Jump to content
Nytro

Configuring Firefox For Web App Pen Testing

Recommended Posts

Posted

[h=3]Configuring Firefox For Web App Pen Testing[/h][h=2]15 March 2012[/h]

You know the routine: you get a gig doing a web app pen test. You break out Burp (or whatever lesser proxy you prefer), and get ready to ruin some developer's day. And then, just as you get ready to load the target URL and start, this happens:

stupid_firefox.png

It's annoying. Your logs are polluted, and if you have to turn them over to the client, the extra noise strips some of the professionalism from your image (as a sidenote: Burp's "only save in-scope items" feature helps quite a lot with this).

Here then, is a quick guide on how to tweak Firefox so that it doesn't spew stupid crap in your web app pen test log files. I may come back and explain the "why" behind some of these later, but for now, just the "how" will have to do. (Note: some of these settings reduce the security of the browser. My presumption here is that Firefox will only be used for testing, not for general purpose browsing. The settings below reflect that.)

1) Open about:config

01.png

2) Disable Safe Browsing

02.png

3) Disable Pipelining

03.png

4) Disable Pre-fetching

04.png

5) Remove all bookmarks

06.png

6) Set homepage to about:blank for startup

07.png

7) Make sure history is enabled, but disable search suggestions

08.png

8) Disable checking for updates

10.png

9) Just say no to helping developers

11.png

10) Disable updates for sync

13.png

That's it. Now you can go forth, and break all the things, knowing that your log files will be nice and tidy afterwards.

Posted by Jason Ross at 14:04

Sursa: cruft: Configuring Firefox For Web App Pen Testing

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...