shadow is a new, extended (and renamed version) of a Firefox heap exploitation tool, which is quite a swiss army knife for Firefox/jemalloc heap exploitation. If you want to dive in really deep to this tool, and the technicalities behind it check this out – OR’LYEH? The Shadow over Firefox [PDF] Support shadow has been […]
firefox-security
At Last – Adobe Launches Sandboxed Flash Player For Firefox
Finally a proactive measure from Adobe to try and remedy the horrible security flaws they have introduced to Firefox with their Flash Player. There have been some massive hacks recently due to Flash – – Hackers Exploiting Latest Adobe Flash Bug On Large Scale – Adobe Patches Latest Flash Zero Day Vulnerability – Adobe Promises […]
Hackers Exploit Unpatched Firefox 0day Using Nobel Peace Prize Website
It’s been a while since Firefox has been in the news, but this is a fairly high profile case involving the Nobel Peace Prize website. It seems there is a race condition vulnerability in the latest versions of Firefox (including 3.6.11) that allows remote exploitation. In this case it was used via an iFrame on […]
Firefox Blocks Microsoft .NET Framework Assistant Add-on
[ad] This is an interesting development, I noticed the pop-up on my Firefox yesterday. The reason however wasn’t security it was ‘instability’. It’s a fair move by Mozilla though as the add-on can cause security vulnerabilities in Firefox outside of their control. They can’t fix the software, so the best thing they can do to […]
Mozilla Denies Firefox 3.5 Bug Is Exploitable
[ad] Ah a bug in our beloved Firefox, after the latest 3.5 update (which sees some definite improvements). The last one I recall was the Clickjacking Vulnerability, which also effected Chrome. It seems like it’s not too serious of an issue and will only cause crashing, there’s no room for remote exploitation or code execution. […]
Password Hasher Firefox Extension
Well seen as though we were talking about breaking passwords, here’s a tool for Firefox to help you manage your more secure passwords. Better security without bursting your brain Password Hasher is a Firefox security extension for generating site-specific strong passwords from one (or a few) master key(s). What good security practice demands: Strong passwords […]
FireCAT 1.3 Released – Firefox Catalog of Auditing Extensions
[ad] FireCAT is a Firefox Framework Map collection of the most useful security oriented extensions. Version 1.3 was pending the ExploitMe tools availability to the public. Changes for version 1.3 Category Information Gathering (Googling and Spidering) GSI Google Site indexer (GSI Creates Site Maps based on Google queries. Useful for both Penetration Testing and Search […]
FireCAT 1.2 Released – Firefox Catalog of Auditing Extensions
[ad] As mentioned in the previous FireCAT 1.1 post, FireCAT 1.2 was released last month. If you aren’t aware, FireCAT is a Firefox Framework Map collection of the most useful security oriented extensions. Changes for FireCAT 1.2 Renamed subcategory “Social Engineering” to “Data mining” Bibirmer updated location (thanks to Zagrodzki Krzysztof from Telekomunikacja Polska) Enhanced […]
FireCAT 1.1 Released – Turn Firefox into a Security Platform
[ad] FireCAT is a Firefox Framework Map collection of the most useful security oriented extensions. It can be used to turn your favorite browser (Firefox) into a powerful security framework. FireCAT comes from “Firefox Catalog of Auditing Toolbox” Changes for FireCAT 1.1 + Category Network Utililies – Added ffsniff to subcat “Sniffers” – Added CrossFTP […]
XSS Warning – A Security Extension/Add-on for Firefox
[ad] XSS Warning is a extension/add-on for Firefox that filters malicious values to prevent Cross Site Scripting (XSS) attacks by malicious URLs (assuming you have Javascript enabled). XSS Warning 0.1.8 beta protect from: URL attack Redirect attack Link code injection Compatible with Firefox: 1.5 – 2.0.0 You can install and read more about XSS Warning […]

