<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="http://unfoldingneurons.com/"
	>

<channel>
	<title>a4apphack &#187; Secfox</title>
	<atom:link href="http://a4apphack.com/tag/secfox/feed" rel="self" type="application/rss+xml" />
	<link>http://a4apphack.com</link>
	<description>Get more out of the Apps!</description>
	<lastBuildDate>Thu, 26 Apr 2012 15:44:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<image>
<link>http://a4apphack.com</link>
<url>http://a4apphack.com/blog/wp-content/themes/primus/favicon.ico</url>
<title>a4apphack</title>
</image>
		<item>
		<title>13 Chrome Extensions for Security Testers</title>
		<link>http://a4apphack.com/featured/13-chrome-extensions-for-security-testers</link>
		<comments>http://a4apphack.com/featured/13-chrome-extensions-for-security-testers#comments</comments>
		<pubDate>Mon, 17 May 2010 02:01:48 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Browser]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[Secfox]]></category>
		<category><![CDATA[va]]></category>

		<guid isPermaLink="false">http://a4apphack.com/index.php/?p=1967</guid>
		<description><![CDATA[This post lists 13 Chrome Extensions to aid security testers during their web application pen testing. 1. WebDeveloper Adds a toolbar button with various web developer tools. The official port of the Web Developer extension for Firefox. Internal post here. 2. Firebug Lite Firebug Lite provides the rich visual representation we are used to see [...]]]></description>
			<content:encoded><![CDATA[<p>This post lists 13 Chrome Extensions to aid security testers during their web application pen testing.</p>
<h3>1. WebDeveloper</h3>
<div>
<div>Adds a toolbar button with various web developer tools. The official port of the Web Developer extension for Firefox. Internal post <a title="here" href="http://a4apphack.com/index.php/featured/pendule-webdeveloper-equivalent-in-chrome-for-security-analysts">here</a>.</div>
</div>
<div><a href="https://chrome.google.com/extensions/detail/bfbameneiokkgbdmiekhjnmfkcnldhhm "><img class="alignnone" title="WebDeveloper" src="http://img.a4apphack.com/chromesecextn-webdeveloper.jpg" alt="WebDeveloper" width="600" height="277" /></a></div>
<h3>2. Firebug Lite</h3>
<div>
<div>Firebug Lite provides the rich visual representation we are used to see in Firebug when it comes to HTML elements, DOM elements, and Box Model shading</div>
</div>
<div><a href="https://chrome.google.com/extensions/detail/bmagokdooijbeehmkpknfglimnifench "><img class="alignnone" title="Firebug Lite" src="http://img.a4apphack.com/chromesecextn-firebug.jpg " alt="Firebug Lite" width="600" height="332" /></a></div>
<h3>3. Pendule</h3>
<div>
<div>This addon is similar to webdeveloper but not as powerful as it is. Internal Post <a title="here" href="http://a4apphack.com/index.php/featured/pendule-webdeveloper-equivalent-in-chrome-for-security-analysts">here</a>.</div>
</div>
<div><a href="https://chrome.google.com/extensions/detail/gbkffbkamcejhkcaocmkdeiiccpmjfdi "><img class="alignnone" title="Pendule" src="http://img.a4apphack.com/chromesecextn-pendule.jpg" alt="Pendule" width="600" height="271" /></a></div>
<p><span id="more-1967"></span></p>
<h3>4. Chrome Web Developer Tools</h3>
<div>
<div>Tool to dynamically view and modify HTML elements.</div>
</div>
<div><a href="https://chrome.google.com/extensions/detail/fbmlldeibipeppiabbdjajcneipfbocm "><img class="alignnone" title="Chrome Web Dev Tools" src="http://img.a4apphack.com/chromesecextn-chromewebdevtools.jpg" alt="Chrome Web Dev Tools" width="600" height="269" /></a></div>
<h3>5. Simple REST Client</h3>
<div>
<div>Construct custom HTTP requests to directly test your web services.</div>
</div>
<div><a href="https://chrome.google.com/extensions/detail/fhjcajmcbmldlhcimfajhfbgofnpcjmb "><img class="alignnone" title="Simple REST Client" src="http://img.a4apphack.com/chromesecextn-simplerestclient.jpg" alt="Simple REST Client" width="600" height="433" /></a></div>
<h3>6. View Selection Source</h3>
<div>
<div>View selection source in resizable popup. Drag the bottom right corner to resize. Simple, but very useful for web developers.</div>
</div>
<div><a href="https://chrome.google.com/extensions/detail/fbhgckgfljgjkkfngcoeajbgndkeoaaj "><img class="alignnone" title="View Selection Source" src="http://img.a4apphack.com/chromesecextn-viewselsource.jpg" alt="View Selection Source" width="600" height="342" /></a></div>
