Connect With Me In Facebook

Welcome to DefendHackers, If u want to Apply for a Blogroll as a Author , With h4ckfreak Mail me @ suren.click@gmail.com

Mark Zuckerberg tells 8th graders “there’s no shortcuts” and to make friends

By h4ckfreak

Metasploit Quick Start Referennce Guide

Metasploit Quick Start Referennce Guide , By h4ckfreak

IP Security

IP Security By H4ckfreak.

15 Network Admin Apps for Android

15 Network Admin Apps for Android , By h4ckfreak

Break All OS Passwords Using KON

Break All OS Passwords Using KON , By h4ckfreak

Recover Or Reset Ur Windows Pwd Using Ubuntu

Recover Or Reset Ur Windows Pwd Using Ubuntu , By h4ckfreak

Security Blueprint For Ethical Hackers..

By h4ckfreak

Blocking IP Using IPSec

By h4ckfreak

Preventing DDos Attacks, Combat Steps abd Tools...

By h4ckfreak

Sunday, January 16, 2011

DNS and DNS cache (DNS Flush Error).

YES..!!!!!!!!!This will help you guys for better understanding of “DNS CACHE” When you use the Internet, you log to a site by its URL name (like www.BUY.com).
The naming scheme was done to make it easier for people to identify and remember the Sites. In reality, each Site name has an IP address (Internet Protocol address), which is a number on a database that is maintained by the Internet supervisors, and the actual surfing it done by the number. As an Example www.BUY.com actually goes around as 209.67.181.11
DNS (Domain Name service), is the data base that translates the name BUY.com to the IP number 209.67.181.11
Your Internet Service Provider (ISP) is usually providing an automatic access to their DNS data base while your are surfing.
Windows can keep the IP address of the sites that you Snoopin evry time, so wen u visit them the 2nd time the number is readily available.
It is done through a running service called DNS Client.
At times, this cache of numbers might end up with incorrect numbers or other mistakes, and can cause surfing troubles.
In case of trouble, the DNS cache can be cleaned by doing the following.
________________________________________
Click Start and Run, in the Run Box type cmd and click OK.
At the prompt of the open Command Box type, ipconfig/flushdns



________________________________________
If every thing were OK, you would get the message,

Successfully flushed the DNS Resolver Cache.
In addition, the DNS cache is flushed as part of repairing the Network’s TCP/IP Stack
If instead of Successful Flushing you get the message indicated that, the DNS could be Flushed.
Meanwhile,If u work with DNS CACHE STUFF U MAY receive this Error also, the following post help you to come up from this “here we go“Could not flush the DNS Resolver Cache error message”

While trying to clear DNS Cache on Windows XP or Vista computer, you might get error “Could not flush the DNS Resolver Cache” instead of successful flushing of DNS cache. We generally get this error when DNS Client service stops working or is disabled. You need to enable this service to resolve the issue.
Enable DNS Client Service



1. Click Start > Run
2. Type services.msc and click OK
3. Double click DNS Client option in the list
4. Set startup type automatic and click Start button
5. Close the settings window

After above steps, run the flush DNS command, you should see successful DNS cache clearance message.

Thursday, January 13, 2011

HIJACKING SSL


""SUCCESS IS ONLY OUR M**** F***** OPTION""

Lovers Of Hackersbay.in, How you all Doing Today…Hope you all Doing Good,Today I am Gonna Show You How To Crack SSL Certification Sites, Where U all PAY Bucks To Buy Stuffs..Lemme Take Yoy Through…

Before We Get Into..!! Let Us Know What Is SSL STRIP:
The SSL Strip Works By Watching All the Http Traffic, When a User Try to create Https Connection, SSL Strip replace the http By Https..And Persuade The User He was Connected To a HTTPS Connection..! You May B Posted Some Fuckin Warnings Ba ur Browser..Like “Page appears to be invalid “ Or “Link was Broken” or “404 Timed Out” Or “Server Not Responding” My Niggas Don Mind Keep your Movin ON.


What The Author Of The TOOL Says:è
The author of the tool Moxie Marlinspike says:”” This tool provides a demonstration of the HTTPS stripping attacks that were presented at Black Hat DC 2009. It will transparently hijack HTTP traffic on a network, watch for HTTPS links and redirects, and then map those links into either look-alike HTTP links or homograph-similar HTTPS links. It also supports modes for supplying a favicon which looks like a lock icon, selective logging, and session denial.””
A https Padlock Will Be Spoofed On the URL Bar, Amd Make The User Believe He/She Fuckin With Secured Website..LOL..!! And a SSL Connection Has Been Created Which Aint Be Pierced..!!

