<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>tanasi.it &#187; firefox</title>
	<atom:link href="http://www.tanasi.it/tag/firefox/feed" rel="self" type="application/rss+xml" />
	<link>http://www.tanasi.it</link>
	<description>Alessandro `jekil` Tanasi blog</description>
	<lastBuildDate>Fri, 02 Jul 2010 11:06:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>A browser as web hacking platform</title>
		<link>http://www.tanasi.it/1254-a-browser-as-web-hacking-platform.html</link>
		<comments>http://www.tanasi.it/1254-a-browser-as-web-hacking-platform.html#comments</comments>
		<pubDate>Tue, 19 Aug 2008 01:08:00 +0000</pubDate>
		<dc:creator>jekil</dc:creator>
				<category><![CDATA[In English]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techie]]></category>
		<category><![CDATA[ethical hacking]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[firefox extension]]></category>

		<guid isPermaLink="false">http://localhost/wordpress/?p=1153</guid>
		<description><![CDATA[A list of Firefox plugins to turn your browser in an hacking platform. This is an improved list based on &#34;Turning Firefox to an ethical hacking platform&#34; from Security-Database.com Information gathering Whois and geo-location ShowIP : Show the IP address of the current page in the status bar. It also allows querying custom services by [...]]]></description>
			<content:encoded><![CDATA[<p>A list of Firefox plugins to turn your browser in an hacking platform. This is an improved list based on &quot;<a href="http://www.security-database.com/toolswatch/Turning-Firefox-to-an-Ethical.html">Turning Firefox to an ethical hacking platform</a>&quot; from Security-Database.com</p>
<p><b>Information gathering</b></p>
<ul class="spip">
<li class="spip"><b> Whois and geo-location</b>
<ul class="spip">
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/590/" class="spip_out">ShowIP</a><br />
: Show the IP address of the current page in the status bar. It also<br />
allows querying custom services by IP (right mouse button) and Hostname<br />
(left mouse button), like whois, netcraft.</li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/2993/" class="spip_out">Shazou</a><br />
: The product called Shazou (pronounced Shazoo it is Japanese for<br />
mapping) enables the user with one-click to map and geo-locate any<br />
website they are currently viewing.</li>
<li class="spip"><a target="_blank" href="https://addons.mozilla.org/firefox/663/" class="spip_out"> HostIP.info Geolocation</a> : Displays Geolocation information for a website using hostip.info data. Works with all versions of Firefox.</li>
<li class="spip"><a target="_blank" href="https://addons.mozilla.org/firefox/2100/" class="spip_out"> Active Whois</a> : Starting Active Whois to get details about any Web site owner and its host server.</li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/2587/" class="spip_out">Bibirmer Toolbar</a><br />
: An all-in-one extension. But auditors need to play with the toolbox.<br />
It includes ( WhoIs, DNS Report, Geolocation , Traceroute , Ping ).<br />
Very useful for information gathering phase</li>
</ul>
</li>
</ul>
<ul class="spip">
<li class="spip"><b> Enumeration / fingerprinting</b>
<ul class="spip">
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/4276/" class="spip_out">Header Spy</a>: Shows HTTP headers on statusbar</li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/575/" class="spip_out">Header Monitor</a><br />
: This is Firefox extension for display on statusbar panel any HTTP<br />
response header of top level document returned by a web server.<br />
Example: Server (by default), Content-Encoding, Content-Type,<br />
X-Powered-By and others.</li>
</ul>
</li>
</ul>
<ul class="spip">
<li class="spip"><b> Social engineering</b>
<ul class="spip">
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/3167/" class="spip_out">People Search and Public Record</a>:<br />
This Firefox extension is a handy menu tool for investigators,<br />
reporters, legal professionals, real estate agents, online researchers<br />
and anyone interested in doing their own basic people searches and<br />
public record lookups as well as background research.</li>
</ul>
</li>
</ul>
<ul class="spip">
<li class="spip"><b> Googling and spidering</b>
<ul class="spip">
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/2144/" class="spip_out">Advanced dork</a><br />
: Gives quick access to Google’s Advanced Operators directly from the<br />
context menu. This could be used to scan for hidden files or narrow<br />
in a target anonymously (via the scroogle.org option) </li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/1616/" class="spip_out">SpiderZilla</a> : Spiderzilla is an easy-to-use website mirror utility, based on Httrack from www.httrack.com.</li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/2214/" class="spip_out">View Dependencies</a><br />
: View Dependencies adds a tab to the &quot;page info&quot; window, in which it<br />
lists all the files which were loaded to show the current page. (useful<br />
for a spidering technique)</li>
</ul>
</li>
</ul>
<p class="spip"><b>Security Assessment / Code auditing</b></p>
<ul class="spip">
<li class="spip"><b> Editors</b>
<ul class="spip">
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/2076/" class="spip_out">JSView</a><br />
: The ’view page source’ menu item now opens files based on the<br />
behavior you choose in the jsview options. This allows you to open the<br />
source code of any web page in a new tab or in an external editor.</li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/1964/" class="spip_out">Cert Viewer Plus</a><br />
: Adds two options to the certificate viewer in Firefox or Thunderbird:<br />
an X.509 certificate can either be displayed in PEM format (Base64/RFC<br />