<h3>7. Domain Details</h3>
<div>
<div>Shows server&#8217;s IP address, country flag, software, headers, and provides links to whois reports. This is similar to the <a title="Domain Details addon for Firefox" href="http://a4apphack.com/index.php/featured/secfox-http-header-analysis-domain-details-part-2">Domain Details addon for Firefox</a></div>
</div>
<div><a href="https://chrome.google.com/extensions/detail/ekgdjkmnfildhenmlbefaajoljlkekfg "><img class="alignnone" title="Domain Details" src="http://img.a4apphack.com/chromesecextn-domaindetails.jpg" alt="Domain Details" width="600" height="329" /></a></div>
<h3>8. Chrome Sniffer</h3>
<div>
<div>Detect web frameworks and javascript libraries run on browsing website.</div>
<div>At the time of writing, this extension identifies the following apps/frameworks</div>
<div>
<p><strong>Blogging Services</strong></p>
<ul>
<li>Tumblr</li>
</ul>
<p><strong>Web Application</strong></p>
<ul>
<li>vBulletin</li>
<li>SMF</li>
<li>phpBB</li>
<li>IPB</li>
<li>miniBB</li>
<li>Drupal</li>
<li>Ubercart</li>
<li>WordPress</li>
<li>bbPress</li>
<li>Movable Type</li>
<li>MediaWiki</li>
<li>DokuWiki</li>
<li>Joomla</li>
<li>Magento</li>
<li>Xoops</li>
<li>Plone</li>
<li>CMS Made Simple</li>
<li>SilverStripe</li>
<li>MODx</li>
<li>Amiro.CMS</li>
<li>Koobi</li>
<li>LifeRay</li>
<li>PHP Fusion</li>
<li>PHP Nuke</li>
<li>WebGUI</li>
<li>ezPublish</li>
<li>DotNetNuke</li>
<li>Sitefinity</li>
</ul>
<p><strong>Javascript framework &amp; tools</strong></p>
<ul>
<li>jQuery &amp; jQuery UI</li>
<li>ExtJS</li>
<li>Prototype</li>
<li>Closure</li>
<li>MooTools</li>
<li>Dojo</li>
<li>script.aculo.us</li>
<li>YUI</li>
<li>Google Analytics</li>
<li>Disqus</li>
<li>GetSatisfaction</li>
<li>Wibiya</li>
<li>reCaptcha</li>
<li>Mollom</li>
</ul>
</div>
</div>
<div><a href="https://chrome.google.com/extensions/detail/homgcnaoacgigpkkljjjekpignblkeae "><img class="alignnone" title="Chrome Sniffer" src="http://img.a4apphack.com/chromesecextn-chromesniffer.jpg" alt="Chrome Sniffer" width="359" height="162" /></a></div>
<h3>9. User-Agent Switcher</h3>
<div>
<div>Spoofs &amp; Mimics navigator.userAgent and navigator, vendor strings for specific sites.</div>
</div>
<div><a href="https://chrome.google.com/webstore/detail/djflhoibgkdhkhhcedjiklpkjnoahfmg"><img class="alignnone" title="User Agent Switcher" src="http://img.a4apphack.com/chromesecextn-useragentswitcher.jpg" alt="User Agent Switcher" width="600" height="301" /></a></div>
<h3>10. Unencrypted Password Warning</h3>
<div>
<div>Unencrypted Password Warning detects whether a password or credit card number is about to be sent with a form that does not use HTTPS.</div>
</div>
<div><a href="https://chrome.google.com/extensions/detail/mjpinemnkjlppmemjfabdaelpfgfjgkj "><img class="alignnone" title="Unencrypted Password Warning" src="http://img.a4apphack.com/chromesecextn-httppasswarning.jpg" alt="Unencrypted Password Warning" width="600" height="276" /></a></div>
<h3>11. JSONView</h3>
<div>
<div>JSONView for chrome is an extension that helps you view JSON documents in the browser.</div>
</div>
<div><a href="https://chrome.google.com/extensions/detail/chklaanhfefbnpoihckbnefhakgolnmc "><img class="alignnone" title="JSON View" src="http://img.a4apphack.com/chromesecextn-jsonview.jpg" alt="JSON View" width="600" height="294" /></a></div>
<h3>12. Cookie Editor</h3>
<p>View and Edit the Cookies created by the site visible in the active page</p>
<p><a href="https://chrome.google.com/extensions/detail/mkfjmbbghhjglaldohfnmccfofoogbik?hl=en"><img class="alignnone" title="Cookie Editor" src="http://img.a4apphack.com/chromesecextn-cookieedit.jpg" alt="Cookie Editor" width="602" height="474" /></a></p>
<h3>13. Light Shot</h3>
<div>
<div>Easy and convenient screen capture tool. Allows you to make screenshot of any selected area, edit and upload it to server. (Not really a security tool, but this can be of help to capture evidences)</div>
</div>
<div><a href="https://chrome.google.com/extensions/detail/mbniclmhobmnbdlbpiphghaielnnpgdp "><img class="alignnone" title="LightShot" src="http://img.a4apphack.com/chromesecextn-lightshot.jpg" alt="LightShot" width="600" height="316" /></a></div>
<h3>14. Note Anywhere (Bonus)</h3>
<div>
