebook) you include a handler for any time it sees a new session on the wire. Without any consent, including hijacked session cookies, even if the firesheep user never once clicks to hijack it.
You have every right to release whatever wannabe click2pwn tools you want. You even have a fair point about session infrastructure, though you made it with all the subtlety of a wrecking ball.
You just look like an idiot, though, when you try cry about someone else's tool claiming injury to the very users and sites your own tool victimizes.
You should grow a much thicker skin if you want to play big boy security researcher.
Similar idea to FireShephard: "BlackSheep, also a Firefox plugin is designed to combat Firesheep. BlackSheep does this by dropping ‘fake’ session ID information on the wire and then monitors traffic to see if it has been hijacked. While Firesheep is largely passive, once it identifies session information for a targeted domain, it then makes a subsequent request to that same domain, using the hijacked session information in order to obtain the name of the hijacked user along with an image of the person, if available. It is this request that BlackSheep identifies in order to detect the presence of Firesheep on the network. When identified, the user will be receive [a] warning message:"