One of the best tools we saw at LayerOne was the Exploit-Me series presented by [Dan Sinclair]. Security Compass created these tools to help developers easily identify cross site scripting (XSS) and SQL injection vulnerabilities.
Exploit-Me is a suite of Firefox web application security testing tools. Exploit-Me tools are designed to be lightweight and easy to use. Instead of using a proxy like many web application testing tools, Exploit-Me integrates directly with Firefox. It currently consists of two tools, one for XSS and one for SQL Injection. The Exploit-Me series was originally introduced at the SecTor conference. Authentication credentials were not provided. There are no ratings yet. Go to Mozilla's homepage. If you remember, there used to an add-on for Firefox – XSS Me; which unfortunately no longer works out of the box for the latest versions of the browser. It was also a part of the Firefox Addons for helping you with web application penetration testing. We now have something similar to it that works on Google Chrome – XSS Radar. Unfortunately, Firefox, Chrome, and Internet Explorer have implemented some techniques for preventing reflected xss attacks. These techniques look at the string passed as a parameter in the url.
XSS-Me is a Firefox add-on that loads in the sidebar. It identifies all the input fields on a page and iterates through a user provided list of XSS strings: opening new tabs and checking the results. When this process completes you get a report of what attacks got through, what didn’t, and what might have. The upcoming 0.3 version will use heuristics to determine what characters can be used and automatically skip attack strings that won’t get through.
The SQL Inject-Me works almost exactly the same way. It does require a little planning though: you need to tell it what you expect the results page to look like when an attack gets through.
The newest tool, Access-Me, surfs along with you while you’re authenticated to a website and checks whether you can see the same page unauthenticated.
Firefox add-ons are useful for penetration testers and security analysts. These penetration testing add-ons helps in performing different kinds of attacks, and modify request headers direct from the browser. This way, it reduces the use of a separate tool for most of the penetration testing related tasks.
Stop Tracking ( Disconnect )
Stop tracking with “Disconnect”
– open source and
– loads pages 44% faster.
– save upto 39% of bandwidth
– stops tracking more than 2,000+ third-party sites
– keeps your searches private
– was named the best privacy tool by the New York Times (2016),
Cookie Quick Manager
This add-on helps you perform various operations on cookies like viewing, searching, creating, and even editing them.
https://addons.mozilla.org/en-US/firefox/addon/cookie-quick-manager/
HackBar Quantum
Unlike the previous version of Hackbar, this one is compatible with firefox quantum also. This tool helps in testing sql injections, XSS holes and site security.
HTTPS Everywhere
Encrypt the web! With this tool as your add-on, you can apply HTTPS ecryption automatically on all the sites even on those where https: prefix is omitted.
Greasemonkey
Allows you to customize the way a web page displays or behaves, by using small bits of JavaScript.
Injector
Its a lightweight web app bug finder. With the provision of custom injection lists, one can intercept and replay web requests.
User-Agent Switcher and Manager
This is among the coolest ones. You can spoof your user-agent so that it becomes impossible for websites to know specific details about our browser , thus protecting your identity and it also unlocks other utilities like some websites can be made to load much faster if you spoof your user-agent with a mobile device.
Easy XSS
Xss Me For Firefox Version
Its a simple to use plugin. It provides you with a menu of various xss payloads. With just one click it gets copied to clipboard and now all we have to do is to paste it in the desired input tag.
Wappalyzer
While doing web app pentesting, its necessary to know the technologies and the software used in building the app and of course the version also. With wappalyzer, it can all be done with single click.
BuiltWith
Xss Me For Firefox Browser
Its used in finding the technologies used behind a Web application. If Wappalyzer, misses something out, it can be verified with Buildwith.
Web developer
It provides an interface to inspect the HTML, CSS , script code for the web page. You can also edit the code and it will display the current output.
Tor browser
Thats the first thing which pops up in mind when we are talking about online privacy,anonymity and encryption. It’s a modified version of Firefox and it comes with pre-installed privacy add-ons, encryption and an advanced proxy.
Tamper Data for FF Quantum
– Monitor live requests
– Edit headers on live requests
– Cancel live requests
– Redirect live requests
Usage: Click the blue cloud in the toolbar to start tampering. When you’re done, click it again to stop.
uBlock Origin
An efficient blocker which at the same time is soft on CPU and memory. It can load and enforce thousands more filters than other popular blockers out there.
Usage: The big power button in the popup is to permanently disable/enable uBlock for the current web site. It applies to the current web site only, it is not a global power button.
NoScript Security Suite
This tool allows potentially malicious web content to run only from sites trusted by you. This tool also protects you from attacks like XSS and other web exploits. Its more of defensive rather than offensive tool, still worth trying.
anonymoX
AnonymoX is an initiative for anonymization on the internet. The aim is to restore the users right of anonymity in the web. Most websites monitor the behaviour of their users, giving the websites hosts the ability to analyze the general users behaviour and create detailed user profiles, which are frequently sold to third parties.
A threat for freedom of speech on the internet manifests in the repression through federal or private organizations. More and more governments censor websites with the excuse of child safety, copyright infringement or the fight against terrorism and thereby limit the freedom of speech.
Easy anonymous web browsing.
– Change your IP-Address and country
– Visit blocked or censored websites.
Xss Me For Firefox Free
Xss Me For Firefox Windows 10
– Delete cookies, show your public ip, and more
Comments are closed.