<div>With this ext, you can make notes on any web page, any position. The notes get loaded automatically whenever the page is opened. (Not really a security tool, but this can be of help to quickly jot comments on the pages where further investigation is to be done later.)</div>
</div>
<div><a href="https://chrome.google.com/extensions/detail/bohahkiiknkelflnjjlipnaeapefmjbh "><img class="alignnone" title="Note Anywhere" src="http://img.a4apphack.com/chromesecextn-noteanywhere.jpg" alt="Note Anywhere" width="600" height="305" /></a></div>
<p>&nbsp;</p>
<p>&nbsp;</p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1967&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/featured/13-chrome-extensions-for-security-testers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WebDeveloper Extension for Chrome for Security Analysts</title>
		<link>http://a4apphack.com/featured/webdeveloper-extension-for-chrome-for-security-analysts</link>
		<comments>http://a4apphack.com/featured/webdeveloper-extension-for-chrome-for-security-analysts#comments</comments>
		<pubDate>Thu, 25 Mar 2010 23:15:39 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[Secfox]]></category>
		<category><![CDATA[webdesign]]></category>

		<guid isPermaLink="false">http://a4apphack.com/index.php/?p=1721</guid>
		<description><![CDATA[I had mentioned in my previous post about Pendule – WebDeveloper Equivalent In Chrome, but lately the developer of WebDeveloper has released Chrome compatible version of this popular Firefox addon. WebDeveloper is definitely a favorite tool used by application security analysts and now it comes handy when you are testing your target in chrome. I [...]]]></description>
			<content:encoded><![CDATA[<p>I had mentioned in my previous post about <a title="Pendule – WebDeveloper Equivalent In Chrome For Security Analysts" href="http://a4apphack.com/index.php/featured/pendule-webdeveloper-equivalent-in-chrome-for-security-analysts">Pendule – WebDeveloper Equivalent In Chrome</a>, but lately the developer of WebDeveloper has released Chrome compatible version of this popular Firefox addon. WebDeveloper is definitely a favorite tool used by application security analysts and now it comes handy when you are testing your target in chrome. I think I&#8217;ll have to start a new series like <a title="SecFox Series" href="http://a4apphack.com/index.php/tag/secfox">SecFox</a>, for Chrome.</p>
<div class="wp-caption alignnone" style="width: 610px"><a href="http://img.a4apphack.com/webdeveloperchrome-main.jpg" rel="lightbox[1721]" title="WebDeveloper For Chrome"><img title="WebDeveloper For Chrome" src="http://img.a4apphack.com/webdeveloperchrome-main.jpg" alt="WebDeveloper For Chrome" width="600" height="276" /></a><p class="wp-caption-text">WebDeveloper For Chrome (Click to Zoom)</p></div>
<p><span id="more-1721"></span></p>
<p><strong>Features (That can aid Security Testing)</strong></p>
<ul>
<li>Clear Radio Buttons</li>
<li>Convert GET to POST and POST to GET</li>
<li>Convert Select Elements to Text input</li>
<li>Display Form Details</li>
<li>Enable Form Fields</li>
<li>Make Form Fields Writable</li>
<li>Remove Maxlength</li>
<li>Show Passwords</li>
<li>View Form Info</li>
<li>Disable Image Alt Attributes</li>
<li>Show Hidden Elements</li>
<li>and much more&#8230; </li>
</ul>
<p>NOTE: The Chrome compatible version doesn&#8217;t seem to be as stable as the one which is available for Firefox, but we can hope for the updates.</p>
<p><br class="spacer_" /></p>
<p><a title="WebDeveloper For Chrome" href="https://chrome.google.com/extensions/detail/bfbameneiokkgbdmiekhjnmfkcnldhhm"><strong>WebDeveloper for Chrome</strong></a></p>
<p><br class="spacer_" /></p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1721&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/featured/webdeveloper-extension-for-chrome-for-security-analysts/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Subscribe to SecFox &#8211; Firefox Addon Collections</title>
		<link>http://a4apphack.com/featured/subscribe-to-secfox-firefox-addon-collections</link>
		<comments>http://a4apphack.com/featured/subscribe-to-secfox-firefox-addon-collections#comments</comments>
		<pubDate>Wed, 13 Jan 2010 19:29:34 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Browser]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[addons]]></category>
		<category><![CDATA[appsec]]></category>
