• Site Info
    h2


    Podango

    • podPress
    • Click to donate thru PayPal
    • Mighty Forums
    • Email
    • Instant Messenger

    FREE Security Scan from NT OBJECTives, Inc

    Create Animations With Stickman

    Custom Plugins

    Podcast/Blog
    h2

    Podcast Links

    • Podcast Feed
    • Blog Feed
    • View in iTunes
    • Mighty Seek on PodcastAlley.com
    • Mighty Seek on PodcastPickle.com
    • Sites that link to here
    • Podcasting Setup
    • Check out our Frappr!

    WebAppSec Links

    Categories

    Archives

    Yahoo


Mighty Seek
home
h1

FireFox Extensions

Mozilla FireFox - If your not using this browser for your normal browsing activity… you should.

There are enough security problems with IE to encourage such a choice, and if you want to do any security hacking/auditing this will become an invaluable tool.

One of the major benefits of FireFox comes in the form of the great number of extensions available. Here are some useful ones broken down into categories and some extensions are in multiple categories.

Extensions Useful for Web App Security Auditing

  • Web Developer - This plugin adds a toolbar full of useful tools for both web developers and web hackers alike.
  • SwitchProxy - Quickly and easily switch between your local proxy server and direct connections.
  • LiveHTTP Headers - This allows you to quickly view the header traffic to and from your browser without the need for connecting to a local proxy server
  • User Agent Switcher - This plugin allows you to quickly and easily change the User Agent string sent to the webserver. Sometimes apps are designed to generate different output based on the browser type and this could result in the execution of a different chunk of code.
  • JSView - Quickly and easily see a list of remote javascript files, and view them.


Extensions Useful for Web App Development

  • Web Developer - This plugin adds a toolbar full of useful tools for both web developers and web hackers alike.
  • SwitchProxy - Quickly and easily switch between your local proxy server and direct connections.
  • LiveHTTP Headers - This allows you to quickly view the header traffic to and from your browser without the need for connecting to a local proxy server
  • User Agent Switcher - This plugin allows you to quickly and easily change the User Agent string sent to the webserver. Sometimes apps are designed to generate different output based on the browser type and this could result in the execution of a different chunk of code.
  • JSView - Quickly and easily see a list of remote javascript files, and view them.
  • View Source Chart - Shows you the HTML table/div structure in a very appealing way. Awesome for debugging formatting problems.


Extensions Useful for Secure Browsing

  • NoScript - This allows javascript only for trusted domains. The icon at the bottom of your browser allows you to easily allow/block websites javascript execution. This means that PopUps and such are a non-issue when you visit a new site.
  • Permit Cookies - Like NoScript, but for cookies. By default sites are not allowed to put cookies on your system, but you are provided an easy interface for allowing/blocking. I find this to be great in avoiding web beacons and other such tracking of my browsing habits.
  • CookieCuller - Not an active security extension, but makes it easier to review your cookies and clean up ones you dont want.
  • FlashBlock - Blocks ALL Flash content from loading. It then leaves placeholders on the webpage that allow you to click to download and then view the Flash content. I find this as one of the best plugins for
  • LiveHTTP Headers - This allows you to quickly view the header traffic to and from your browser without the need for connecting to a local proxy server

Leave a Reply

 
Mighty Seek Podcast, MightySeek Podcast, Mighty Seek Blog, MightySeek Blog, Web application security podcast, Web application security blog, Web application development blog, Web application development podcast
Mighty Seek Podcast, MightySeek Podcast, Mighty Seek Blog, MightySeek Blog, Web application security podcast, Web application security blog, Web application development blog, Web application development podcast