FLAW IN SSL AS PRACTISE:
Researcher Have Used 3 Techniques To Bring This Operation Success..! FAKE LEAF NODE CERTIFICATION . NULL CHARACTER ATTACK , MAN-IN-THE-MIDDLE ATTACK…We aint Gonna Discuss About this Shit..Coz a Person Who Buys a Car Don Need To Kno The Cars Tech Like TURBINE POWER, FUEL INJECTION TECHNIQUES, Enigines CC..Etcetra..!! If He Knows To Drive that’s Hell a Lot Enuf..Like Guys if u Can abl 2 Understand n Deploy..More Than Enuf.. !!
Here Is a Concept, For SSL Connection X509 Certificate is used To Authenticante a Person to Logging in His SECURED SERVER(Lmao).. !! If u are Log in to www.paypal.com.


They don fuckin care whether ur Requesting Into anything.paypal.com OR something.paypal.com..!! Wateva the page in Noob Lang.. X509 Certificates are formatted thro ASN1 Notation..! PASCAL Lang used By ASN1.. Pascal Will Consider the NULL as Character..! this is the Flaw.

So Signing a Request Like www.paypal.com \ 0.paypal.com Will be treated valid by authentication Servers. Coz the prefix can be ignored by servers..!!

If u guys any Doubt in Rejecting “0” Shoot ur Comments I have a real time Example that will Help u Understand Better..! the Blueanarchy.org can create a Fake Cert and use as Paypal.com and Use it..!

PERFORMING THE HIJACK ON WINDOWS:
Using the SSL Strip On Windows iz Similar 2 Using In LINUX..!! But LINUX Has Inbuilt FIREWALL , PORT FORWARDING mean If there is a Traffic On a Port While The Data is Travelling it has been Redirect 2 Another Port..! BUT Ma Man BILL GATES Forgot to Consider Tis Shits While Constructin His OS`s.
So We Make it as Manual .!!
Turn ur Machine Into IP FORWARDING MODE.
Riderct ur HTTP traffic To SSL Strip.
Now Run Ur SSL Strip.
Perform Arp Spoof to Decieve Ur network that all Traffic Has Been Pass Away Ba You.


PREREQUSITE:
Install Python , And SSLStrip is a Python based tool. You need two machines running Windows on same LAN- one for attacker, another for victim


Step 1:
Enable IP forwarding on Attacker’s Machine
Get the hacker machine into acting as a router as it
needs to forward all the traffic coming to it to outside
internet.
• Start Registry Editor (Regedit.exe).
• In Registry Editor, locate the following registry key:
• HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\Tcpip\Parameters
• Set the following registry value:
• Value Name: IPEnableRouter
• Value type: REG_DWORD
• Value Data: 1
• A value of 1 enables TCP/IP forwarding for all
network connections that are installed and used by
this computer.
• Quit Registry Editor. Restart the PC.

Step 2:
Set a firewall rule that forwards HTTP trafc from the victim to hacker’s machine for modification:
It tells all HTTP traffic from victim, coming on port 80 of hacker’s machine to redirect it on port 10000 on the same hacker’s machine. Port 10000 is used by SSLStrip tool by default..if u don find any utility to set a new firewall rule Visit Kenneth Xu (http://
kennethxu.blogspot.com) and fetch it..! Java based TCP/IP port forwarding utility – (Download here http://code.google.com/p/portforward/downloads/list)

C:\>java -classpath commons-logging.jar;portforward.jar org.enterprisepower.net.portforward. Forwarder 80 localhost:10000
This command forwards all HTTP traffic received on port 80 of Hacker’s machine to port 10000 of the same machine. SSLStrip runs on port 10000 by default

GOT INTERSTING..!! If u are a Die Hard Hacker U Must Be, I kno To Be a Hacker, It Takes Years , And Matters Full Of Brain n Passion in Wat He Do.! Lemme Come to Topic..
Step 3:
ARP spoof the target traffic to redirect to hacker’s machine Suppose the Victim machine’s IP is 192.168.1.10 and IP of the gateway is 192.168.1.1. It will poison the victim machine (192.168.1.10) MAC table and instead of sending the traffic to Gateway (192.168.1.1) it will send to the hacker’s machine falsely assuming it as the real gateway.Run the following command on attacker’s machine
arpspoof –t 192.168.1.10 192.168.1.1
It Will Update The Update The ARP Table Of Victim Machine.
Step 4:
Run SSLStrip on hacker’s machine:
Run the following command on Hacker’s machineè
python sslstrip.py -f lock.ico
You can see the log fle in the SSLStrip installation folder for logged credentials.The SSLStrip will log all the traffic coming from Victim’s machine and strips the all the SSL link (https://) to http:// between the Victim and Hacker. Thus the traffic between the Victim to Hacker is transparent and in clear