1421, opens in a new window) or saved to a file (in PEM or DER format -<br />
and PKCS#7 provided that the respective patch has been applied &#8211; cf.</li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/1843/" class="spip_out">Firebug</a><br />
: Firebug integrates with Firefox to put a wealth of development tools<br />
at your fingertips while you browse. You can edit, debug, and monitor<br />
CSS, HTML, and JavaScript live in any web page</li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/2897/" class="spip_out">XML Developer Toolbar</a>:allows XML Developer’s use of standard tools all from your browser.</li>
<li class="spip"><a href="https://addons.mozilla.org/en-US/firefox/addon/60">Web developer</a> : Adds a menu and a toolbar with various web developer tools.</li>
</ul>
</li>
</ul>
<ul class="spip">
<li class="spip"><b> Headers manipulation</b>
<ul class="spip">
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/575/" class="spip_out">HeaderMonitor</a><br />
: This is Firefox extension for display on statusbar panel any HTTP<br />
response header of top level document returned by a web server.<br />
Example: Server (by default), Content-Encoding, Content-Type,<br />
X-Powered-By and others.</li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/953/" class="spip_out">RefControl</a> : Control what gets sent as the HTTP Referer on a per-site basis.</li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/59/" class="spip_out">User Agent Switcher</a> :Adds a menu and a toolbar button to switch the user agent of the browser</li>
</ul>
</li>
</ul>
<ul class="spip">
<li class="spip"><b> Cookies manipulation</b>
<ul class="spip">
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/573/" class="spip_out">Add N Edit Cookies</a> : Cookie Editor that allows you add and edit &quot;session&quot; and saved cookies. </li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/3255/" class="spip_out">CookieSwap</a><br />
: CookieSwap is an extension that enables you to maintain numerous sets<br />
or &quot;profiles&quot; of cookies that you can quickly swap between while<br />
browsing</li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/3629/" class="spip_out">httpOnly</a> : Adds httpOnly cookie support to Firefox by encrypting cookies marked as httpOnly on the browser side</li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/2208/" class="spip_out">Allcookies</a> : Dumps ALL cookies (including session cookies) to Firefox standard cookies.txt file</li>
</ul>
</li>
</ul>
<ul class="spip">
<li class="spip"><b> Security auditing</b>
<ul class="spip">
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/3899/" class="spip_out">HackBar</a><br />
: This toolbar will help you in testing sql injections, XSS holes and<br />
site security. It is NOT a tool for executing standard exploits and it<br />
will NOT learn you how to hack a site. Its main purpose is to help a<br />
developer do security audits on his code.</li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/966/" class="spip_out">Tamper Data</a> : Use tamperdata to view and modify HTTP/HTTPS headers and post<br />
parameters.</li>
<li class="spip"><a target="_blank" href="http://groups.csail.mit.edu/uid/chickenfoot/" class="spip_out">Chickenfoot</a><br />
: Chickenfoot is a Firefox extension that puts a programming<br />
environment in the browser’s sidebar so you can write scripts to<br />
manipulate web pages and automate web browsing. In Chickenfoot, scripts<br />
are written in a superset of Javascript that includes special functions<br />
specific to web tasks. </li>
</ul>
</li>
</ul>
<p class="spip"><b>Proxy/web utilities</b></p>
<ul class="spip">
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/2464/" class="spip_out">FoxyProxy</a><br />
: FoxyProxy is an advanced proxy management tool that completely<br />
replaces Firefox’s proxy configuration. It offers more features than<br />
SwitchProxy, ProxyButton, QuickProxy, xyzproxy, ProxyTex, etc</li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/125/" class="spip_out">SwitchProxy</a>:<br />
SwitchProxy lets you manage and switch between multiple proxy<br />
configurations quickly and easily. You can also use it as an anonymizer<br />
to protect your computer from prying eyes</li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/3002/" class="spip_out">POW (Plain Old WebServer)</a><br />
: The Plain Old Webserver uses Server-side Javascript (SJS) to run a<br />
server inside your browser. Use it to distribute files from your<br />
browser. It supports Server-side JS, GET, POST, uploads, Cookies,<br />
SQLite and AJAX. It has security features to password-protect your<br />
site. Users have created a wiki, chat room and search engine using SJS.</li>
<li class="spip"><a href="https://addons.mozilla.org/en-US/firefox/addon/2275">Torbutton</a> : Torbutton provides a button to securely and easily enable or disable<br />
the browser&#8217;s use of Tor. It is currently the only addon that will<br />
safely manage your Tor browsing to prevent IP address leakage, cookie<br />
leakage, and general privacy attacks.</li>
</ul>
<p class="spip"><b>Misc</b></p>
<ul class="spip">
<li class="spip"><b> Hacks for fun</b>
<ul class="spip">
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/748/" class="spip_out">Greasemonkey</a> : Allows you to customize the way a webpage displays using small bits of JavaScript (scripts could be download <a target="_blank" href="http://userscripts.org/" class="spip_out">here</a>)</li>
</ul>
</li>
</ul>
<ul class="spip">
<li class="spip"><b> Encryption</b>
<ul class="spip">
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/3208/" class="spip_out">Fire Encrypter</a><br />
: FireEncrypter is an Firefox extension which gives you<br />