		<category><![CDATA[Secfox]]></category>

		<guid isPermaLink="false">http://a4apphack.com/index.php/?p=1630</guid>
		<description><![CDATA[Stay updated with addons discussed in the SecFox series, the most popular section of this blog. For that you need to subscribe to the SecFox addon collection available in the mozilla addons site. SecFox is collection of addons which can be used to customize any firefox to a security assessment tool. At the time of [...]]]></description>
			<content:encoded><![CDATA[<p>Stay updated with addons discussed in the <a title="SecFox Series" href="http://a4apphack.com/index.php/tag/secfox">SecFox series</a>, the most popular section of this blog. For that you need to subscribe to the SecFox addon collection available in the mozilla addons site.</p>
<p>SecFox is collection of addons which can be used to customize any firefox to a security assessment tool. At the time of writing this collection has 40+ addons which can help the web app sec testers during their assessments.</p>
<p><span id="more-1630"></span>An &#8216;<a title="Add-on Collector" href="https://addons.mozilla.org/en-US/firefox/pages/collector">addon collector</a>&#8216; addon is to be installed to get the SecFox updates. So if any new addon added to SecFox collection gives an alert to the subscriber.</p>
<p>Check the video below which explains how.</p>
<p><object type="application/x-shockwave-flash" style="width:600px;height:440px" data="http://www.youtube.com/v/mzryNGYmvjg&amp;hl=en&amp;fs=1"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="quality" value="best" /><param name="wmode" value="transparent" /><param name="movie" value="http://www.youtube.com/v/mzryNGYmvjg&amp;hl=en&amp;fs=1" /><param name="pluginspage" value="http://www.macromedia.com/go/getflashplayer" />If you can see this, then you might need a Flash Player upgrade or you need to install Flash Player if it's missing. Get <a href="http://get.adobe.com/flashplayer/" target="_blank">Flash Player</a> from Adobe.</object><br/>
		<!-- Valid XHTML flash object delivered by XHTML Video Embed. Get it at: http://saltwaterc.net/xhtml-video-embed -->
		</p>
<p><strong>Download Secfox Collection :</strong> <a target="_blank" href="https://addons.mozilla.org/en-US/firefox/collection/secfox"><img style="vertical-align: middle;" height="30" width="30" alt="Download" src="http://img.a4apphack.com/site/a4apphack-download.png" title="Download"/></a></p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1630&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/featured/subscribe-to-secfox-firefox-addon-collections/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<series:name><![CDATA[Secfox]]></series:name>
	</item>
		<item>
		<title>Secfox &#8211; Addons for Cookie Analysis And Manipulation</title>
		<link>http://a4apphack.com/featured/secfox-addons-for-cookie-analysis-and-manipulation</link>
		<comments>http://a4apphack.com/featured/secfox-addons-for-cookie-analysis-and-manipulation#comments</comments>
		<pubDate>Wed, 16 Dec 2009 19:57:00 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Browser]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[access]]></category>
		<category><![CDATA[addons]]></category>
		<category><![CDATA[Secfox]]></category>
		<category><![CDATA[youtube]]></category>

		<guid isPermaLink="false">http://a4apphack.com/index.php/?p=1604</guid>
		<description><![CDATA[In this part of the Secfox series, we will be discussing about the addons that can help us during the app security assessments which involves cookie analysis and manipulation. These addons can be of huge help when we perform the type of tests mentioned below. Cookie Prediction Session Fixation Cookie Persistence/Expiration Broken Session Management Traditional Method [...]]]></description>
			<content:encoded><![CDATA[<p>In this part of the Secfox series, we will be discussing about the addons that can help us during the app security assessments which involves cookie analysis and manipulation.</p>
<p>These addons can be of huge help when we perform the type of tests mentioned below.</p>
<ul>
<li>Cookie Prediction</li>
<li>Session Fixation</li>
<li>Cookie Persistence/Expiration</li>
<li>Broken Session Management</li>
</ul>
<h3>Traditional Method</h3>
