Ravikanth's Blog

Happenings around Me

Disclaimer

India MVP Blogs

Mugh blogs

My

My Favorites

My Network Places

Firefox Plugins for Security Professionals by Schmidt, Chris

Access Me
Although it doesn’t find 90% of what it says it will, this plugin can be somewhat useful for determining whether a server configuration is vulnerable to certain attacks that can me made with different request methods such as DELETE.

SQL Inject Me
I have seen this plugin succesfully detect several *easy-to-find* SQL Injection vulnerable form fields. But it doesn’t really do a whole lot of checking beyond the simple obvious ones.

XSS Me
Of all of the Security Compass plug-in’s this one is by far the most useful and does most of what it says it will. However, just because the plug-in says a site is not vulnerable to XSS doesn’t mean it truly isn’t. This plugin, like SQL Inject Me, simply checks for the simplest XSS vectors.

Web Developer
Of every plugin I use, I probably use the functionality of this one more than any other. This is an entire suite of tools aimed at assisting web developers with things like local validation, src highlighting, form modifications, etc. That being said, the same functionality is invaluable to web application hackers to break your forms, discover XSS vectors, and analyze your code for other problems.

FireBug
Like Web Developer, this plugin was designed and built with the developer in mind. However, with enhanced JS debugging capabilities, and arguably the best DOM browser there is, this plugin has singlehandedly been responsible for more XSS powered CSRF exploits in my audits than every tool in my toolkit combined. This is a must-have.

Passive Recon
This is an entire suite of tools that allow you to pseudo anonymously get a pretty detailed domain recon report from a single click, or parts of that report individually. This can come in very handy when performing an audit on a site or app that you know very little about to begin with and often gives insight into the system and server architecture of the target that can prove invaluable to finding holes.

TorButton
If you haven’t heard of TOR you probably have no idea what I am talking about in most of the above plugins. While it is by no means perfect, and can never replace a good proxy chain, TOR provides basic anonymization of your internet traffic. This button allows you to switch in and out of TOR mode in firefox with a single click.

FireCookie
Firecookie is actually an extension to the FireBug plugin, and thus requires that FireBug be running and installed. However, it provides a means to view and edit cookies in real-time.

Modify Headers
This plugin can prove invaluable when used correctly, for everything from spoofing user-agent to spoofing client ip, this is a must have for any hackers toolbox.

Tamper Data
Like Modify Headers, the Tamper Data plugin allows you to modify headers and cookies. The difference is, it does so on a Per-Request policy, meaning that if you are enumerating manually to isolate a bug, this plug-in will prove to be your best friend. I have broken many a webservice with this tool.

Comments

Pupeevetlylit said:

Доброго времени суток,  

Хочу представить вам свежий лабаз курительных смесей

сайт магазина http://spice-family.ru  

3г микса Rest - 1,500 р. + доставка (ems, pony get across)  

Сообразно вопросам опта отмечать вразброд в скайп - FomaX2

# September 3, 2011 6:15 AM

BlooreMof said:

Glad to cry, laugh so overpowered .

# December 20, 2011 12:27 PM

boumperourogs said:

http://tor4.su - снижение вреда и борьба с наркозависимостью по средствам введения наркотиков в свой организм

# February 27, 2012 1:13 AM

boumperourogs said:

http://tor4.su - Крупнейший ресурс о наркотиках и наркомании созданный самими зависимыми людьми. Об этом не скажут в СМИ!

# March 4, 2012 5:27 PM

boumperourogs said:

Растения-стимуляторы tor4.su/.../viewtopic.php

# March 16, 2012 2:07 PM

boumperourogs said:

Винт, белый, метамфетамин, самый большой рассказ о нем tor4.su/.../viewtopic.php

# March 25, 2012 8:10 PM

boumperourogs said:

Не хочется работать? tor4.su/.../viewtopic.php

# April 11, 2012 2:26 PM

boumperourogs said:

А вы трипуете под сиропом от кашля tor4.su/.../viewtopic.php

# April 19, 2012 10:34 PM
Leave a Comment

(required) 

(required) 

(optional)

(required)