encryption/decryption and hashing functionalities right from your<br />
Firefox browser, mostly useful for developers or for education &amp;<br />
fun.</li>
</ul>
</li>
</ul>
<ul class="spip">
<li class="spip"><b> Malware scanner</b>
<ul class="spip">
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/4115/" class="spip_out">QArchive.org web files checker</a><br />
: llowing people to check web files for any malware (viruses, trojans,<br />
worms, adware, spyware and other unwanted things) inclusions.</li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/938/" class="spip_out">Dr.Web anti-virus link checker</a> : This plugin allows you to check any file you are about to download, any page you are about to visit</li>
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/771/" class="spip_out">ClamWin Antivirus Glue for Firefox</a> : This extension scans every downloaded file automatically with ClamWin. </li>
</ul>
</li>
</ul>
<ul class="spip">
<li class="spip"><b> Anti Spoof</b>
<ul class="spip">
<li class="spip"> <a target="_blank" href="https://addons.mozilla.org/firefox/667/" class="spip_out">refspoof</a><br />
: Easy to pretend to origin from a site by overriding the url referrer<br />
(in a http request). — it incorporates this feature by using the<br />
pseudo-protocol spoof:// .. thus it’s possible to store the information<br />
in a &quot;hyperlink&quot; &#8211; that can be used in any context .. like html pages<br />
or bookmarks</li>
</ul>
</li>
</ul>
<ul class="related_post"><li><a href="http://www.tanasi.it/1118-how-to-create-firefox-extensions.html" title="How to create Firefox extensions">How to create Firefox extensions</a></li><li><a href="http://www.tanasi.it/1053-useful-firefox-security-extensions.html" title="Useful Firefox Security Extensions">Useful Firefox Security Extensions</a></li><li><a href="http://www.tanasi.it/1235-mozilla-port-banning.html" title="Mozilla port banning">Mozilla port banning</a></li><li><a href="http://www.tanasi.it/1126-must-have-seo-firefox-extensions.html" title="Must Have SEO Firefox Extensions">Must Have SEO Firefox Extensions</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.tanasi.it/1254-a-browser-as-web-hacking-platform.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla port banning</title>
		<link>http://www.tanasi.it/1235-mozilla-port-banning.html</link>
		<comments>http://www.tanasi.it/1235-mozilla-port-banning.html#comments</comments>
		<pubDate>Mon, 02 Jun 2008 23:06:00 +0000</pubDate>
		<dc:creator>jekil</dc:creator>
				<category><![CDATA[In English]]></category>
		<category><![CDATA[OSs and Apps]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techie]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[port banning]]></category>

		<guid isPermaLink="false">http://localhost/wordpress/?p=1141</guid>
		<description><![CDATA[Using a specially crafted HTML page, an attacker can trick a browser displaying this HTML page into accessing SMTP, NNTP, POP3, IRC, or other servers, possibly behind a firewall. Cert issued a Vulnerability Note VU#476267 for a &#34;Cross-Protocol&#34; scripting attack, known as the HTML Form Protocol Attack which allowed sending arbitrary data to most TCP [...]]]></description>
			<content:encoded><![CDATA[<p>Using a specially crafted HTML page, an attacker can trick a browser displaying this HTML page into accessing SMTP, NNTP, POP3, IRC, or other servers, possibly behind a firewall.</p>
<p>Cert issued a<br />
    <a href="http://www.kb.cert.org/vuls/id/476267">Vulnerability Note VU#476267</a><br />
    for a &quot;Cross-Protocol&quot; scripting attack, known as the <a href="http://www.remote.org/jochen/sec/hfpa/index.html">HTML<br />
      Form Protocol Attack</a> which allowed sending arbitrary data to most TCP ports.<br />
    A simple exploit of this hole allows an attacker to send forged unsigned mail through<br />
a mail server behind your firewall: A really nasty hole.
</p>
<p>I found the list of ports blocked by Mozilla here: <a href="http://www.mozilla.org/projects/netlib/PortBanning.html">http://www.mozilla.org/projects/netlib/PortBanning.html</a></p>
<ul class="related_post"><li><a href="http://www.tanasi.it/1254-a-browser-as-web-hacking-platform.html" title="A browser as web hacking platform">A browser as web hacking platform</a></li><li><a href="http://www.tanasi.it/1118-how-to-create-firefox-extensions.html" title="How to create Firefox extensions">How to create Firefox extensions</a></li><li><a href="http://www.tanasi.it/1053-useful-firefox-security-extensions.html" title="Useful Firefox Security Extensions">Useful Firefox Security Extensions</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.tanasi.it/1235-mozilla-port-banning.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to create Firefox extensions</title>
		<link>http://www.tanasi.it/1118-how-to-create-firefox-extensions.html</link>
		<comments>http://www.tanasi.it/1118-how-to-create-firefox-extensions.html#comments</comments>
		<pubDate>Thu, 04 Oct 2007 01:54:00 +0000</pubDate>
		<dc:creator>jekil</dc:creator>
				<category><![CDATA[In English]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Techie]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[firefox extension]]></category>
		<category><![CDATA[firefox plugin]]></category>

		<guid isPermaLink="false">http://localhost/wordpress/?p=1040</guid>
		<description><![CDATA[Extensions are small add-ons that add new functionality to Firefox, from a simple toolbar button to a completely new feature. They allow you to customize Firefox to fit your own needs and preferences, while letting us keep Firefox itself light and lean.Learn how to write your own extensions. Links: Creating Firefox extensions How to create [...]]]></description>
