<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Lifedork &#187; Firefox</title>
	<atom:link href="http://www.lifedork.net/tag/firefox/feed" rel="self" type="application/rss+xml" />
	<link>http://www.lifedork.net</link>
	<description>still GeeX? still SuX!</description>
	<lastBuildDate>Thu, 08 Jul 2010 16:15:55 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<image>
  <link>http://www.lifedork.net</link>
  <url>http://www.lifedork.com/favicon.ico</url>
  <title>Lifedork</title>
</image>
		<item>
		<title>Firefox 3.5 zero day exploit released</title>
		<link>http://www.lifedork.net/firefox-35-zero-day-exploit-released.html</link>
		<comments>http://www.lifedork.net/firefox-35-zero-day-exploit-released.html#comments</comments>
		<pubDate>Thu, 16 Jul 2009 09:31:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Browser]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[Mozilla Foundation]]></category>
		<category><![CDATA[Secunia]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Windows Vista]]></category>

		<guid isPermaLink="false">http://www.lifedork.net/?p=820</guid>
		<description><![CDATA[



Image via Wikipedia



Milw0rm is finally back with some new interesting informations and exploits , one of then is Firefox 3.5 Zero Day exploit! the exploit has been published on milw0rm yesterday. The firefox 3.5 zero day exploit itself simply demonstrates a security vulnerability that existed on firefox 3.5 by loading windows calculator. The most preventive [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:Mozilla_Foundation_logo.svg"><img title="Mozilla Foundation logo" src="http://upload.wikimedia.org/wikipedia/en/thumb/7/74/Mozilla_Foundation_logo.svg/300px-Mozilla_Foundation_logo.svg.png" alt="Mozilla Foundation logo" width="300" height="282" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:Mozilla_Foundation_logo.svg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>Milw0rm is finally back with some new interesting informations and exploits , one of then is <strong>Firefox 3.5 Zero Day exploit</strong>! the exploit has been published on milw0rm yesterday. The firefox 3.5 zero day exploit itself simply demonstrates a security vulnerability that existed on firefox 3.5 by loading windows calculator. The most preventive way to take is by disabling javascript on firefox 3.5 , otherwise your pcs might get infected!</p>
<p>Excerpt :</p>
<blockquote><p>The exploit portal Milw0rm has published an exploit for Firefox 3.5. The exploit demonstrates a security vulnerability by starting the Windows calculator. In testing by heise Security, the exploit crashed Firefox under Vista, but security service providers Secunia and VUPEN confirmed that attackers using prepared websites can infect PCs. The cause of the problem is a buffer overflow when processing specially prepared Font tags.</p>
<p>The Mozilla Foundation has been informed about the problem, but so far has not responded to queries by heise Security. An update does not currently exist. So far there are no reports of sites on the internet being first to use the hole for active infections and exploitation of Windows PCs. Since the published exploit uses PC heap spraying under JavaScript, disabling JavaScript should act as a stop gap. When the exploit was tested with Windows 7 RC1, after a short time, the browser displayed a dialogue offering to abort the script.</p></blockquote>
<p><strong>Download firefox 3.5 zero day Exploit : http://www.milw0rm.com/exploits/9137</strong></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles :</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://mashable.com/2009/07/15/security-vulnerability-firefox-3-5/"> Highly Critical Security Vulnerability Found in Firefox 3. </a> (mashable.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.macworld.com/article/141694/2009/07/firefox35_javascript.html?lsrc=rss_main"> Firefox 3.5 vulnerable to critical Javascript attack </a> (macworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.consumingexperience.com/2009/07/firefox-users-critical-security.html"> Firefox users: critical security vulnerability </a> (consumingexperience.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><span class="zem-script more-related pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.lifedork.net/firefox-35-zero-day-exploit-released.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox Keylogger Add on videos</title>
		<link>http://www.lifedork.net/firefox-keylogger-add-on-video.html</link>
		<comments>http://www.lifedork.net/firefox-keylogger-add-on-video.html#comments</comments>
		<pubDate>Sun, 12 Jul 2009 22:30:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Sectools]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[video|podcast]]></category>
		<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Clients]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Mozilla Firefox]]></category>
		<category><![CDATA[Web browser]]></category>
		<category><![CDATA[WWW]]></category>

		<guid isPermaLink="false">http://www.lifedork.net/?p=813</guid>
		<description><![CDATA[



