{"id":913,"date":"2015-10-13T11:46:02","date_gmt":"2015-10-13T06:16:02","guid":{"rendered":"https:\/\/www.armourinfosec.com\/?p=913"},"modified":"2020-01-29T01:50:57","modified_gmt":"2020-01-28T20:20:57","slug":"best-firefox-addons-for-hacking","status":"publish","type":"post","link":"https:\/\/www.armourinfosec.com\/best-firefox-addons-for-hacking\/","title":{"rendered":"Best Firefox Addons for Hacking"},"content":{"rendered":"
<\/a>Firefox add-ons are useful for penetration testers and security analysts. These penetration testing add-ons helps in performing different kinds of attacks, and modify request headers direct from the browser. This way, it reduces the use of a separate tool for most of the penetration testing related tasks.<\/p>\n Stop tracking with \u201cDisconnect\u201d https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/disconnect\/<\/a><\/p>\n This add-on helps you perform various operations on cookies like viewing, searching, creating, and even editing them. Unlike the previous version of Hackbar, this one is compatible with firefox quantum also. This tool helps in testing sql injections, XSS holes and site security.<\/p>\n https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/hackbar-quantum\/?src=recommended<\/a><\/p>\n Encrypt the web! With this tool as your add-on, you can apply HTTPS ecryption automatically on all the sites even on those where https: prefix is omitted.<\/p>\n https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/https-everywhere\/<\/a><\/p>\n Allows you to customize the way a web page displays or behaves, by using small bits of JavaScript.<\/p>\n https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/greasemonkey\/<\/a><\/p>\n Its a lightweight web app bug finder. With the provision of custom injection lists, one can intercept and replay web requests.<\/p>\n https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/injector\/<\/a><\/p>\n This is among the coolest ones. You can spoof your user-agent so that it becomes impossible for websites to know specific details about our browser , thus protecting your identity and it also unlocks other utilities like some websites can be made to load much faster if you spoof your user-agent with a mobile device.<\/p>\n https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/user-agent-string-switcher\/<\/a><\/p>\n Its a simple to use plugin. It provides you with a menu of various xss payloads. With just one click it gets copied to clipboard and now all we have to do is to paste it in the desired input tag.<\/p>\n https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/easy-xss\/<\/a><\/p>\n While doing web app pentesting, its necessary to know the technologies and the software used in building the app and of course the version also. With wappalyzer, it can all be done with single click.<\/p>\n https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/wappalyzer\/<\/a><\/p>\n Its used in finding the technologies used behind a Web application. If Wappalyzer, misses something out, it can be verified with Buildwith.<\/p>\n https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/builtwith\/<\/a><\/p>\n It provides an interface to inspect the HTML, CSS , script code for the web page. You can also edit the code and it will display the current output.<\/p>\n https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/web-developer\/?src=search<\/a><\/p>\n Thats the first thing which pops up in mind when we are talking about online privacy,anonymity and encryption. It\u2019s a modified version of Firefox and it comes with pre-installed privacy add-ons, encryption and an advanced proxy.<\/p>\n https:\/\/www.torproject.org\/<\/a><\/p>\n – Monitor live requests Usage: Click the blue cloud in the toolbar to start tampering. When you’re done, click it again to stop.<\/p>\n https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/tamper-data-for-ff-quantum\/<\/a><\/p>\n An efficient blocker which at the same time is soft on CPU and memory. It can load and enforce thousands more filters than other popular blockers out there. https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/ublock-origin\/<\/a><\/p>\n This tool allows potentially malicious web content to run only from sites trusted by you. This tool also protects you from attacks like XSS and other web exploits. Its more of defensive rather than offensive tool, still worth trying.<\/span><\/p>\nStop Tracking ( Disconnect )<\/strong><\/span><\/h5>\n
\n– open source and
\n– loads pages 44% faster.
\n– save upto 39% of bandwidth
\n– stops tracking more than 2,000+ third-party sites
\n– keeps your searches private
\n– was named the best privacy tool by the New York Times (2016),<\/p>\nCookie Quick Manager<\/strong><\/span><\/h5>\n
\nhttps:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/cookie-quick-manager\/<\/a><\/p>\nHackBar Quantum<\/strong><\/span><\/h5>\n
HTTPS Everywhere<\/strong><\/span><\/h5>\n
Greasemonkey<\/strong><\/span><\/h5>\n
Injector<\/strong><\/span><\/h5>\n
User-Agent Switcher and Manager<\/strong><\/span><\/h5>\n
Easy XSS<\/strong><\/span><\/h5>\n
Wappalyzer<\/strong><\/span><\/h5>\n
BuiltWith<\/strong><\/span><\/h5>\n
Web developer<\/strong><\/span><\/h5>\n
Tor browser<\/strong><\/span><\/h5>\n
Tamper Data for FF Quantum<\/strong><\/span><\/h5>\n
\n– Edit headers on live requests
\n– Cancel live requests
\n– Redirect live requests<\/p>\nuBlock Origin<\/strong><\/span><\/h5>\n
\nUsage: The big power button in the popup is to permanently disable\/enable uBlock for the current web site. It applies to the current web site only, it is not a global power button.<\/p>\nNoScript Security Suite<\/strong><\/span><\/h5>\n