			<content:encoded><![CDATA[<p>Extensions are small add-ons that add new functionality to Firefox, from a simple toolbar button to a completely new feature. They allow<br />
you to customize Firefox to fit your own needs and preferences, while letting us keep Firefox itself light and lean.<br />Learn how to write your own extensions.<br />
Links:
<ul>
<li><a href="http://extensions.roachfiend.com/howto_bug.html">Creating Firefox extensions</a></li>
<li><a href="http://roachfiend.com/archives/2004/12/08/how-to-create-firefox-extensions/">How to create Firefox extensions</a></li>
<li><a href="http://www.rietta.com/firefox/">Extend Firefox: Your Guide to Writing Firefox Extensions</a></li>
<li><a href="http://www.businesslogs.com/technology/firefox_extension_tutorial.php">Firefox Extension Tutorial</a></li>
<li><a href="http://lifehacker.com/software/programming/how-to-build-a-firefox-extension-264490.php">How to build a Firefox extension</a></li>
<li><a href="http://www.softwaredeveloper.com/features/firefox-extension-resource-072307/">Developing a Firefox Extension That People Actually Use: 32 Essential Tools and Tutorials</a></li>
<li><a href="http://www.captain.at/howto-firefox-statusbar-tutorial.php">Firefox Extension: Firefox Statusbar Tutorial &#8211; How to add stuff to the statusbar in Firefox/Mozilla</a></li>
<li><a href="http://ginatrapani.org/spun/posts/2006/11/01/firefox-20-extension-development" rel="bookmark" title="Permanent Link: Firefox 2.0 extension development">Firefox 2.0 extension development</a></li>
<li><a href="http://www.bengoodger.com/software/mb/extensions/packaging/extensions.html">Packaging Firefox/Thunderbird Extensions</a></li>
<li><a href="http://www.captain.at/programming/xul/">Captain&#8217;s Mozilla XUL LOG &#8211; read local files and write local files</a></li>
</ul>
<ul class="related_post"><li><a href="http://www.tanasi.it/1053-useful-firefox-security-extensions.html" title="Useful Firefox Security Extensions">Useful Firefox Security Extensions</a></li><li><a href="http://www.tanasi.it/1254-a-browser-as-web-hacking-platform.html" title="A browser as web hacking platform">A browser as web hacking platform</a></li><li><a href="http://www.tanasi.it/1235-mozilla-port-banning.html" title="Mozilla port banning">Mozilla port banning</a></li><li><a href="http://www.tanasi.it/1126-must-have-seo-firefox-extensions.html" title="Must Have SEO Firefox Extensions">Must Have SEO Firefox Extensions</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.tanasi.it/1118-how-to-create-firefox-extensions.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Useful Firefox Security Extensions</title>
		<link>http://www.tanasi.it/1053-useful-firefox-security-extensions.html</link>
		<comments>http://www.tanasi.it/1053-useful-firefox-security-extensions.html#comments</comments>
		<pubDate>Thu, 02 Aug 2007 22:19:00 +0000</pubDate>
		<dc:creator>jekil</dc:creator>
				<category><![CDATA[In English]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techie]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[firefox extension]]></category>
		<category><![CDATA[firefox plugin]]></category>

		<guid isPermaLink="false">http://localhost/wordpress/?p=997</guid>
		<description><![CDATA[Useful Firefox plugin list: Add n’ Edit Cookies This might be more of a web developer tool, but being able to view in detail the cookies that various sites set on your visits can be an eye-opening experience. This extension not only shows you all the details, but lets you modify them too. You’ll be [...]]]></description>
			<content:encoded><![CDATA[<p>Useful Firefox plugin list:
<ul>
<li><a href="https://addons.mozilla.org/extensions/moreinfo.php?application=firefox&#038;category=Privacy%20and%20Security&#038;numpg=10&#038;id=573">Add n’ Edit Cookies</a> This might be more of a web developer tool, but being able to view in detail the cookies that various sites set on your visits can be an eye-opening experience. This extension not only shows you all the details, but lets you modify them too. You’ll be surprised at how many web apps do foolish things like saving your password in the cookie.</li>
<li><a href="https://addons.mozilla.org/extensions/moreinfo.php?application=firefox&#038;category=Privacy%20and%20Security&#038;numpg=10&#038;id=938">Dr. Web Anti-Virus Link Checker<br />
</a>This is an interesting idea — scanning files for viruses <em>before</em><br />
you download them. Basically, this extension adds an option to the link<br />
context menu that allows you to pass the link to the Dr. Web AV<br />
service. I haven’t rigorously tested this or anything, but it’s an<br />
interesting concept that could be part of an effective multilayer<br />
personal security model.<a href="https://addons.mozilla.org/extensions/moreinfo.php?application=firefox&#038;category=Privacy%20and%20Security&#038;numpg=10&#038;id=938"><br />
</a></li>
<li><a href="https://addons.mozilla.org/extensions/moreinfo.php?application=firefox&#038;category=Privacy%20and%20Security&#038;numpg=10&#038;id=1579">FormFox<br />
</a>This extension doesn’t do a whole lot, but what it does is<br />
important — showing a tooltip when you roll over a form submission<br />
button of the form action URL. Extending this further to visually<br />
differentiate submission buttons that submit to SSL URLs would be<br />
really nice <a href="https://addons.mozilla.org/extensions/moreinfo.php?application=firefox&#038;category=Privacy%20and%20Security&#038;numpg=10&#038;id=1579"><br />
</a></li>
<li><a href="https://addons.mozilla.org/extensions/moreinfo.php?application=firefox&#038;category=Privacy%20and%20Security&#038;numpg=10&#038;id=433">FlashBlock<br />
</a>Flash hasn’t been quite as popular an attack vector as Javascript,<br />
but it still potentially could be a threat, and it’s often an<br />