Image via CrunchBase



Firefox is known as the most used web browser in the world. But only few people know how malicious code can be embedded in your Firefox without Antivirus or Firewall even notice it. In this case, You&#8217;re about to see how powerful Firefox keylogger addon is. Its ability to log the keystrokes whenever [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 240px;">
<dt class="wp-caption-dt"><a href="http://www.crunchbase.com/product/firefox"><img title="Image representing Firefox as depicted in Crun..." src="http://www.crunchbase.com/assets/images/resized/0001/3109/13109v1-max-450x450.png" alt="Image representing Firefox as depicted in Crun..." width="230" height="77" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://www.crunchbase.com">CrunchBase</a></dd>
</dl>
</div>
</div>
<p>Firefox is known as the most used web browser in the world. But only few people know how <strong>malicious code</strong> can be embedded in your Firefox without Antivirus or Firewall even notice it. In this case, You&#8217;re about to see how powerful <strong>Firefox keylogger addon</strong> is. Its ability to <strong>log the keystrokes</strong> whenever a victim type something within his browser is the main fun part of this firefox keylogger addon.</p>
<p>Here&#8217;s the short excerpt taken from the artile written by armando romeo :</p>
<blockquote><p>My small POC consists of a keylogger written in javascript and embedded into Firefox browser in form of extension. This code can be injected into any known/famous addon without even noticing it since it creates no warnings at Antiviruses (it&#8217;s just legal javascript) and no warning from Firewalls since the logs of the keystrokes are sent through Firefox on port 80 to a malicious server.<br />
Firewalls allow Firefox on port 80 if you want to browse the internet, so no way to understand what&#8217;s going on under the hood unless you track all the packets going out of your internet interface. The POC is an installable extension that once installed it doesn&#8217;t add anything to the Firefox appearance.</p></blockquote>
<p>Get it here : <strong>http://www.hackerscenter.com/public/Firefox_poc/poc_keylogger.zip</strong><br />
More information :<br />
<strong>http://blogs.hackerscenter.com/2008/04/firefox-addons-threat.html</strong></p>
<p>The addon which is used in the video might not related to the firefox keylogger addon created by armando , but it&#8217;s still nice to watch anyway. So here&#8217;s the firefox <strong>keylogger addon video</strong> :</p>
<p><object width="400" height="300" data="http://vimeo.com/moogaloop.swf?clip_id=5353818&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=&amp;fullscreen=1" type="application/x-shockwave-flash"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://vimeo.com/moogaloop.swf?clip_id=5353818&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=&amp;fullscreen=1" /></object></p>
<p><a href="http://vimeo.com/5353818">Firefox Keylogger</a> from <a href="http://vimeo.com/user571210">Jabra</a> on <a href="http://vimeo.com">Vimeo</a>.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles :</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.theregister.co.uk/2009/07/08/orange_and_ie6/"> Orange UK exiles Firefox from call centers </a> (theregister.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://tech.slashdot.org/story/09/06/09/0052232/Mozilla-To-Launch-Build-Your-Own-Browser?from=rss"> Mozilla To Launch &#8220;Build Your Own Browser&#8221; </a> (tech.slashdot.org)</li>
<li class="zemanta-article-ul-li"><a href="http://www.downloadsquad.com/2009/06/09/mozilla-to-let-enterprise-users-build-custom-firefox-based-brow/"> Mozilla to let enterprise users build custom Firefox-based browsers </a> (downloadsquad.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><span class="zem-script more-related pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.lifedork.net/firefox-keylogger-add-on-video.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>hack password facebook with javascript keylogger</title>
		<link>http://www.lifedork.net/hack-password-facebook-with-javascript-keylogger.html</link>
		<comments>http://www.lifedork.net/hack-password-facebook-with-javascript-keylogger.html#comments</comments>
		<pubDate>Tue, 27 Jan 2009 18:20:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Miscs]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[Keystroke logging]]></category>
		<category><![CDATA[Mozilla Firefox]]></category>
		<category><![CDATA[Netscape]]></category>
		<category><![CDATA[Password]]></category>

		<guid isPermaLink="false">http://www.lifedork.com/?p=644</guid>
		<description><![CDATA[



