Brute force attack in Firefox




Fireforce is a Firefox extension under GPL license that allows to perform brute-force or dictionary attacks on forms sent by GET or POST.

Fireforce is for administrators of the sites, it can be used to test the reliability of his login / password, or test the security of its website.

You can download Firefoce this link. The extension is compatible with all versions of the Firefox browser between 1.5 and 3.5.x.

Slide to install the downloaded "fireforce.xpi" in your browser and click on install.
During use, the extension block your Firefox profile. It is therefore advisable to run it from a different profile and launch 2 profiles simultaneously. To do this:

Run this command in Windwos Start> Run.
firefox.exe -profilemanager
Then click on "Create Profile ...

With linux type this command in a console: firefox -profilemanager

To prevent these types of attacks, it is better to have an anti-brute-force system (blocking the ip after n false passwords, captcha) in the adminitration page. For more information, a guide is available on the official website of the creators of the tool.




Previous
Next Post »