Skip to main content

Turning Mozilla Firefox To Ethical Hacking Platform

Turning Mozilla Firefox To Ethical Hacking Platform 




Hey Friends Some toolz wich make your firefox into Hackers Browser


Information gathering
● Whois and geo-location
o ShowIP : Show the IP address of the current page in the status bar. 
It also allows querying custom services by IP (right mouse button) and Hostname (left mouse button), like whois, 
Netcraft.
This link goes to an HTTPS secured site.

o Shazou : The product called Shazou (pronounced Shazoo it is Japanese for mapping)

enables the user with one-click to map and geo-locate any website they are currently
viewing.
This link goes to an HTTPS secured site.

o HostIP.info Geolocation : Displays Geolocation information for a website using hostip.info
data. Works with all versions of Firefox.
This link goes to an HTTPS secured site.

o Active Whois : Starting Active Whois to get details about any Web site owner and its host
server.
This link goes to an HTTPS secured site.

o Bibirmer Toolbar : An all-in-one extension. But auditors need to play with the toolbox. It
includes (WhoIs, DNS Report, Geolocation, Traceroute, Ping). Very useful for information
gathering phase

● Enumeration / fingerprinting
o Header Spy : Shows HTTP headers on statusbar
This link goes to an HTTPS secured site.

o Header Monitor : This is Firefox extension for display on statusbar panel any HTTP
response header of top level document returned by a web server. Example: Server (by
default), Content-Encoding, Content-Type, X-Powered-By and others.
This link goes to an HTTPS secured site.

● Social engineering
o People Search and Public Record : This Firefox extension is a handy menu tool for
investigators, reporters, legal professionals, real estate agents, online researchers and
anyone interested in doing their own basic people searches and public record lookups as
well as background research.
This link goes to an HTTPS secured site.

● Googling and spidering
o Advanced dork : Gives quick access to Google’s Advanced Operators directly from the
context menu. This could be used to spider a site or scan for hidden files (this spider
technique is used via scroogle.org)
This link goes to an HTTPS secured site.

o SpiderZilla : Spiderzilla is an easy-to-use website mirror utility, based on Httrack from
https://addons.mozilla.org/en-US/firefox/addon/spiderzilla/

o View Dependencies : View Dependencies adds a tab to the "page info" window, in which it
lists all the files which were loaded to show the current page. (useful for a spidering
technique)
Security Assessment / Code auditing
This link goes to an HTTPS secured site.

● Editors
o JSView : The ’view page source’ menu item now opens files based on the behaviour you
choose in the jsview options. This allows you to open the source code of any web page in
a new tab or in an external editor.
This link goes to an HTTPS secured site.

o Cert Viewer Plus : Adds two options to the certificate viewer in Firefox or Thunderbird: an
X.509 certificate can either be displayed in PEM format (Base64/RFC 1421, opens in a new
window) or saved to a file (in PEM or DER format - and PKCS#7 provided that the
respective patch has been applied - cf.
This link goes to an HTTPS secured site.

o Firebug : Firebug integrates with Firefox to put a wealth of development tools at your
fingertips while you browse. You can edit, debug, and monitor CSS, HTML, and JavaScript
live in any web page
This link goes to an HTTPS secured site.

o XML Developer Toolbar : Allows XML Developer’s use of standard tools all from your
browser.
This link goes to an HTTPS secured site.

● Headers manipulation
o HeaderMonitor : This is Firefox extension for display on statusbar panel any HTTP response
header of top level document returned by a web server. Example: Server (by default),
Content-Encoding, Content-Type, X-Powered-By and others.
This link goes to an HTTPS secured site.

o RefControl : Control what gets sent as the HTTP Referrer on a per-site basis.
This link goes to an HTTPS secured site.

o User Agent Switcher : Adds a menu and a toolbar button to switch the user agent of the
browser
This link goes to an HTTPS secured site.

● Cookies manipulation
o Add N Edit Cookies : Cookie Editor that allows you add and edit "session" and saved
cookies.
This link goes to an HTTPS secured site.

o CookieSwap : CookieSwap is an extension that enables you to maintain numerous sets or
"profiles" of cookies that you can quickly swap between while browsing
This link goes to an HTTPS secured site.

o httpOnly : Adds httpOnly cookie support to Firefox by encrypting cookies marked as
httpOnly on the browser side
This link goes to an HTTPS secured site.

o Allcookies : Dumps ALL cookies (including session cookies) to Firefox standard cookies.txt
file
This link goes to an HTTPS secured site.

● Security auditing
o HackBar : This toolbar will help you in testing SQL injections, XSS holes and site security. It
is NOT a tool for executing standard exploits and it will NOT teach you how to hack a site.
Its main purpose is to help a developer do security audits on his code.
This link goes to an HTTPS secured site.

Tamper Data : Use “tamper data” to view and modify HTTP/HTTPS headers and post
parameters can also use to tamper data while processing the file.
This link goes to an HTTPS secured site.

