What's with all the judging... without really spoonfeeding, iTpHo3NiX is correct - there are many things you can do, sniffing traffic with Cain&Abel (windows) or Ettercap (linux) works good if you just want facebook sessions.
As for "hacking in", well that's a bit harder - you need to find open services and go through them, but this doesn't usually work for home computers. You could however perform MITM and redirect traffic to your own proxy which would feed her with malware downloads/driveby.