annoyance. This extension disables all embedded Flash elements by<br />
default (score one for securing things <em>by default</em>), allowing<br />
you to click to activate a particular one if you like. It lacks the<br />
flexibility I’d like (things like whitelists would be very handy), and<br />
doesn’t give you much (any?) info about the Flash element before you<br />
run it, but it’s still a handy tool.</li>
<li><a href="http://livehttpheaders.mozdev.org/">LiveHTTPHeaders</a> &amp; <a href="https://addons.mozilla.org/extensions/moreinfo.php?application=firefox&#038;category=Privacy%20and%20Security&#038;numpg=10&#038;id=575">Header Monitor<br />
</a>LiveHTTPHeaders is an incredibly useful too for web developers,<br />
displaying all of the header traffic between the client and server.<br />
Header Monitor is basically an add-on for LiveHTTPHeaders that displays<br />
a chosen header in Firefox’s status bar. They’re not really<br />
specifically security tools, but they do offer a lot of info on what’s<br />
really going on when you’re browsing, and an educated user is a safer<br />
user.</li>
<li><a href="http://users.blueprintit.co.uk/%7Edave/web/firefox/jsoptions/index.html">JavaScript Option<br />
</a>This restores some of the granularity Firefox users used<br />
to have over what Javascript can and cannot do. I’d like to see this<br />
idea taken farther (see below), but it’s handy regardless.</li>
<li><a href="http://www.noscript.net/">NoScript<br />
</a>This extension is pretty smooth.  Of all the addons for Firefox covered here, this is <em>the</em><br />
one to get. NoScript is a powerful javascript execution whitelisting<br />
tool, allowing full user control over what domains allow scripts to<br />
run. Notifications of blocked execution and the allowed domain<br />
interface are nearly identical to the built-in Firefox popup blocker,<br />
so users should find it comfortable to work with. NoScript can also<br />
block Flash, Java, and “other plugins;” forbid bookmarklets block or allow the ping attribute of the tag; and attempt to rewrite links that execute javascript to go<br />
to their intended donation without triggering the script code.</p>
<p>The one thing I’d really like to see from this extension would be<br />
more ganularity over what the Javascript engine can access. Now it’s<br />
only “on” or “off,” but being able to disable things like cookie access<br />
would eliminate a lot of potential security issues while still letting<br />
JS power rich web app interfaces. Also read <a href="http://www.cerias.purdue.edu/weblogs/pmeunier/secure-it-practices/post-8/">Pascal Meunier’s take on NoScript</a>.
</p>
</li>
<li><a href="https://addons.mozilla.org/extensions/moreinfo.php?application=firefox&#038;category=Privacy%20and%20Security&#038;numpg=10&#038;id=1237">QuickJava<br />
</a>Places handy little buttons in the status bar that let you quickly<br />
enable or disable Java or Javascript support. Note that this will <em>not</em> work with the latest stable Firefox (1.5.0.1).  Hopefully a new version will be available soon.</li>
<li><a href="https://addons.mozilla.org/extensions/moreinfo.php?application=firefox&#038;category=Privacy%20and%20Security&#038;numpg=10&#038;id=590">ShowIP<br />
</a>This is another tool that isn’t aimed at security per se,<br />
but offers a lot of useful information. ShowIP drops the IP address of<br />
the current site in your status bar. Clicking on it brings up a menu of<br />
lookup options for the IP, like whois and DNS info. You can add<br />
additional web lookups if you like, as well as passing the IP to a<br />
local program. Handy stuff.<a href="https://addons.mozilla.org/extensions/moreinfo.php?application=firefox&#038;category=Privacy%20and%20Security&#038;numpg=10&#038;id=590"><br />
</a></li>
<li><a href="http://www.spoofstick.com/">SpoofStick<br />
</a>The idea with this extension is to make it easier to catch<br />
spoofing attempts by displaying a very large, brightly colored “You’re<br />
on ” in the toolbar. For folks who know what they’re doing this isn’t<br />
wildly useful, but it could be just the ticket for less savvy users. It<br />
requires a bit too much setup for them, though, and in the end I think<br />
this is something the browser itself should be handling.<a href="http://www.spoofstick.com/"><br />
 </a></li>
<li><a href="https://addons.mozilla.org/extensions/moreinfo.php?application=firefox&#038;category=Privacy%20and%20Security&#038;numpg=10&#038;id=966">Tamper Data<br />
</a>Much like LiveHTTPHeaders, Tamper Data is a very useful<br />
extension for web devs that lets the user view HTTP headers and POST<br />
data passed between the client and server. In addition, Tamper Data<br />
makes it easy for the user to alter the data being sent to the server,<br />
which is enormously useful for doing security testing against web apps.<br />
I also like how the data is presented in TD a bit better than<br />
LiveHTTPHeaders: it’s easier to see at a glance all of the traffic and<br />
get an overall feel of what’s going on, but you can still drill down<br />
and get as much detail as you like.</li>
<li><a href="http://perso.wanadoo.fr/marc.boullet/ext/extensions-en.html">All-in-One Gestures</a><br />
- merges the popular following extensions for management of mouse<br />
gestures, scrolling and power navigation. (Mix of Mouse Gestures,<br />
Rocker navigation, Tab scroller, History scroller, Link tooltip and<br />
Autoscrolling extensions)</li>
<li><a href="http://216.55.161.203/theonekea/tabprefs/">Tabbrowser Preferences</a><br />
- a comprehensive UI for changing a number of the hidden tabbed<br />
browsing preferences in Firefox. It also provides the ability to<br />
control how internal and external links are opened in the browser and<br />