<p>We use a proxy interceptor like Paros/Burp/WebScarab to trap the HTTP requests and modify the values during its transit. For this to happen, we need to setup a proxy and ensure that it listens to the browser traffic. An additional step is required if the application uses an SSL connection, i.e. to store the Proxy&#8217;s forged certificate in the browser. The intercepted request enables us to add new cookies or modify the existing ones. We can also check when exactly are the cookie values issued and whether it is getting flushed upon session expiration.</p>
<h3>Usage of Addons</h3>
<p>We have various addons for firefox which makes the tasks mentioned above easier. Certain addons allow to view the cookies stored in the browser and others allows us to edit it. The advantage &#8211; we don&#8217;t need any proxy to do this job, we can view/edit from the browser itself.</p>
<p><strong>1. View Cookies</strong></p>
<p>This addon adds a tab in the &#8216;Page Info&#8217; box available on the Firefox context menu.</p>
<div class="wp-caption alignnone" style="width: 610px"><a title="View Cookies Addon" href="http://img.a4apphack.com/secfox-cookiemanip-viewcookie.jpg" rel="lightbox[1604]"><img class="" title="View Cookies Addon" src="http://img.a4apphack.com/secfox-cookiemanip-viewcookie.jpg" alt="View Cookies Addon" width="600" height="422" /></a><p class="wp-caption-text">View Cookies Addon</p></div>
<p><strong>Download Link:</strong> <a target="_blank" href="https://addons.mozilla.org/en-US/firefox/addon/315"><img style="vertical-align: middle;" height="30" width="30" alt="Download" src="http://img.a4apphack.com/site/a4apphack-download.png" title="Download"/></a></p>
<hr />
<p><strong>2. Add N Edit Cookies</strong></p>
<p>This addon integrates a Cookie Editor to firefox. This also allows us to edit the attributes of the cookie.</p>
<div class="wp-caption alignnone" style="width: 360px"><a title="Add n Edit Cookies Addon" href="http://img.a4apphack.com/secfox-cookiemanip-addnedit.jpg" rel="lightbox[1604]"><img class="" title="Add n Edit Cookies Addon" src="http://img.a4apphack.com/secfox-cookiemanip-addnedit.jpg" alt="Add n Edit Cookies Addon" width="350" height="257" /></a><a href="http://img.a4apphack.com/secfox-cookiemanip-addnedit.jpg"></a><p class="wp-caption-text">Add n Edit Cookies Addon</p></div>
<p><strong>Download Link:</strong> <a target="_blank" href="https://addons.mozilla.org/en-US/firefox/addon/13793"><img style="vertical-align: middle;" height="30" width="30" alt="Download" src="http://img.a4apphack.com/site/a4apphack-download.png" title="Download"/></a></p>
<p><span id="more-1604"></span></p>
<hr />
<p>3. <strong>FireCookie</strong></p>
<p>If you are using Firebug a lot, then cookies are easily accessible inside firebug tabs if you have FireCookie installed.</p>
<div class="wp-caption alignnone" style="width: 610px"><a title="FireCookie Addon" href="http://img.a4apphack.com/secfox-cookiemanip-firecookie.jpg" rel="lightbox[1604]"><img class="" title="FireCookie Addon" src="http://img.a4apphack.com/secfox-cookiemanip-firecookie.jpg" alt="FireCookie Addon" width="600" height="165" /></a><p class="wp-caption-text">FireCookie Addon</p></div>
<p><strong>Download Link:</strong> <a target="_blank" href="https://addons.mozilla.org/en-US/firefox/addon/6683"><img style="vertical-align: middle;" height="30" width="30" alt="Download" src="http://img.a4apphack.com/site/a4apphack-download.png" title="Download"/></a></p>
<hr />
<p><strong>4. Cookie Swap</strong></p>
<p>This is an amazing addon which helps us to switch between various cookie profiles. This addon saves all the cookies for a particular domain to the chosen profile. These profiles can be managed through a Profile Manager which comes with the tool. One can add and organize the profile which can be easily swapped from the Firefox status bar. This is of great use if you are testing the application which has multiple login credentials.</p>
<div class="wp-caption alignnone" style="width: 410px"><a title="Cookie Swap - Status Bar" href="http://img.a4apphack.com/secfox-cookiemanip-cookieswap.jpg" rel="lightbox[1604]"><img class="" title="Cookie Swap - Status Bar" src="http://img.a4apphack.com/secfox-cookiemanip-cookieswap.jpg" alt="Cookie Swap - Status Bar" width="400" height="226" /></a><p class="wp-caption-text">Cookie Swap - Status Bar</p></div>