View page source can also reveal that links are stripped of SSL:
..
Gmail on http: see Figure 7




****IMP Look Up The URL BAR Guys…!! Fuck The SECURITY..! FUCK THE WORLD..!!
An example of Log file of SSLStrip, Passwords logged: see Figure 8.





Guys There We Are…!! Have Spent Some time Get to Know About SSL Stripps Where are Other Guys Was Spendin Time Thinkin About Wen Their GIRL FRIEND STRIPS OFF HER CLOTHES For them..! He he he.. Jus For Kiddin..LOL…!!
GOSH ..!! My Back Hurts !!
Materials Refered, I just gave d cream ,And For Ur Future Reference As Well..If u wanna Kno In Depth Info Fetch the Research Papers Wat I fuckin Gone Thro To Put in ma Own Sentence..! Here They Are…=è
SSLStrip tool:
http://www.thoughtcrime.org/software/sslstrip/
http://www.thoughtcrime.org/papers/null-prefix-attacks.pdf
http://www.blackhat.com/presentations/bh-dc-09/Marlinspike/BlackHat-DC-09-Marlinspike-Defeating-SSL.pdf


This Contents Are Strictly Belongs To The Property Of (hackersbay.in)-> HACKERS & Also d techie Who Helped To Bring this Paper To Our Readers Nilesh Kumar, A Nerd From HONEYWELL TECHNOLOGY, Bengaluru….!



.




Analysis of a PDF attack:

Our Research Papers Are ripped and compiled by the way even n00b can understand if u go weird about somethin.y shyin drop comment and share it..!! Yeah Here is thhe Picture """Hacker Found a Loophole In Adobe Reader So He Hided The .exe Files With PDF Book, There s another Hacker Who Found A LoopHole In Playin Vdos In Adobe Reader “These r the News , We Often Hear”, And If You Ask Me Why Its Coz, Almost Every Month Adobe Fixes D Issue Our Guys Start To Find A Exploit,, And it makes Global Noobs To get freakin Scared , There FOXIT READER Understand The Opportunity And Marketed Their New PDF Reader, Guys TRUST ME..!! Foxit has Lotta Mother Fuckin Options Wen Compare to the Adobe…!!!

So How These Hackers Tryina Find Exploits In PDF, over the past twelve months, the following scenario was developed to highlight methods used by attackers to extract corporate secrets from a victim organization. Not every attack follows these steps in this order. However, this scenario illustrates some of the most common and damaging tactics used against commercial and government organizations today.

Here We Goè

Step 1: The attacker begins by using powerful free attack software to create a malicious PDF file that containsexploitation code. If this file is opened on a victim computer with unpatched PDF reader software, this code will execute commands of the attacker’s choosing.



Step 2: The attacker loads the malicious PDF file 2 a third-party website.The attacker then loads the malicious PDF file on a publicly accessible website.


STEP 3 : The attacker now sends e-mail to high-profile individualin the target organization, including corporate officers.This message contains a hyperlink to the attacker’s malicious PDF file on the external Web server. The e-mail message is finely tuned to each target individual with a focused effort to get the recipient to click on the link. some other trusted site. The attacker does not includethe malicious PDF file as an e-mail attachment, because such attacks are more likely to be blocked by e-mail filters, anti-virus software, and other defenses of the target organization.


Step4: The victim inside the targeted organization reads the e-mail, pulling down the attacker’s message with the link to the malicious PDF. The user reads the e-mail and clicks on the link.


Step5: When the user on the victim machine clicks on the link in the e-mail message, the victim’s computer automatically launches a browser to fetch the malicious PDF file. When the file arrives at the victim computer, the browser automatically invokes the PDF reader program to process and display the malicious PDF file.


Step6: When the PDF reader software processes the malicious PDF file for display, exploit code from the file executes on the victim machine. This code causes the system to launch an interactive command shell the attacker can use to control the victim machine. The exploit code also causes the machine to make an outbound connection back to the attacker through the enterprise firewall. Via this reverse shell connection, the attacker uses an outbound connection to gain inbound control of the victim machine.