how the browser will react when links are sent to it.</li>
<li><a href="http://tmp.garyr.net/">Tab Mix Plus</a> &#8211; More tweaks<br />
added to tabs. Ability to select and open muliple links in tabs, open<br />
link in a duplicated tab, merge tabs and close tabs from similar domain…</li>
<li><a href="http://twanno.mozdev.org/duplicatetab/">Duplicate Tab</a> &#8211; allows you to clone a tab with its history and place the duplicate tab in a new window or in the current window.</li>
<li><a href="https://addons.mozilla.org/extensions/moreinfo.php?id=1368&#038;application=firefox">Colorful Tabs</a><br />
- Colors every tab in a different color and makes them easy to<br />
distinguish while beautifying the overall appeal of the interface.</li>
<li><a href="http://viamatic.com/firefox/">Viamatic foXpose</a> &#8211; Click on the icon in the status bar to view all the browser windows with a single click.</li>
<li><a href="http://showcase.uworks.net/">Firefox Showcase</a> &#8211; easily locate and select any open browser window in Firefox.</li>
<li><a href="http://m4ng0.lilik.it/separe.php">Separe</a> &#8211; Helps you keeping tabs tidy by introducing a new kind of tab.</li>
<li><a href="https://addons.mozilla.org/firefox/2558/">Permatabs</a> &#8211; turn tabs of your choice into permanent tabs that can’t be closed, and stick around between sessions.</li>
<li><a href="https://addons.mozilla.org/firefox/3780/">FaviconizeTab</a> &#8211; resizes the width of the tab to display the favicon only (and back again).</li>
<li><a href="http://gemal.dk/mozilla/linky.html">Linky</a> &#8211; Lets you open or download all or selected links, image links and even web addresses <a href="http://www.quickonlinetips.com/archives/2005/12/50-best-firefox-extensions-for-power-surfing/#" style="text-decoration: underline ! important; position: static;" class="kLink" target="_top" id="KonaLink2"><font color="#0033cc" style="color: rgb(0, 51, 204) ! important; font-family: verdana,Arial,Helvetica,sans-serif; font-weight: 400; font-size: 12px; position: static;"><span style="color: rgb(0, 51, 204) ! important; font-family: verdana,Arial,Helvetica,sans-serif; font-weight: 400; font-size: 12px; position: static;" class="kLink"></span></font></a>found in the text in separate or different tabs or windows.</li>
<li><a href="http://jedbrown.net/1.0/mozilla/extensions/">WebMailCompose</a> &#8211; Makes mailto: links load your webmail’s compose page and adds a Compose link to the context menu.</li>
<li><a href="http://www.beggarchooser.com/firefox/">Linkification</a> &#8211; Allows Firefox (0.9+) to view plain-text URLs and e-mail addresses as actual links</li>
<li><a href="http://ietab.mozdev.org/">IE Tab</a> &#8211; can open the<br />
current page or a selected link embedding Internet Explorer in tabs of<br />
Mozilla/Firefox. Very useful for those IE only pages.</li>
<li><a href="http://www.iosart.com/firefox/firefoxview/">FirefoxView</a><br />
- Open Firefox with the current page or a selected link displayed in<br />
Internet Explorer. Adds “View in Firefox” menu items to the content and<br />
link context menus.</li>
<li><a href="http://tecwizards.de/mozilla/">Paste and Go</a> &#8211; lets you<br />
paste an URL from the clipboard into the address bar and load it as a<br />
single step, either via the adress bar’s context menu or by pressing<br />
Ctrl-Shift-V</li>
<li><a href="http://roachfiend.com/archives/2006/08/28/errorzilla-useful-error-pages-for-firefox/">ErrorZilla</a><br />
- changes the default 404 error page with following choices: a google<br />
cache, an archival snapshot from the wayback machine, a ping, a trace<br />
route, and a whois lookup.</li>
<li><a href="http://www.flashgot.net/">FlashGot</a> &#8211; handles single and massive downloads with several external Download Managers.</li>
<li><a href="http://www.rabotat.org/firefox/">PDF Download</a> &#8211; Every<br />
time you click on a link, checks if the target is a pdf file and in<br />
this case let you choose what you want to do (open pdf file inside a<br />
new tab, download it to the filesystem or view it as HTML).</li>
<li><a href="http://amb.vis.ne.jp/mozilla/scrapbook/">ScrapBook</a> &#8211; helps you to save Web pages and easily manage collections.</li>
<li><a href="http://downthemall.mozdev.org/">DownThemAll!</a> &#8211; adds<br />
new advanced downloading capabilities to your browser. It lets you<br />
download in just one click all the links or images contained in a<br />
webpage or refine your preferences using fully customizable filters.</li>
<li><a href="http://www.bolinfest.com/targetalert/">TargetAlert</a> -<br />
provides visual cues for the destinations of hyperlinks. If a hyperlink<br />
points to a something that is not a web page (in cases of pdf, doc, zip<br />
files etc.), then TargetAlert will try to append an icon to the<br />
hyperlink that represents its destination</li>
<li><a href="http://dmextension.mozdev.org/">Download Manager Tweak</a> &#8211; modifies the default appearance of the firefox download manager and allows it to be opened in a separate window, the sidebar, or a tab.</li>
<li><a href="http://downloadstatusbar.mozdev.org/">Download Statusbar</a> &#8211; is a browser extension that allows you to keep track of ongoing and completed downloads in a hide-away statusbar</li>
<li><a href="https://addons.mozilla.org/extensions/moreinfo.php?id=241">Disable Targets For Downloads</a> &#8211;  Prevents sites spawning blank windows when clicking binary downloads.</li>
<li><a href="http://fireftp.mozdev.org/">FireFTP</a> &#8211; is a free, secure, cross-platform FTP client for Mozilla Firefox which provides easy and intuitive access to FTP servers</li>
<li><a href="http://greasemonkey.mozdev.org/">GreaseMonkey</a> &#8211; Install user scripts and  change the behavior of any web page</li>
