Firefox till version 3.5 stores the sign-on secrets in signons.txt
file located in the Firefox profile directory. With version 3.5 onwards
Firefox started storing the sign-on secrets in Sqlite database
file named 'signons.sqlite'. The structure of sign-on information
stored in the signons.txt file (signons2.txt for version 2
and signons3.txt for version 3) and signons.sqlite for version
3.5 onwards is described below...
|
|||||||||||
|
|||||||||||
Here each Host entry can have multiple
username/password pairs. Starting from Firefox version 2.0, sub domain
URL is also included along with username/password entry. If it is the password
field then it begins with '*'. This is the key in distinguishing
between username and password entry.
Now once the username and password values are extracted, next task is to decrypt them. Information required to decrypt these values is stored in key3.db file. If the master password is set, then you must provide the master password to proceed with decryption. If you have forgotten the master password, then you can use Firemaster tool to recover the master password. If the master password is set and if you have not provided it, then FirePasswordViewer will prompt you to enter the master password. |
Penetration Test, Malware Analysis, Mobile Security, Reverse Engineering, Fuzzing, Web Application Security, Windows Internals, Cracking, Hacking
11 Nisan 2012 Çarşamba
Firefox Password Internals
Kaydol:
Kayıt Yorumları (Atom)
Hiç yorum yok:
Yorum Gönder