<div class="wp-caption alignnone" style="width: 360px"><a title="Cookie Swap - Manage Profiles" href="http://img.a4apphack.com/secfox-cookiemanip-cookieswapmanage.jpg" rel="lightbox[1604]"><img class="" title="Cookie Swap - Manage Profiles" src="http://img.a4apphack.com/secfox-cookiemanip-cookieswapmanage.jpg" alt="Cookie Swap - Manage Profiles" width="350" height="239" /></a><p class="wp-caption-text">Cookie Swap - Manage Profiles</p></div>
<p><strong>Download Link: </strong><a target="_blank" href="Download"><img style="vertical-align: middle;" height="30" width="30" alt="Download" src="http://img.a4apphack.com/site/a4apphack-download.png" title="Download"/></a></p>
<hr />
<p><strong>5. WebDeveloper &#8211; View Cookies</strong></p>
<p>Web developer has a built-in cookie viewer and editor. Once you select on &#8216;View Cookies&#8217; available under the &#8216;Cookies&#8217; menu, a new tab is displayed with a big list of cookies for that particular domain and options to edit it. I prefer using &#8216;Add n Edit Cookie&#8217; to this addon.</p>
<div class="wp-caption alignnone" style="width: 510px"><a title="WebDeveloper - View Cookies" href="http://img.a4apphack.com/secfox-cookiemanip-webdeveloper.jpg" rel="lightbox[1604]"><img class="" title="WebDeveloper - View Cookies" src="http://img.a4apphack.com/secfox-cookiemanip-webdeveloper.jpg" alt="WebDeveloper - View Cookies" width="500" height="316" /></a><p class="wp-caption-text">WebDeveloper - View Cookies</p></div>
<p><strong>Download Link:</strong> <a target="_blank" href="https://addons.mozilla.org/en-US/firefox/addon/60"><img style="vertical-align: middle;" height="30" width="30" alt="Download" src="http://img.a4apphack.com/site/a4apphack-download.png" title="Download"/></a></p>
<hr />
<h3>Video Demo</h3>
<p>Watch the following video. Here, I quickly go through each of the addon I&#8217;d mentioned above.</p>
<p><object type="application/x-shockwave-flash" style="width:600px;height:440px" data="http://www.youtube.com/v/5i4aXl7vx_g&amp;hl=en&amp;fs=1"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="quality" value="best" /><param name="wmode" value="transparent" /><param name="movie" value="http://www.youtube.com/v/5i4aXl7vx_g&amp;hl=en&amp;fs=1" /><param name="pluginspage" value="http://www.macromedia.com/go/getflashplayer" />If you can see this, then you might need a Flash Player upgrade or you need to install Flash Player if it's missing. Get <a href="http://get.adobe.com/flashplayer/" target="_blank">Flash Player</a> from Adobe.</object><br/>
		<!-- Valid XHTML flash object delivered by XHTML Video Embed. Get it at: http://saltwaterc.net/xhtml-video-embed -->
		</p>
<p>Stay tuned&#8230; Secfox will continue&#8230;.</p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1604&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/featured/secfox-addons-for-cookie-analysis-and-manipulation/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<series:name><![CDATA[Secfox]]></series:name>
	</item>
		<item>
		<title>Secfox &#8211; GroundSpeed, Client Side Data Manipulation From Sidebar</title>
		<link>http://a4apphack.com/featured/secfox-groundspeed-client-side-manipulation-a-click-away</link>
		<comments>http://a4apphack.com/featured/secfox-groundspeed-client-side-manipulation-a-click-away#comments</comments>
		<pubDate>Tue, 15 Dec 2009 00:57:17 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Browser]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[addons]]></category>
		<category><![CDATA[Secfox]]></category>

		<guid isPermaLink="false">http://a4apphack.com/index.php/?p=1593</guid>
		<description><![CDATA[Pen testers fondly use webproxy a lot to manipulate the HTTP requests created by the browser before it is sent to the web sever. This helps us to verify the the absence of any server side validations or flaw in the client side validations. But feel lucky if you are using Firefox while performing web [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>Pen testers fondly use webproxy a lot to manipulate the HTTP requests created by the browser before it is sent to the web sever. This helps us to verify the the absence of any server side validations or flaw in the client side validations. But feel lucky if you are using Firefox while performing web app security assessments, &#8217;cause we have a cool extension &#8216;GroundSpeed&#8217; which exactly does that.</p>
<p>I dont want to blabber much on describing how it works since the author has a nice writeup in his GroundSpeed homepage.</p>