<li><a href="http://imagezoom.yellowgorilla.net/">Image Zoom</a> -<br />
Right click on an image and select a zoom option from the popup menu,<br />
or, hold down the right mouse button in combination with the mouse<br />
wheel to zoom in or out on an image.</li>
<li><a href="http://fasterfox.mozdev.org/">Fasterfox</a> &#8211; Speed up Firefox. Dynamic speed increases can be obtained with Fasterfox’s unique prefetching mechanism, which recycles idle bandwidth by silently loading and caching all of the links on the page you are browsing. Also tweaks many network <a href="http://www.quickonlinetips.com/archives/2005/12/50-best-firefox-extensions-for-power-surfing/#" style="text-decoration: underline ! important; position: static;" class="kLink" target="_top" id="KonaLink6"><font color="#0033cc" style="color: rgb(0, 51, 204) ! important; font-family: verdana,Arial,Helvetica,sans-serif; font-weight: 400; font-size: 12px; position: static;"><span style="border-bottom: 1px solid rgb(0, 51, 204); color: rgb(0, 51, 204) ! important; font-family: verdana,Arial,Helvetica,sans-serif; font-weight: 400; font-size: 12px; position: static; padding-bottom: 1px; background-color: transparent;" class="kLink"></span></font></a>and rendering settings. </li>
<li><a href="http://spellbound.sourceforge.net/">SpellBound</a> -<br />
enables spell checking in web forms such as html textarea / input<br />
elements (html input password elements are not checked by SpellBound)<br />
and rich text form elements. This allows you to spell check forms before submitting them.</li>
<li><a href="http://roachfiend.com/archives/2005/02/07/bugmenot">BugMeNot</a><br />
- Bypasses compulsory web registration using the BugMeNot without the<br />
hassle of surfing to it and querying its database everytime.</li>
<li><a href="http://autocopy.mozdev.org/">AutoCopy</a> &#8211; Select text on any web page and it will be automatically copied to the clipboard. Middle click to Paste.</li>
<li><a href="https://addons.mozilla.org/extensions/moreinfo.php?id=134">Copy Plain Text</a><br />
- Copies text without formatting. Have you ever copied something and<br />
been annoyed that the text formatting (bold, font size, etc) came with<br />
it? Don’t you wish you could just copy the text itself, without having<br />
to copy it, paste it into notepad, then copy it again?</li>
<li><a href="http://roachfiend.com/archives/2005/03/06/google-images-re-linker/">Google Images Re-Linker</a><br />
- This will let you click the thumbnail images on images.google.com,<br />
skip the referred framed page, and jump straight to the full-size image.</li>
<li><a href="http://v2studio.com/k/moz/">Stop-or-Reload Button</a> &#8211; Makes the Stop and Reload button behave like a single one (as in Safari).</li>
<li><a href="http://galeb.etf.bg.ac.yu/%7Eks040161d/firefox/extensions/esb/">Extended Statusbar</a><br />
- adds an Opera-like statusbar for Firefox that shows number of loaded<br />
images, bytes downloaded, average download speed, load time and<br />
percentage of the page loaded.</li>
<li><a href="http://www.extensionsmirror.nl/index.php?showtopic=2796">Resizeable Textarea</a> &#8211; Resize small textareas in forums to your needed size avoiding scrolling.</li>
<li><a href="http://adblockplus.org/en/">Adblock Plus</a> &#8211; is an enhanced version of Adblock. Block ads, applets, flash, embedded-media etc.</li>
<li><a href="http://flashblock.mozdev.org/">Flashblock</a> &#8211; blocks all Flash content from loading on a webpage.</li>
<li><a href="http://sage.mozdev.org/">Sage</a> &#8211; add a lightweight RSS and Atom feed aggregator which integrates with Firefox’s bookmark storage and Live Bookmarks.</li>
<li><a href="https://addons.mozilla.org/extensions/moreinfo.php?id=1453&#038;application=firefox">Cacheout!</a>- lets you try to access articles on servers affected by the Digg Effect /Slashdot Effect through Google’s caching service and CoralCDN.org.</li>
<li><a href="http://pearlcrescent.com/products/pagesaver/">Pearl Crescent Page Saver</a> &#8211; capture screenshots and save full webpages as images easily.</li>
<li><a href="http://reloadevery.mozdev.org/">Reload Every</a> &#8211; adds an<br />
option to the context menu to reload the web page you are viewing every<br />
so many seconds or minutes. Useful if you keep refreshing some pages<br />
often.</li>
<li><a href="http://copyurlplus.mozdev.org/">Copy URL+</a> &#8211; copy to<br />
the clipboard the current document’s address along with additional<br />
information such as the document’s title, the current selection or<br />
both. Customize it to add your own menu entries.</li>
<li><a href="http://informenter.mozdev.org/">InFormEnter</a> &#8211; adds a<br />
small, clickable icon next to every input field in a web form, from<br />
where you can select the item to be inserted with your frequently used<br />
information such as name, email, address and whatever else you want to<br />
be available from the form menu.</li>
<li><a href="http://firefox.exxile.net/">All-in-One Sidebar</a> &#8211; is a sidebar control, inspired by Opera that lets you quickly switch between sidebars, view dialog window<a href="http://www.quickonlinetips.com/archives/2005/12/50-best-firefox-extensions-for-power-surfing/#" style="text-decoration: underline ! important; position: static;" class="kLink" target="_top" id="KonaLink11"><font color="#0033cc" style="color: rgb(0, 51, 204) ! important; font-family: verdana,Arial,Helvetica,sans-serif; font-weight: 400; font-size: 12px; position: static;"><span style="color: rgb(0, 51, 204) ! important; font-family: verdana,Arial,Helvetica,sans-serif; font-weight: 400; font-size: 12px; position: static;" class="kLink"></span></font></a> such as downloads, extensions, and more in the sidebar, or view source code or websites in the sidebar. Can be extensively customized.</li>
