<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title> &#187; Firefox</title>
	<atom:link href="http://www.megapanzer.com/tag/firefox/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.megapanzer.com</link>
	<description></description>
	<lastBuildDate>Fri, 23 Dec 2011 13:02:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Trojan forces Firefox to secretly store passwords</title>
		<link>http://www.megapanzer.com/2010/10/14/trojan-forces-firefox-to-secretly-store-passwords/</link>
		<comments>http://www.megapanzer.com/2010/10/14/trojan-forces-firefox-to-secretly-store-passwords/#comments</comments>
		<pubDate>Thu, 14 Oct 2010 07:06:00 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Passwords]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=4212</guid>
		<description><![CDATA[A trojan recently analysed by Webroot is said to rely on retrieving web page passwords from a browser&#8217;s password storage, rather than logging a user&#8217;s keyboard inputs. To make sure it will find all the interesting passwords in Firefox, the malware, called PWS-Nslog, makes some changes to jog the browser&#8217;s memory. A few manipulations in [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><glossarycode><p><img class="alignright size-thumbnail wp-image-2595" title="newspaper" src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="" width="75" height="75" />A trojan recently analysed by Webroot is said to rely on retrieving web page passwords from a browser&#8217;s password storage, rather than logging a user&#8217;s keyboard inputs. To make sure it will find all the interesting passwords in Firefox, the <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1210" title="Glossary: Malware" target="_blank">malware</a>, called PWS-Nslog, makes some changes to jog the browser&#8217;s memory. A few manipulations in a JavaScript file prompt Firefox to store log-in information automatically and without requesting the user&#8217;s consent.<br />
The <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1210" title="Glossary: Malware" target="_blank">malware</a> will, for instance, simply comment out Firefox&#8217;s confirmation request in the nsLoginManagerPrompter.js file and add a line with automatic storage instructions. The H&#8217;s associates at heise Security were able to reproduce the effect of the manipulations – manipulations which the <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1210" title="Glossary: Malware" target="_blank">malware</a> author probably borrowed from a work around that has been in circulation <a class="glossaryLink" href="http://www.megapanzer.com/" title="Glossary: SIN" target="_blank">since</a> 2009.</p>
<p>Read more <a href="http://www.h-online.com/security/news/item/Trojan-forces-Firefox-to-secretly-store-passwords-1106100.html" target="_blank">here</a>.</p></glossarycode></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/10/14/trojan-forces-firefox-to-secretly-store-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Extracting Firefox logfile entries with FFLogDump</title>
		<link>http://www.megapanzer.com/2010/03/16/extracting-firefox-logfile-entries-with-fflogdump/</link>
		<comments>http://www.megapanzer.com/2010/03/16/extracting-firefox-logfile-entries-with-fflogdump/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 06:40:51 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Tools & sources]]></category>
		<category><![CDATA[extract]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Logfile]]></category>
		<category><![CDATA[source]]></category>
		<category><![CDATA[Tool]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=2395</guid>
		<description><![CDATA[Tool name : FFLogDump 0.1 &#160; Description : FFLogDump is a tool to access the Firefox 3.* main logfile and extract details about sites the user visited. In this version cookie information, favorites/bookmarks and the browsing history are extracted. &#160; Tested on : Windows XP, Firefox 3.5.1 &#160; Feedback : In case you encounter any [...]]]></description>
			<content:encoded><![CDATA[<table border="0" width="100%">
<tbody>
<tr valign="top">
<td width="30%"></td>
<td width="70%"></td>
</tr>
<tr valign="top">
<td><strong>Tool name</strong> :</td>
<td>FFLogDump 0.1</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Description</strong> :</td>
<td>FFLogDump is a tool  to access the Firefox 3.* main logfile and extract details about sites the user visited. In this version cookie information, favorites/bookmarks and the browsing history are extracted.</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Tested on</strong> :</td>
<td>Windows XP, Firefox 3.5.1</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr  valign="top">
<td><strong>Feedback</strong> :</td>
<td>In case you encounter any problems with the tool, you have suggestions to improve it, or you tested it with a Windows version i&#8217;ve not yet tested please drop me an <a href="http://www.megapanzer.com/contact/">email</a>.</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Downloads</strong> :</td>
<td><a href="http://www.megapanzer.com/wp-content/uploads/FFLog_binary_20100316.zip">Binary</a> | <a href="http://www.megapanzer.com/wp-content/uploads/FFLog_source_20100316.zip" target="_blank">Source</a></td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Screen shots</strong> :</td>
<td>-</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/03/16/extracting-firefox-logfile-entries-with-fflogdump/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>Zero day exploit for Firefox 3.6</title>
		<link>http://www.megapanzer.com/2010/02/20/zero-day-exploit-for-firefox-3-6/</link>
		<comments>http://www.megapanzer.com/2010/02/20/zero-day-exploit-for-firefox-3-6/#comments</comments>