Live HTTP Header : Use “lovehttpheader” to view and modify HTTP/HTTPS headers and post parameters.
This link goes to an HTTPS secured site.


o Chickenfoot : Chickenfoot is a Firefox extension that puts a programming environment in
the browser’s sidebar so you can write scripts to manipulate web pages and automate web
browsing. In Chickenfoot, scripts are written in a superset of JavaScript that includes
special functions specific to web tasks.
Proxy/web utilities

● FoxyProxy : FoxyProxy is an advanced proxy management tool that completely replaces Firefox’s
proxy configuration. It offers more features than SwitchProxy, ProxyButton, QuickProxy, xyzproxy,
ProxyTex, etc
This link goes to an HTTPS secured site.

● AnonyMox: AnonyMox lets you manage and switch between multiple proxy configurations
quickly and easily. You can also use it as an anonymizer to protect your computer from prying eyes
This link goes to an HTTPS secured site.
https://addons.mozilla.org/en-US/firefox/addon/anonymox/

● POW (Plain Old WebServer) : The Plain Old Webserver uses Server-side JavaScript (SJS) to run a
server inside your browser. Use it to distribute files from your browser. It supports Server-side JS,
GET, POST, uploads, Cookies, SQLite and AJAX. It has security features to password-protect your
site. Users have created a wiki, chat room and search engine using SJS.
Misc
This link goes to an HTTPS secured site.
https://addons.mozilla.org/en-us/firefox/addon/pow-plain-old-webserver/

● Hacks for fun

o Greasemonkey : Allows you to customize the way a webpage displays using small bits of
JavaScript
This link goes to an HTTPS secured site.

● Encryption

o Fire Encrypter : FireEncrypter is a Firefox extension which gives you encryption/decryption
and hashing functionalities right from your Firefox browser, mostly useful for developers or
for education & fun.
Malware scanner

● QArchive.org web files checker : Allowing people to check web files for any malware (viruses, trojans, worms, adware, spyware and other unwanted things) inclusions.

● Dr.Web anti-virus link checker : This plugin allows you to check any file you are about to download,
any page you are about to visit.
This link goes to an HTTPS secured site.

● ClamWin Antivirus Glue for Firefox : This extension scans every downloaded file automatically with
ClamWin.

● refspoof : Easy to pretend to origin from a site by overriding the URL referrer (in a http request). —
It incorporates this feature by using the pseudo-protocol spoof:// .. 
Thus it’s possible to store the information in a "hyperlink" - that can be used in any context... like html pages or bookmarks
Besides, we keep watching new extensions and we are on the way to develop a new extension for Nmap and Nessus.
This link goes to an HTTPS secured site.
https://addons.mozilla.org/en-US/firefox/addon/refspoof/


o SkipScreen -- Great Multi-Host download helper!
Skips unnecessary pages on sites like Rapidshare, 4Shared, zShare, Mediafire, and more. Try it out, or watch a demo at http://www.skipscreen.com
Why click through ad-laden pages and wait for countdowns when your computer can do it for you

Comments

Popular posts from this blog

10 Best Forum Software For Webmasters

10 Best Forum Software For Webmasters Do you want to create your online discussion forum or online community where people can discuss about their favorite topics? In this article, you can see 10 best forum software (scripts for setting up discussion forums) that can be used free of cost. Although some scripts are paid but rest of these forum scripts are free to use.You only need to buy hosting space and domain name for your website and after then you can install any of these forum scripts to start your own discussion forums on the internet. Online discussion forums generate huge page views because thousands of people want to join online discussion forums to ask questions or share knowledge. Some of online marketers join forums to discuss about their products with community members. You don't need to acquire any kind of technical skill to run a professional discussion forums because these days, almost all web hosting providers offer one click script installer which h...

How to Hack WhatsApp using just a GIF

A picture is worth a thousand words, but a GIF is worth a thousand pictures. Today, the short looping clips, GIFs are everywhere—on your social media, on your message boards, on your chats, helping users perfectly express their emotions, making people laugh, and reliving a highlight. But what if an innocent-looking GIF greeting with Good morning, Happy Birthday, or Merry Christmas message hacks your smartphone? Well, not a theoretical idea anymore. WhatsApp has recently patched a critical security vulnerability in its app for Android, which remained unpatched for at least 3 months after being discovered, and if exploited, could have allowed remote hackers to compromise Android devices and potentially steal files and chat messages. WhatsApp Remote Code Execution Vulnerability The vulnerability, tracked as  CVE-2019-11932 , is a double-free memory corruption bug that doesn't actually reside in the WhatsApp code itself, but in an open-source GIF image parsing library that What...

|Bypass Symlink on 2013 Server With Different .htaccess and Methods by Sen Haxor |

Hi, Guys,  Please a wonderfull tutorial provided bt Sem;\  Today I gonna Explain how to bypass Symlink on 2013 Server With Different .htaccess and Methods. So let's Get Started :) Note: This method is not applicable for Godaddy, Bluehost, Hostgator and Hostmonstor Servers. For This First You Need the Following Files : 1 -> Sen Haxor CGI Shell 2 -> sen.zip 3 -> passwd-bypass.php 4 -> Turbo Brute force Cpanel 5 - > Port.py First Before Starting to symlink we need to create php.ini and ini.php to Disable Safe mode and Disabled Functions on the server . Use the Following Code : Make a php.ini with the following code safe_mode=Off And ini.php with <? echo ini_get("safe_mode"); echo ini_get("open_basedir"); include($_GET["file"]); ini_restore("safe_mode"); ini_restore("open_basedir"); echo ini_get("safe_mode"); echo...