Usefull Google Chrome Extensions For Penetration Testers & Security Researcher 2022
1. Web Developer is a Google Chrome extension that adds a tool bar with various web development tools in Chrome. With these tools, users can perform various web development tasks. This extension helps analyzing web application elements like HTML and JS.. Add Web Developer Extension in Chrome here
2. Firebug Lite for Google Chrome provides a rich
visual environment to analyze HTML elements, DOM elements and other Box
Model Shading. It also provides live CSS editing. It helps in analyzing
how an application is working on the client’s side.Add Firebug Lite to Google Chrome:
3. d3coder, is another nice Google Chrome extension
that helps penetration testers. It enables us to encode and decode
selected text via context menu. Thus it reduces the time to encode and
decode strings by using separate tools. This extension can perform a
wide range of functions. See the list below:
- Timestamp decoding
- rot13 en-/decoding
- base64 encoding
- base64 decoding
- CRC32 hashing
- MD5 hashing
- SHA1 hashing
- bin2hex
- bin2txt
- HTML entity encoding
- HTML entity decoding
- HTML special chars encoding
- HTML special chars decoding
- URI encoding
- URI decoding
- Quoted printable decoding
- Quoted printable encoding
- Escapeshellarg
- Base64 decode
- Base64 encode
- Unserialize
- L33T-en/decode
- Reverse
Add d3coder extension to Google Chrome.
4. Proxy SwitchySharp, is a proxy extension that helps
in managing and switching between multiple proxies quickly. It also has
an option to set auto proxy switching based on URL. You can also import
or export data easily. With proxy switcher, we can hide IP addresses
and perform penetration testing tasks to check how a person can attack
with proxy servers.
5. Site Spider, is an extension that adds a crawler in Chrome. It crawls all pages and reports all broken links. One can also restrict the spider by adding restrictions and regular expressions, it works at the client’s side. It can also use your authentication to access all pages. This extension is opensource. So, you can easily modify it according to your needs.
6. Form fuzzer, is used to populate predefined
characters into different form fields. It can also select checkboxes,
radio buttons and select items in forms. It has a configuration menu
where you can manage all settings of the extension. It is really helpful
in testing forms. You can set payloads for forms and then populate
payloads quickly with this nice tool. Really helpful in performing XSS
and SQL injection attacks.Add Form Fuzzer to Google Chrome
7. Session manager, is a powerful Chrome extension
that lets users save, update, restore, and remove sets of tabs. You can
create a group of tabs of the same interest and then restore those pages
in one click. If you open few specific pages daily, and create groups
of those pages and then open with a single click.Add Session Manager to Google Chrome
8. Request maker, is a core penetration testing tool. It’s used in creating and capturing requests, tampering the URL, and making new headers with post data. It can capture requests made via forms or XMLHttpRequests. You can see the function of this tool is similar to Burp. It’s also helpful in performing various kind of attacks in a web applications by modifying http requests. Add Request Maker to Google Chrome
9. Proxy Switchy Sharp. Add Proxy SwitchySharp to Google Chrome
10. Cookie editor is a nice Chrome extension that lets
users edit cookies. This tool is really helpful while hijacking
vulnerable test sessions. It lets users delete, edit, add/or search
cookies. It also lets users protect, block or export cookies in json.
You can play with cookies as you want. This extension is ad-supported
and all revenue goes to Unicef to help children worldwide. But Ads are
not necessary and you can disable anytime from the extension settings
page.Add Edit This Cookie to Google Chrome
11.Cache Killer, is another nice extension that
automatically cleans the browser cache before loading pages. It can be
easily enabled or disabled with a single mouse click. It’s useful to
bypass the browser cache and see the exact website in case it’s
changing. This is much useful for web developers.
Add Cache Killer Extension to Google Chrome:
12. XSS Rays, is a nice extension that helps in finding
XSS vulnerability in a website. It finds how a website is filtering the
code. It also checks for injections and inspects objects. You can also
easily extract, view and edit forms non-destructively even if forms
cannot be edited. So many penetration testers use this extension as a
dedicated XSS testing tool. It’s pure JavaScript XSS scanner. You can read more about XSS Rays here.Add XSS rays to Google Chrome:
13.WebSecurify is a powerful cross platform web
security testing tool. It’s available for various desktop, mobile
platforms and browsers. This is the first web security tool that runs
directly from the browser. It’s capable of finding XSS, XSRF, CSRF, SQL
Injection, File upload, URL redirection and various other security
vulnerabilities. It has a built in crawler that scans and crawls pages.
Then it will try to find vulnerability on pages. It’s not a fully
automatic tool. It lists possible vulnerability on the URL. You will
need to confirm the vulnerability manually. We have already covered the
websecurify tool in detail. You can check older posts to read more on
how this tool works and how to master websecurify for penetration
testing. While scanning, it pulls all features from the WebSecurify
server, so you do not need to worry about database updates. The
vulnerability engine will be updated at all times. Penetration testing
tools are just a click away. Use this either as a browser tool or
desktop tool.
Add Websecurify to Google Chrome:
14. Port Scanner, Google Chrome extension adds port
scanning capabilities to the browser. With this extension, you will be
able to scan which TCP ports are listening. Port Scanner analyzes any
given IP or URL addresses, and then will scan for open ports to help you
to secure them. It is also available for Opera and Mozilla Firefox.Add Port Scanner to Google Chrome:
15. XSS chef, is the popular Chrome extension that works directly in the browser. It helps us in identifying XSS vulnerability in a web application. It’s similar to BeEF but for browsers. It performs following tasks:
- Monitor open tabs of victims
- Execute JS on every tab (global XSS)
- Extract HTML, read/write cookies (also httpOnly), local Storage
- Get and manipulate browser history
- Stay persistent until whole browser is closed (or even further if you can persist in extensions’ local Storage)
- Make screenshot of victims window
- Further exploit e.g. via attaching BeEF hooks, keyloggers etc.
- Explore filesystem through file:// protocol
- Bypass Chrome extensions content script sandbox to interact directly with page JS
This is not an extension but a framework. So, installation is not same as any other extension. Read the official link of XSS Chef given below and learn how to install it in Chrome.
Add XSS chef to Google Chrome
Add GHDB in Google Chrome
Comments
Post a Comment