Image via CrunchBase



If you&#8217;ve read my previous post about hacking myspace account using keylogger on &#8216;myspace account hacking &#8211; does your wife cheat on you?&#8217; , the same thing can also be implemented in hacking into facebook account by using more advanced keylogging method like javascript keylogger. Hack Password Facebook with javascript keylogger can be [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; float: right; display: block;">
<div>
<dl class="wp-caption" style="width: 255px;">
<dt class="wp-caption-dt"><a href="http://www.crunchbase.com/company/facebook"><img title="Image representing Facebook as depicted in Cru..." src="http://www.crunchbase.com/assets/images/resized/0000/4561/4561v1-max-450x450.png" alt="Image representing Facebook as depicted in Cru..." width="245" height="100" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://www.crunchbase.com">CrunchBase</a></dd>
</dl>
</div>
</div>
<p>If you&#8217;ve read my previous post about <strong>hacking myspace account using keylogger</strong> on &#8216;<a href="http://www.lifedork.com/myspace-account-hacking-does-your-wife-cheat-on-you.html" target="_blank">myspace account hacking &#8211; does your wife cheat on you</a>?&#8217; , the same thing can also be implemented in <strong>hacking into facebook account</strong> by using more advanced keylogging method like <strong>javascript keylogger</strong>. <strong>Hack Password Facebook with javascript keylogger</strong> can be achieved by combining those both XSS vulnerabilities and Javascript Keylogger itself. Facebook was <a href="http://www.lifedork.com/more-facebook-xss-hacking-2009.html" target="_blank">vulnerable to some XSS</a> back then , this hole can be a good opportunity for intruders to infect a lot of facebook members with their web malware , including javascript keylogger ! And of course by keylogging , intruders can retrieve those <strong>facebook users &#8217;s password</strong> easily , and then extend their hack into <strong>hack facebook profiles</strong> , etc</p>
<p>A good implementation of javascript keylogger can be found on <a href="http://www.xssed.com/article/25/Paper_Smashing_the_Web_for_fun_&amp;_profit_using_XSS/" target="_blank">http://www.xssed.com/article/25/Paper_Smashing_the_Web_for_fun_&amp;_profit_using_XSS/</a>. Exceprts :</p>
<blockquote><p><strong>Introduction</strong></p>
<p>This article is dedicated to all this people that believe XSS is not a serious Web application vulnerability. Using XSS vulnerabilities someone can actually make lots of money. I don’t have any responsibility how this knowledge is going to be used, this article was created at of love of hacking and not to hack other people sites. Recently I became very interested to XSS and decided to write an article that fully explains how to inject a JavaScript key logger, and by saying fully explain I mean describe in full detail how can someone perform XSS filter invasion and run my JavaScript key logger in order to steal user names, passwords and user credentials. The scary part is that you don’t have to be a JavaScript expert to write effective JavaScript malicious code, you just have to have a good understanding of the Web. In the following article I provide the reader with two flavors of practically the same JavaScript key logger.</p>
<p>In order to understand this article you have to know:</p>
<p>1. How to write Html web forms (look at [4]).<br />
2. How to write Javascript DOM objects (look at [3]).<br />
3. Basic functionality of Http protocol (look at [1]).<br />
4. Understand JavaScript what obfuscation is (have a look at [5]).<br />
5. Understand how to use Burp Suite1.1 (look at [6]).</p>
<p><strong>The functionality of your XSS</strong></p>
<p>Before you exploit an XSS someone has to understand what is the functionality a XSS exploit should have. By saying functionality I mean what is the reason of your XSS, e.g. to deface a website, to cause a redirect or to steal user credentials (something that is the most interesting!!). In our situation we have to think about writing a key logger XSS. So that is why we have to make some thoughts about what is a log-in page form, from the user perspective, for example what is the average user name and password length? And how fast the an average user is typing? We are going to use this information to build up two flavors of JavaScript key loggers that run in IE, Firefox, Opera and Netscape. So our program is going to steal the user credential based only on time (e.g. auto execute after certain amount of time) or based only on password length (e.g. auto execute after the user types 5 characters) or based on both time and password length (e.g. maybe perform some character mapping, like check if Enter or Tab buttons have been pressed).</p></blockquote>
<p>You can also read insanesecurity&#8217;s article to extend your understanding of <a href="http://insanesecurity.info/2009/01/javascript-userscript-keylogger/" target="_blank">userscript keylogger</a>.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Random articles :</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.downloadsquad.com/2009/01/21/thwart-password-hungry-keyloggers-with-a-greasemonkey-script/">Thwart password-hungry keyloggers with a Greasemonkey script</a></li>
<li class="zemanta-article-ul-li"><a href="http://blog.deurainfosec.com/harmful-spyware-and-their-stealthier-means">Harmful Spyware and their stealthier means</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.engadget.com/2008/10/20/keyboard-eavesdropping-just-got-way-easier-thanks-to-electrom/">Keyboard &#8220;eavesdropping&#8221; just got way easier, thanks to electromagnetic emanations</a></li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/9e7b32a9-7976-48c3-a112-13487fdc4137/"><br />
</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.lifedork.net/hack-password-facebook-with-javascript-keylogger.html/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Firefox security addons you must have</title>
		<link>http://www.lifedork.net/firefox-security-addons-you-must-have.html</link>
		<comments>http://www.lifedork.net/firefox-security-addons-you-must-have.html#comments</comments>
		<pubDate>Wed, 26 Nov 2008 10:13:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Misc2]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Mozilla Firefox]]></category>