<li><a href="http://www.splintered.co.uk/experiments/70/">Text size toolbar</a> &#8211; Adds buttons to increase or decrease text size or restore default size easily. Useful for those small unreadable font sizes.</li>
<li><a href="http://aluminum.sourmilk.net/reveal/"> Reveal</a> &#8211; allows you to see thumbnails of pages in your session history and quickly find the page you want.</li>
<li><a href="http://www.mystickies.com/">Mystickies</a> &#8211; allows you to place sticky notes all over the web and organize them with tags.</li>
<li><a href="https://addons.mozilla.org/extensions/moreinfo.php?application=firefox&#038;id=1801">Clear Cache Button</a> &#8211; Adds a clear cache toolbar button that cleans the cache in one click. Very handy for those who have use for it.</li>
<li><a href="https://addons.mozilla.org/firefox/918/">gTranslate</a> &#8211; translate any text in a webpage just by selecting and right-clicking over it. Uses the Google translation services.</li>
<li><a href="http://www.hypercubed.com/projects/firefox/">Xinha Here!</a> &#8211; is a wrapper for the Xinha HTML editor that enables WYSIWYG editing in any textarea and text box on any website.</li>
<li><a href="http://www.yoono.com/">Yoono</a> &#8211; instantly suggests alternate sites and people who share the same interests while you are surfing.</li>
<li><a href="http://www.adaptiveblue.com/">BlueOrganizer</a> &#8211; It helps you personalize your web experience based on what you already like, helping you discover relevant new information and save time.</li>
<li><a href="http://www.roundtwo.com/product/switchproxy">SwitchProxy</a><br />
- lets you manage and switch between multiple proxy configurations quickly and easily. You can also use it as an anonymizer to protect your computer from prying eyes.</li>
<li><a href="http://noscript.net/">NoScript</a> &#8211; allows JavaScript, Java (and other plugins) only for trusted domains of your choice. This whitelist based pre-emptive blocking approach prevents exploitation of security vulnerabilities with no loss of functionality</li>
<li><a href="http://roachfiend.com/archives/2005/03/03/always-remember-password/">Always Remember Password</a> &#8211; Instructs web sites to always remember your password. Some sites like Yahoo Mail, Hotmail, and banking sites instruct the browser to never allow your password manager to retain your information.</li>
<li><a href="http://cookieculler.mozdev.org/">CookieCuller</a> &#8211; Extended Cookie Manager to protect/unprotect selected cookies.</li>
<li><a href="https://addons.mozilla.org/extensions/moreinfo.php?id=1306&#038;application=firefox">Stealther</a> &#8211; surf the web without leaving a trace in your local computer by *temporarily disabling history (and address bar), cookies, formFill, disk cache and sending of ReferrerHeader. Verify details of what exactly it can work for you.</li>
<li><a href="http://toolbar.google.com/firefox/index.html">Google Toolbar for Firefox</a> &#8211; Lets you search google and all its services easily. Also powered by Google Suggest (Get query suggestions as you type in the search box), SpellCheck, AutoFill, Pagerank of webpage, access to gmail, WordTranslator etc.</li>
<li><a href="http://www.customizegoogle.com/">CustomizeGoogle</a> &#8211; enhances Google search results by adding extra information (like links to Yahoo, Ask Jeeves, MSN etc) and removing unwanted information (like ads and spam).</li>
<li><a href="http://nextplease.mozdev.org/">NextPlease!</a> &#8211; allows you to assign keyboard shortcuts to jump to next and previous links on search results pages, like Google, Yahoo, Ebay, Amazon, and many other sites.</li>
<li><a href="http://bettersearch.g-blog.net/">BetterSearch</a> &#8211; enhances Google, MSN Search, Yahoo Search, A9, Answers.com, AllTheWeb, Dogpile.com, del.icio.us and Simpy.com bookmarks by adding previews (thumbnails) and Amazon product images and info etc.</li>
<li><a href="https://addons.mozilla.org/firefox/735/">Answers</a> &#8211; Press Alt (or Option on a Mac) and click any word to get a quick, relevant definition or explanation, drawn from a collection of over 100 reference titles.</li>
<li><a href="https://addons.mozilla.org/extensions/moreinfo.php?id=500&#038;application=firefox">dsense Notifier</a> &#8211; Displays your Adsense earnings on the statusbar.</li>
<li><a href="http://users.rcn.com/shoofy/forecastfox_enhanced/">Forecastfox Enhanced</a><br />
- Get international weather forecasts and display it in any toolbar or statusbar. Now with improved radar images and allows for pausing, restarting and setting the frequency of automatic updates.</li>
<li><a href="http://dictionarysearch.mozdev.org/">DictionarySearch</a> &#8211; Looks up a user selected word in an online dictionary you selected.</li>
<li><a href="http://chrispederick.com/work/webdeveloper/">Web Developer</a> &#8211; Adds a menu and a toolbar with various essential web developer tools.</li>
</ul>
<ul class="related_post"><li><a href="http://www.tanasi.it/1118-how-to-create-firefox-extensions.html" title="How to create Firefox extensions">How to create Firefox extensions</a></li><li><a href="http://www.tanasi.it/1254-a-browser-as-web-hacking-platform.html" title="A browser as web hacking platform">A browser as web hacking platform</a></li><li><a href="http://www.tanasi.it/1235-mozilla-port-banning.html" title="Mozilla port banning">Mozilla port banning</a></li><li><a href="http://www.tanasi.it/1126-must-have-seo-firefox-extensions.html" title="Must Have SEO Firefox Extensions">Must Have SEO Firefox Extensions</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.tanasi.it/1053-useful-firefox-security-extensions.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