		<pubDate>Sat, 20 Feb 2010 18:43:06 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[zero-day]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3481</guid>
		<description><![CDATA[Russian security firm Intevydis has made a Windows exploit for a previously unknown security hole in Firefox 3.6 available to its customers. The exploit allows attackers to remotely gain control of a PC. Intevydis develops the commercial VulnDisco add-on for the also commercial Canvas exploit toolkit by vendor Immunity. On the Immunity forum, developer Evgeny [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><p><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" />Russian security firm Intevydis has made a Windows exploit for a previously unknown security hole in Firefox 3.6 available to its customers. The exploit allows attackers to remotely gain control of a PC. Intevydis develops the commercial VulnDisco add-on for the also commercial Canvas exploit toolkit by vendor Immunity. On the Immunity forum, developer Evgeny Legerov praises his exploit for Windows XP (SP3) and Vista as being quite reliable. The developer says It was an interesting challenge to find the flaw – a <a class="glossaryLink" href="http://www.megapanzer.com/" title="Glossary: Buffer overflow" target="_blank">buffer overflow</a> – and to exploit it.</p>
<p>Read more <a href="http://www.h-online.com/security/news/item/Zero-day-exploit-for-Firefox-3-6-936124.html" target="_blank">here</a>.</p></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/02/20/zero-day-exploit-for-firefox-3-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox-based attack wreaks havoc on IRC users</title>
		<link>http://www.megapanzer.com/2010/02/01/firefox-based-attack-wreaks-havoc-on-irc-users/</link>
		<comments>http://www.megapanzer.com/2010/02/01/firefox-based-attack-wreaks-havoc-on-irc-users/#comments</comments>
		<pubDate>Mon, 01 Feb 2010 08:17:24 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[irc]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3444</guid>
		<description><![CDATA[Underscoring a little-known web vulnerability, hackers are exploiting a weakness in the Mozilla Firefox browser to wreak havoc on Freenode and other networks that cater to users of internet relay chat. Using a piece of javascript embedded into a web link, the hackers force users of the open-source browser to join IRC networks and flood [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><glossarycode><p><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" />Underscoring a little-known web vulnerability, <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1220" title="Glossary: Hacker" target="_blank">hackers</a> are <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=2563" title="Glossary: Exploit" target="_blank">exploiting</a> a weakness in the Mozilla Firefox browser to wreak havoc on Freenode and other networks that cater to users of internet relay chat.</p>
<p>Using a piece of javascript embedded into a web link, the <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1220" title="Glossary: Hacker" target="_blank">hackers</a> force users of the open-source browser to join IRC networks and flood channels with diatribes that include the same internet address. As IRC users with Firefox follow the link, their browsers are also forced to spam the channels, giving the attack a viral quality that has has caused major disruptions for almost a month.</p>
<p>&#8220;Huge numbers of users of the Freenode network ended up getting banned themselves because they would click the link and then they would join the network and flood the network,&#8221; one of the <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1220" title="Glossary: Hacker" target="_blank">hackers</a>, who goes by the moniker Weev, told The Register. &#8220;We get this huge rollover effect.&#8221;</p>
<p>He added: &#8220;We got the the people who run Freenode to actually k-line each other,&#8221; a reference to the process of banning a user from an IRC server for spamming or other inappropriate actions.</p>
<p>Read more <a href="http://www.theregister.co.uk/2010/01/30/firefox_interprotocol_attack/" target="_blank">here</a>.</p></glossarycode></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/02/01/firefox-based-attack-wreaks-havoc-on-irc-users/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New version of the Firefox account data extractor available for download</title>
		<link>http://www.megapanzer.com/2010/01/29/new-version-of-the-firefox-account-data-extractor-available-for-download/</link>
		<comments>http://www.megapanzer.com/2010/01/29/new-version-of-the-firefox-account-data-extractor-available-for-download/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 00:01:34 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Tools & sources]]></category>
		<category><![CDATA[Account]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Recovery]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3440</guid>
		<description><![CDATA[As I already announced in the morning an updated version of the FFPasswordRecovery tool is available tonight. So here it is. I reorganised the code a little and added the SQLite support that was integrated into FireFox lately. You can download both the binary version if you don&#8217;t want to compile it yourself or the [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.megapanzer.com/wp-content/uploads/code-150x150.jpg" alt="" title="code" width="75" height="75" class="alignright size-thumbnail wp-image-3203" />As I already announced in the morning an updated version of the <a href="http://www.megapanzer.com/2009/07/28/ffpasswordrecovery/"><strong>FFPasswordRecovery </strong></a>tool is available tonight. So here it is.<br />
