DATAXPLOIT

Learn-Hack-Secure-XploiT

Turning Firefox To An Ethical Hacking Platform.

Posted by (-)AX0R M3. On December - 31 - 2011
  HostZilla Cloud Web Hosting

3jokes firefox wallpaper 12 250x200 Turning Firefox To An Ethical Hacking Platform.

 

 

 

 

 

 

 

Internet is an amazing virtual world where you can “virtually” do anything : gambling, playing, watching movies, shopping, working, “VoIPying”, spying other people and for sure auditing remote systems.

The security testers community has a large panel of security tools, methodologies and much more to perform their pentests and audit assessments. But what happens if you find yourself weaponless.

No more Top 100 security tools, no more LiveCDs and no more exploitation frameworks. A security auditor without toolbox is like a cop without gun.

Nevertherless, there is maybe a way to rescue yourself from this nightmare situation.

The magical solution could be Firefox and its extensions developed by ethical hackers and coders.

Here is an updated list of useful security auditing extensions :

puce 68c92 Turning Firefox To An Ethical Hacking Platform. Information gathering

  • Whois and geo-location
    • ShowIP : Show the IP address of the current page in the status bar. It also allows querying custom services by IP (right mouse button) and Hostname (left mouse button), like whois, netcraft.
    • Shazou : The product called Shazou (pronounced Shazoo it is Japanese for mapping) enables the user with one-click to map and geo-locate any website they are currently viewing.
    • HostIP.info Geolocation : Displays Geolocation information for a website using hostip.info data. Works with all versions of Firefox.
    • Active Whois : Starting Active Whois to get details about any Web site owner and its host server.
    • Bibirmer Toolbar : An all-in-one extension. But auditors need to play with the toolbox. It includes ( WhoIs, DNS Report, Geolocation , Traceroute , Ping ). Very useful for information gathering phase
  • Enumeration / fingerprinting
    • Header Spy: Shows HTTP headers on statusbar
    • Header Monitor : This is Firefox extension for display on statusbar panel any HTTP response header of top level document returned by a web server. Example: Server (by default), Content-Encoding, Content-Type, X-Powered-By and others.
  • Social engineering
    • People Search and Public Record: This Firefox extension is a handy menu tool for investigators, reporters, legal professionals, real estate agents, online researchers and anyone interested in doing their own basic people searches and public record lookups as well as background research.
  • Googling and spidering
    • Advanced dork : Gives quick access to Google’s Advanced Operators directly from the context menu. This could be used to scan for hidden files or narrow in a target anonymously (via the scroogle.org option) [Updated Definition. Thanks to CP author of Advanced Dork]
    • SpiderZilla : Spiderzilla is an easy-to-use website mirror utility, based on Httrack from www.httrack.com.
    • View Dependencies : View Dependencies adds a tab to the “page info” window, in which it lists all the files which were loaded to show the current page. (useful for a spidering technique)

puce 68c92 Turning Firefox To An Ethical Hacking Platform. Security Assessment / Code auditing

  • Editors
    • JSView : The ’view page source’ menu item now opens files based on the behavior you choose in the jsview options. This allows you to open the source code of any web page in a new tab or in an external editor.
    • Cert Viewer Plus : Adds two options to the certificate viewer in Firefox or Thunderbird: an X.509 certificate can either be displayed in PEM format (Base64/RFC 1421, opens in a new window) or saved to a file (in PEM or DER format – and PKCS#7 provided that the respective patch has been applied – cf.
    • Firebug : Firebug integrates with Firefox to put a wealth of development tools at your fingertips while you browse. You can edit, debug, and monitor CSS, HTML, and JavaScript live in any web page
    • XML Developer Toolbar:allows XML Developer’s use of standard tools all from your browser.
  • Headers manipulation
    • HeaderMonitor : This is Firefox extension for display on statusbar panel any HTTP response header of top level document returned by a web server. Example: Server (by default), Content-Encoding, Content-Type, X-Powered-By and others.
    • RefControl : Control what gets sent as the HTTP Referer on a per-site basis.
    • User Agent Switcher :Adds a menu and a toolbar button to switch the user agent of the browser
  • Cookies manipulation
    • Add N Edit Cookies : Cookie Editor that allows you add and edit “session” and saved cookies.
    • CookieSwap : CookieSwap is an extension that enables you to maintain numerous sets or “profiles” of cookies that you can quickly swap between while browsing
    • httpOnly : Adds httpOnly cookie support to Firefox by encrypting cookies marked as httpOnly on the browser side
    • Allcookies : Dumps ALL cookies (including session cookies) to Firefox standard cookies.txt file
  • Security auditing
    • HackBar : This toolbar will help you in testing sql injections, XSS holes and site security. It is NOT a tool for executing standard exploits and it will NOT learn you how to hack a site. Its main purpose is to help a developer do security audits on his code.
    • Tamper Data : Use tamperdata to view and modify HTTP/HTTPS headers and post parameters.
    • Chickenfoot : Chickenfoot is a Firefox extension that puts a programming environment in the browser’s sidebar so you can write scripts to manipulate web pages and automate web browsing. In Chickenfoot, scripts are written in a superset of Javascript that includes special functions specific to web tasks.