<blockquote><p>&#8220;Groundspeed is an open-source Firefox extension that manipulates the interface of web applications in order to make the life of the security tester easier. It allows security testers to manipulate the way they interact with the web application’s user interface by manipulating the forms and form elements, eliminating annoying limitations and client-side controls.</p>
<p>Some of the practical uses of Groundspeed include changing the types of form fields, like for example changing hidden fields into text fields, removing size and length limitations on input fields and modifying any JavaScript event handlers to bypass client side validation.</p>
<p>Groundspeed works by dynamically modifying the Document Object Model (DOM) of the page after Firefox has finished loading and rendering it. The changes take effect immediately and, since it happens entirely on the client side without generating new requests to the server, it is completely transparent to the application.&#8221;</p>
</blockquote>
<p><span id="more-1593"></span></p>
<p><strong>Check the video</strong></p>
<p><object type="application/x-shockwave-flash" style="width:600px;height:440px" data="http://www.vimeo.com/moogaloop.swf?clip_id=7465799&amp;server=www.vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="quality" value="best" /><param name="wmode" value="transparent" /><param name="movie" value="http://www.vimeo.com/moogaloop.swf?clip_id=7465799&amp;server=www.vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0" /><param name="pluginspage" value="http://www.macromedia.com/go/getflashplayer" />If you can see this, then you might need a Flash Player upgrade or you need to install Flash Player if it's missing. Get <a href="http://get.adobe.com/flashplayer/" target="_blank">Flash Player</a> from Adobe.</object><br/>
		<!-- Valid XHTML flash object delivered by XHTML Video Embed. Get it at: http://saltwaterc.net/xhtml-video-embed -->
		</p>
<p><strong>Conclusion</strong></p>
<p>Whatever GroundSpeed can do can be done with Firebug, but this makes life super easy. We might tend to mess the HTML code displayed in the firebug window. But with GroundSpeed, we exactly achieve want we want. Another advantage of this addon compared to firebug is that this helps us to minimize the time wasted in searching for the variable names and the attributes which we intend to change if we had used Firebug.</p>
<p>As the author quotes, Firebug is meant for Developers and GroundSpeed for PenTesters. We hope that there will be many enhancements in the future so as to make this a full fledged PenTest addon.</p>
<h3>Gallery</h3>
<div class="wp-caption alignnone" style="width: 260px"><a title="GroundSpeed Conversions" href="http://img.a4apphack.com/groundspeed-conversions.png" rel="lightbox[1593]"><img class="" title="GroundSpeed Conversions" src="http://img.a4apphack.com/groundspeed-conversions.png" alt="GroundSpeed Conversions" width="250" height="459" /></a><p class="wp-caption-text">GroundSpeed Conversions</p></div>
<div class="wp-caption alignnone" style="width: 260px"><a title="GroundSpeed Conversions" href="http://img.a4apphack.com/groundspeed-removelength.jpg" rel="lightbox[1593]"><img class="" title="GroundSpeed - Remove Max Length" src="http://img.a4apphack.com/groundspeed-removelength.jpg" alt="GroundSpeed - Remove Max Length" width="250" height="168" /></a><p class="wp-caption-text">GroundSpeed - Remove Max Length</p></div>
<p><br class="spacer_" /></p>
<p><strong>Install GroundSpeed Firefox Addon:</strong> <a target="_blank" href="https://addons.mozilla.org/en-US/firefox/addon/46698"><img style="vertical-align: middle;" height="30" width="30" alt="Download" src="http://img.a4apphack.com/site/a4apphack-download.png" title="Download"/></a></p>
<p><br class="spacer_" /></p>
<p><a href="http://groundspeed.wobot.org/"><img class="alignnone" title="GroundSpeed Logo" src="http://img.a4apphack.com/groundspeed-logo.jpg" alt="" width="188" height="50" /></a></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
</div>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1593&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/featured/secfox-groundspeed-client-side-manipulation-a-click-away/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<series:name><![CDATA[Secfox]]></series:name>