I reorganised the code a little and added the <strong>SQLite support</strong> that was integrated into FireFox lately. You can download both the binary version if you don&#8217;t want to compile it yourself or the sourcecode (SQLite lib and headers included).</p>
<p>You find the files <a href="http://www.megapanzer.com/2009/07/28/ffpasswordrecovery/">here</a>.<br />
<br/></p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/01/29/new-version-of-the-firefox-account-data-extractor-available-for-download/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox account data extractor and SkypeTap</title>
		<link>http://www.megapanzer.com/2010/01/28/firefox-account-data-extractor-and-skypetap/</link>
		<comments>http://www.megapanzer.com/2010/01/28/firefox-account-data-extractor-and-skypetap/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 08:00:32 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Info]]></category>
		<category><![CDATA[Stuff]]></category>
		<category><![CDATA[Tools & sources]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[skypetap]]></category>
		<category><![CDATA[sourcecode]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3429</guid>
		<description><![CDATA[The new code that extracts the Firefox account data out of the SQLite database is more or less done. If everything goes well I&#8217;ll upload the new sourcecode tonight (Swiss time) in a new version of the FFPasswordRecovery tool. During spring I plan to conduct some tests with the SkypeTap plugin and other instant messengers. [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.megapanzer.com/wp-content/uploads/information-150x150.jpg" alt="" title="information" width="75" height="75" class="alignright size-thumbnail wp-image-2871" />The new <strong>code that extracts the Firefox account data</strong> out of the SQLite database is more or less done. If everything goes well I&#8217;ll upload the new sourcecode tonight (Swiss time) in a new version of the <a href="http://www.megapanzer.com/2009/07/28/ffpasswordrecovery/">FFPasswordRecovery </a>tool.</p>
<p>During spring I plan to conduct some tests with the <a href="http://www.megapanzer.com/wp-content/uploads/SkypeTap_20091226.zip">SkypeTap </a>plugin and other instant messengers. If you have some minutes spare and want to see how these apps and the plugin work together don&#8217;t hesitate to conduct these tests yourself and inform me afterwards and tell me what happened. Unfortunately my time is rather limited at the moment and school keeps me busy. Therefore hings are moving more slowly than usual.<br />
<br/></p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/01/28/firefox-account-data-extractor-and-skypetap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox password recovery with FFPasswordRecovery</title>
		<link>http://www.megapanzer.com/2009/07/28/ffpasswordrecovery/</link>
		<comments>http://www.megapanzer.com/2009/07/28/ffpasswordrecovery/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 16:02:44 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Tools & sources]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Password]]></category>
		<category><![CDATA[Recovery]]></category>
		<category><![CDATA[Sources]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=2094</guid>
		<description><![CDATA[Tool name : FFPasswordRecovery 0.2 &#160; Description : FFPasswordRecovery is a tool to extract and decrypt the Firefox authentication and auto complete information. &#160; Tested on : Windows XP, Firefox 3.5.7 &#160; Feedback : In case you encounter any problems with the tool, you have suggestions to improve it, or you tested it with a [...]]]></description>
			<content:encoded><![CDATA[<table border="0" width="100%">
<tbody>
<tr valign="top">
<td width="30%"></td>
<td width="70%"></td>
</tr>
<tr valign="top">
<td><strong>Tool name</strong> :</td>
<td>FFPasswordRecovery 0.2</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Description</strong> :</td>
<td>
FFPasswordRecovery is a tool to extract and decrypt the Firefox authentication and auto complete information.
</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Tested on</strong> :</td>
<td>Windows XP, Firefox 3.5.7</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr>
<td><strong>Feedback</strong> :</td>
<td>In case you encounter any problems with the tool, you have suggestions to improve it, or you tested it with a Windows version i&#8217;ve not yet tested please drop me an <a href="http://www.megapanzer.com/contact/">email</a>.</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Downloads</strong> :</td>
<td>Version 0.1 &#8211; <a href="http://www.megapanzer.com/wp-content/uploads/ffpasswordrecovery_binary.zip">Binary</a> | <a href="http://www.megapanzer.com/wp-content/uploads/ffpasswordrecovery_source.zip">Source</a></td>
</tr>
<tr valign="top">
<td>&nbsp;</td>
<td>Version 0.2 &#8211; <a href="http://www.megapanzer.com/wp-content/uploads/FFPasswordRecovery_0_2_binary.zip">Binary</a> | <a href="http://www.megapanzer.com/wp-content/uploads/FFPasswordRecovery_0_2_source.zip">Source</a></td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Screen shots</strong> :</td>
<td><a href="http://www.megapanzer.com/wp-content/uploads/ffpasswordrecovery.jpg" target="_blank"><img class="size-thumbnail wp-image-1496" title="FFPasswordRecovery" src="http://www.megapanzer.com/wp-content/uploads/ffpasswordrecovery-150x150.jpg" alt="HandleServices" width="150" height="150" /></a></td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/07/28/ffpasswordrecovery/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

