pen testing the web with firefox: add-on management

44
 Pen Testing the Web with Firefox: Add-on Management Michael “theprez98” Schearer 

Upload: michael-schearer

Post on 30-May-2018

223 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 1/44

 Pen Testing the Web

with Firefox: Add-onManagement

Michael “theprez98” Schearer 

Page 2: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 2/44

Add-on management

n Experimental add-onsn Version checksn

Ignoring version checksn Override compatibility checkingn Disabling compatibility checkingn Manual compatibility forcingn

Add-on utilities (CLEO/FEBE/OPIE)n Other useful add-ons (Xmarks)n Profiles

Page 3: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 3/44

Experimental add-ons

n Use at your own risk

n Newer add-ons which have not yet

undergone the public review processn May be alpha, beta or pre-production in

quality, performance and features

n You may have to explicitly select to viewexperimental add-ons

Page 4: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 4/44

Version checks

n By default, Firefox will not show you add-onsthat are not compatible with your currentinstalled version

n By default, Firefox will not allow you todownload or install add-ons that are for older versions

n Manually changing these settings will enable

you to view more add-ons (although thereis no guarantee that they will work)

Page 5: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 5/44

Page 6: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 6/44

Ignoring version checks

n Creating a Firefox account will allow youto sign in and ignore version checks; or 

n Viewing the source will enable you to findthe direct link to the add-on (.xpi) todownload manually

n

These methods will allow you to downloadbut Firefox still won’t install incompatibleversions

Page 7: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 7/44

Page 8: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 8/44

Page 9: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 9/44

Page 10: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 10/44

Page 11: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 11/44

Page 12: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 12/44

Override compatibility checking

1.Install Nightly Tester Tools add-on

2.Right-click on disabled add-ons and select

Override compatibility3.Override all compatibility option is

available but use with caution

Page 13: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 13/44

Page 14: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 14/44

Page 15: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 15/44

If NTT is already installed

Page 16: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 16/44

Disable compatibility checking

1.Type about:config in the browser bar 

2.Right-click and select New > Boolean

3.Enter preference nameextensions.checkCompatibility

4.Select false

5.Restart Firefox

Page 17: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 17/44

Page 18: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 18/44

Page 19: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 19/44

Page 20: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 20/44

Page 21: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 21/44

Page 22: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 22/44

Page 23: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 23/44

Page 24: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 24/44

Page 25: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 25/44

Page 26: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 26/44

Page 27: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 27/44

Page 28: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 28/44

Page 29: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 29/44

Page 30: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 30/44

Page 31: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 31/44

Page 32: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 32/44

Caveats to manual forcing

n This method works for many but not allincompatible add-ons; there is no

guarantee that this method will workn The more recent the add-on, the more

likely it will work

n

These steps are specific to using 7-Zipwith Windows; other programs may workbut you may have to modify the steps

Page 33: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 33/44

Add-on utilities

n Concerns:Add-on portability

Time consuming to manually install multipleadd-ons for multiple locations and devices

n Fixes:FEBE (Firefox Environment Backup

Extension)CLEO (Compact Library Extension Organizer)

OPIE (Ordered Preference Import/Export)

Page 34: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 34/44

Page 35: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 35/44

Page 36: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 36/44

OPIE

n Ordered Preference Import/Export allowsyou to import and export your installed

extension preferencesn Useful when installing extensions in a new

profile, or synchronizing multiple Firefoxinstallations

Page 37: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 37/44

Other useful add-ons (1)

n Xmarks provides seamless bookmarksynchronization between your 

computers and browsersn Adblock Plus blocks ads and banners

n NoScript allows active content to run only

from sites you trust, and protect yourself against XSS and clickjacking attacks

Page 38: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 38/44

Page 39: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 39/44

Profiles (1)

n Concerns:Too many add-ons!Duplicate tasksMemory use/time to load

n Fixes:Profile Manager 

n “Default”

n “Pen Testing” Install/load only those you use regularly

Page 40: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 40/44

Page 41: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 41/44

Page 42: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 42/44

If you uncheck “Don’t ask at startup” the

profile manager will load every time

Page 43: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 43/44

Authors and add-ons

n Edward Ackroyd (SearchPreview)n Chuck Baker (FEBE/CLEO/OPIE)

n Mime Cuvalo (FireFTP)n Giorgio Maone (NoScript)n Mossop (Nightly Tester Tools)n

Xmarks Inc. (Xmarks)n Wladimir Palant (Adblock Plus)

Page 44: Pen Testing the Web with Firefox: Add-on Management

8/14/2019 Pen Testing the Web with Firefox: Add-on Management

http://slidepdf.com/reader/full/pen-testing-the-web-with-firefox-add-on-management 44/44

 Pen Testing the Webwith Firefox: Add-onManagement

Michael “theprez98” Schearer