puce 68c92 Turning Firefox To An Ethical Hacking Platform. Proxy/web utilities

  • FoxyProxy : FoxyProxy is an advanced proxy management tool that completely replaces Firefox’s proxy configuration. It offers more features than SwitchProxy, ProxyButton, QuickProxy, xyzproxy, ProxyTex, etc
  • SwitchProxy: SwitchProxy lets you manage and switch between multiple proxy configurations quickly and easily. You can also use it as an anonymizer to protect your computer from prying eyes
  • POW (Plain Old WebServer) : The Plain Old Webserver uses Server-side Javascript (SJS) to run a server inside your browser. Use it to distribute files from your browser. It supports Server-side JS, GET, POST, uploads, Cookies, SQLite and AJAX. It has security features to password-protect your site. Users have created a wiki, chat room and search engine using SJS.

puce 68c92 Turning Firefox To An Ethical Hacking Platform. Misc

  • Hacks for fun
    • Greasemonkey : Allows you to customize the way a webpage displays using small bits of JavaScript (scripts could be download here)
  • Encryption
    • Fire Encrypter : FireEncrypter is an Firefox extension which gives you encryption/decryption and hashing functionalities right from your Firefox browser, mostly useful for developers or for education & fun.
  • Anti Spoof
    • refspoof : Easy to pretend to origin from a site by overriding the url referrer (in a http request). — it incorporates this feature by using the pseudo-protocol spoof:// .. thus it’s possible to store the information in a “hyperlink” – that can be used in any context .. like html pages or bookmarks

Besides, we keep watching new extensions and we are on the way to develop a new extension for Nmap and Nessus. So keep watching us.

 




Related posts

coded by nessus
  • http://www.bestantivirusforwindows7.org/ Randal Rasual
    Many thanks for this write-up. Highly appreciated. You usually have got to trawl through a shed load of junk to track down a handful of very good information! Anybody know the most impressive site so you can get the best antivirus from the United kingdom?
    • (-)AX0R M3.
      best antivirus download here
  • http://www.BitdefenderInternetSecurity2012Reviews.com/ Bitdefender Internet Security 2012 Reviews
    antivirus programs are necessary to the proper operating of your computer. be sure to look up the best program for your particular use. there are lots of different options available.
  • http://onetowniassda.net Domenic Smolen
    Heya i am for the first time here. I came across this board and I to find It truly helpful & it helped me out much. I hope to give one thing back and aid others such as you aided me.
  • http://AustinTXFoundationRepairs.com austin engineer letters
    Pretty great post. I simply stumbled upon your weblog and wanted to mention that I have really enjoyed browsing your blog posts. After all I?ll be subscribing to your feed and I hope you write again very soon!
  • http://www.spis.100sport.pl/116582,artykul,Strony-internetowe.html Randell Sleiman
    Thank you for publishing such a great article for the world to see. I offer two thumbs up for this writing both for grammar and engaging material. I could only hope to write this well.
  • http://www.najlepsze.waw.pl/a/Projektowanie-stron-Kielce,8500 Curt Barrena
    Good day! I just would like to give a huge thumbs up for the good info you have here on this post. I will probably be coming back to your blog for extra soon.
  • http://linguim.com/es/en/ Aprender Ingles en Linea
    It was an great idea, full of sense and facts. It had enjoyable reading this post ^_^
  • http://privateproxyreviews.com Private Proxies
    Hey handsome I simply discover your web blog thru a keyword “private proxy” , would you use private proxy services ,If so please leave a reviews on my site.Cheers.
  • http://www.naudndw.net Lewis Estridge
    I would like to use the chance of saying thanks to you for your professional guidance I have continually enjoyed viewing your site. I am looking forward to the commencement of my school research and the general preparing would never have been complete without consulting your site. If I could be of any assistance to others, I will be delighted to help by way of what I have discovered from here.
  • http://bikinfo.com.pl/ Ciekawe artykuły
    very nice post, i certainly love this website, keep on it
  • http://tdaaddad.lopadss Detra Mailliard
    I actually desired to compose a small note to thank for you for some of the pleasant secrets you happen to be showing on this webpage.
  • http://www.wyfopedia.org.uk/index.php?title=User:ElzamBran448 Koh Yao Noi hotels
    Simply want to say your article is as amazing. The clearness to your submit is just spectacular and i could suppose you’re knowledgeable on this subject. Fine along with your permission let me to grab your feed to keep up to date with approaching post. Thank you one million and please continue the gratifying work.
  • http://www.askiitians.com/ Huey Styers
    Hiya. Very cool blog!! Man .. Excellent .. Wonderful .. I’ll bookmark your web site and take the feeds also…I am glad to locate numerous useful information here within the article. Thanks for sharing.
  • http://the247news.info/09014559/iphone-5-release-date/ iPhone 5 Release Date
    Nice read, I just passed this onto a friend who was doing some research on that. And he actually bought me lunch as I found it for him smile So let me rephrase that: Thank you for lunch! “The guy with the biggest stomach will be the first to take off his shirt at a baseball game.” by Glenn Dickey.
  • http://www.martysmarketview.com/the-independent-financial-advisor.htm Independent Financial Advisor
    As a Newbie, I am always searching online for articles that can help me. Thank you
Related Links

About Me

Learn-Hack-Secure-XploiT

DMCA.com

Twitter

Disclaimer

The views expressed in the posts and comments of this blog do not necessarily reflect the www.dataXploit.net.The content and Other Information is provided by Various Sources (Emails, Messages, etc..) for Educational Purpose and Security Awareness only. If any Law Enforcement Agency or Related Company needs Information, Please Feel free to Contact Us. Thank You !!!
Promote Your Blog