		<guid isPermaLink="false">http://www.lifedork.com/firefox-security-addons-you-must-have.html</guid>
		<description><![CDATA[

Fifrefox Security Addons are some firefox addons which have some special purpose like web application pentesting , web browser security enhancement and so on. I&#8217;m going to give you a list of Firefox security addons that you must have on your firefox browser  
So here they are :
1. Firebug
This addon can be useful  to [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img zemanta-action-click">
<div class="wp-caption alignright" style="width: 212px"><a href="http://en.wikipedia.org/wiki/Image:Firefox-logo.svg"><img title="Mozilla Firefox" src="http://upload.wikimedia.org/wikipedia/en/thumb/e/e3/Firefox-logo.svg/202px-Firefox-logo.svg.png" alt="Mozilla Firefox" width="202" height="193" /></a><p class="wp-caption-text">Image via Wikipedia</p></div>
</div>
<p><strong>Fifrefox Security Addons</strong> are some firefox addons which have some special purpose like web application pentesting , web browser security enhancement and so on. I&#8217;m going to give you a list of <strong>Firefox security addons</strong> that you must have on your firefox browser <img src='http://www.lifedork.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>So here they are :</p>
<p>1. Firebug</p>
<p>This addon can be useful  to debug your javascript,css,html from your firefox browser. Download Firebug : <strong>https://addons.mozilla.org/en-US/firefox/addon/1843</strong></p>
<p>2. Hackbar</p>
<p>A very useful firefox security addon to effectively launch some <a class="zem_slink" title="Penetration test" rel="wikipedia" href="http://en.wikipedia.org/wiki/Penetration_test">penetration testing</a> to web application (sql injection,xss and more) it supports md5 , base64 . mssql char and so on . Download Hackbar : <strong>https://addons.mozilla.org/en-US/firefox/addon/3899</strong></p>
<p>3. Anonymouser</p>
<p>This firefox addon will be useful to anonymously open a link (by using anonymouse.org proxy). Download Anonymouser : <strong>https://addons.mozilla.org/en-US/firefox/addon/1415</strong></p>
<p>4. <a class="zem_slink" title="User agent" rel="wikipedia" href="http://en.wikipedia.org/wiki/User_agent">User Agent</a> Switcher</p>
<p>This will be useful to hide your User Agent <img src='http://www.lifedork.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  . Download User Agent Switcher : <strong>https://addons.mozilla.org/en-US/firefox/addon/59</strong></p>
<p>5. Modify Headers</p>
<p>Easily modify your http header <img src='http://www.lifedork.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Download Modify headers addon : <strong>https://addons.mozilla.org/en-US/firefox/addon/967</strong></p>
<p>6. XSS-me</p>
<p>By using XSS-me , you will be able to do a xss pentest easily. Download XSS-me : <strong>http://www.securitycompass.com/exploit_me/xssme/xssme-0.2.1.xpi</strong></p>
<p>7. Sql-inject-me</p>
<p>Same as the addon aboce , but it&#8217;s specialized in sql injection attack. Download sql-inject-me : <strong>http://www.securitycompass.com/exploit_me/sqlime/sqlime-0.2.xpi</strong></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles :</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://dobrzanski.net/2008/08/02/firefox-download-day/">Firefox Download Day</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.robinmalau.com/i-stop-using-firefox-3/">I Stop Using Firefox 3</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.articlesbase.com/article.php?aid=657217&amp;pid=6775764102">Search Engine Optimization Services &#8211; Then and Now</a></li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/50a81244-eb8b-4918-b114-7071d3c77117/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=50a81244-eb8b-4918-b114-7071d3c77117" alt="Reblog this post [with Zemanta]" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.lifedork.net/firefox-security-addons-you-must-have.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