	</item>
		<item>
		<title>Secfox &#8211; Hackbar, Audit / Penetration Test Tool in Firefox</title>
		<link>http://a4apphack.com/security/hackbar-audit-penetration-test-tool</link>
		<comments>http://a4apphack.com/security/hackbar-audit-penetration-test-tool#comments</comments>
		<pubDate>Thu, 19 Feb 2009 06:59:00 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[addons]]></category>
		<category><![CDATA[appsec]]></category>
		<category><![CDATA[automate]]></category>
		<category><![CDATA[Secfox]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://a4apphack.com/blog/?p=686</guid>
		<description><![CDATA[Hackbar is a tiny toolbar in Firefox with features to aid in application pen-testing. This can be used to perform our security tests quickly and effectively. 1. Manipulate integer values: Click on Load URL and then Split URL. Now select the Integer under interest and click on the INT +1 or INT -1 as required. [...]]]></description>
			<content:encoded><![CDATA[<p>Hackbar is a tiny toolbar in Firefox with features to aid in application pen-testing. This can be used to perform our security tests quickly and effectively.</p>
<p><img class="alignnone" title="Hackbar" src="http://img.a4apphack.com/hackbar-featured.jpg" alt="" width="349" height="199" /></p>
<p><span id="more-686"></span></p>
<h3>1. Manipulate integer values:</h3>
<p>Click on Load URL and then Split URL. Now select the Integer under interest and click on the INT +1 or INT -1 as required. This will automatically load the page with the new modified param value. This can help us while checking for &#8216;forceful browsing&#8217; or &#8216;revealing hidden pages&#8217; kind of tests.</p>
<div class="wp-caption alignnone" style="width: 610px"><a title="Change Integer Value" href="http://img.a4apphack.com/hackbar-changeintegervalue.jpg" rel="lightbox[686]"><img title="Change Integer Value" src="http://img.a4apphack.com/hackbar-changeintegervalue.jpg" alt="Change Integer Value" width="600" height="513" /></a><p class="wp-caption-text">Change Integer Value</p></div>
<h3>2. Calculate MD5 of selected string</h3>
<p>Some of the sites amateur developers might do poor encoding for the sensitive data which is communicated between server and the client. But with Hackbar the values can be easily decoded with a single click.</p>
<div class="wp-caption alignnone" style="width: 610px"><a title="Hash Selected Value" href="http://img.a4apphack.com/hackbar-hashselectedvalue.jpg" rel="lightbox[686]"><img class="" title="Hash Selected Value" src="http://img.a4apphack.com/hackbar-hashselectedvalue.jpg" alt="Hash Selected Value" width="600" height="513" /></a><p class="wp-caption-text">Hash Selected Value</p></div>
<h3>3. Calculate MySQL Char code of selected string.</h3>
<p>MySQL CHAR() button can help us in calculating the charcode of the selected string. This can help in injecting the char code value during some tests which usually are not stripped of while performing server side validation.</p>
<div class="wp-caption alignnone" style="width: 610px"><a title="Calculate Char Code" href="http://img.a4apphack.com/hackbar-calculatecharcode.jpg" rel="lightbox[686]"><img title="Calculate Char Code" src="http://img.a4apphack.com/hackbar-calculatecharcode.jpg" alt="Calculate Char Code" width="600" height="513" /></a><p class="wp-caption-text">Calculate Char Code</p></div>
<h2>Features</h2>
<ul>
<li>Increment/Decrement the numeric value of the params (e.g. change pageid to reveal hidden page, session ids etc)</li>
<li>Above operation on HEX values</li>
<li>SQL and XSS vectors string construction</li>
<li>Built-In string encryption options (MD5, SHA-1, SHA-256)</li>
<li>Encode and Decode URL (Base 64, URL Encoding)</li>
<li>Strings for performing BoF attacks.</li>
</ul>
<p><strong>Download Hackbar :</strong> <a href="https://addons.mozilla.org/en-US/firefox/addon/hackbar/"><img style="vertical-align: middle;" title="Hackbar Logo" src="http://img.a4apphack.com/hackbar-logo.png" alt="Hackbar Logo" /></a></p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=686&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/security/hackbar-audit-penetration-test-tool/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced (User agent is rejected)
Object Caching 1030/1060 objects using disk: basic

Served from: a4apphack.com @ 2012-05-22 10:49:25 -->