Step 7 : With shell access of the victim machine, the attacker scours the system looking for sensitive files stored locally. After stealing some files from this first conquered system, the attacker looks for evidence of other nearby machines. In particular, the attacker focuses on identifying mounted file shares the user has connected to on a file server.



Step8: After identifying a file server, the attacker uses the command shell to access the server with the credentials of the victim user who clicked on the link to the malicious PDF. The attacker then analyzes the file server, looking for more files from the targetorganization.


Step9: Finally, with access to the file server, the attacker extracts a significant number of sensitive documents, possibly including the organization’s trade secrets and business plans, Personally Identifiable Information about customers and employees, or other important data the attacker could use or sell.



I Hope Guys You Liked The Scene Behind PDF Exploitation Steps, No Hesitation…!! Lets Share it..!!! This Contents Are Strictly Belongs To The Property Of (hackersbay.in)-> HACKERS

How to Secure your Wireless NETWORK:


Niggas, Wereva We GO Some Bullshits, Followin us Freq Doin DoS attack against us, But we never gonna back DOWN..We got 20k hits in a matter 0f one week..it shows our Victory..And Unique Content..!! Back to Business
Lemme take yo thro how to keep ur Wireless network secured if u donn wanna mess up or gettin fucked by some b*****…!


Before to Drive a Truck, Lets learn how to drive, and Wats in it..!! Here are the few Terminologies, You shud know About Wireless networked systems..!! if u don understand this underlyin concepts, it lll be a hard time for u to guarding yo Wireless network..

 SSID: (Service Set Identifier) If u having a wireless router or modem or any shits..the Hardware must have SSID(Like Namin a New born Baby, Yo can name ur Router How it wann be called ba others,But If u take any BSNL Connection Wi fi ASDL Modem Comes With SSID name May be second name of yo father) , Router has a


Device Burned With MAC &SSID Found in the Picture(WANADOO-02DB)
functionality that it can broadcast or stealth broadcast Which means if u scan for wireless networks u often find networks in Broadcast mode (I.e Tikona 1800 204 3333)Like that…In stealth Broadcast we cant identify the wireless network.. MODEM Don have this fuckin option, so that’s y weneva u scan any, u find some home networks modem range..but u can proceed only after Given SSID in the prompt box..!!


 WEP: (Wired Equivalence privacy) this Protocol givea Base level security for all wi fi vendors and system Can benefit from OSI Standardization effort..Tha fat ass option is one can Set in “ON” Or
“OFF”To use this…But Mostly all jerks n Geeks Forcibly set this “ON”

 WPA: (Wi Fi Protected Access) A security protocol tat was designed to secure Wireless Technology and To overcome the WEP Limitations..!! (WPA & WPA2 )


 TKIP: (Temporal Key Intergrity protocol) It’s a More secure version of WEP and it utilize the WPA For Network Security, It uses Some Diff kinda Algorithms than WEP, More trusted Encryption tunnels.(But trust me, most admin will not use this, But the Company Security policy wants to maintain diff security scheme for each heirerachy of the employes in the Org…Admins will deploy this feature)

 MAC: (Media Access Control) Its used to get Multiple access in a Networked Environment,But MAC Address is a 12Digit Hexa decimal number that is associated with Network adapter, MAC Address is unique to each IP Address…(00-12-FA-WE-3R-TR) First 6 digits Says 00-12-FA Manufacturer Code Which say Network Adapter belongs to Whom, And next 6 digit Was assigned to unique Persons WE-3R-TR.

 DHCP : (Dynamic Host Configuration Protocol)  its one of the inbuilt features of Router..It services for the User who restarts the system, Generates the fresh IP address to them to frame the Device address in the network

YOU ARE UNDER COVER:
Whether you are in Wired or wireless Environment..Yo are under Scan by some1 eye, TCP Monitor Or Any one Can use Sniffer tools like packetyzer to and can read your communication Coz all the transportations are not encrypted..
POSSIBLE ATTACKS: EAVESDROPPING(Installing Malicious tools and Make ur machine as a listener, And he hacker gets all packet information coz it was redirected by him to server)
DoS Attacks Injecting Noise Or Interfrences in the wireless network Infinitely, Cause inturn Denial for particular service which tey Requested,Remember A Hacker Can Extract the SSID name of the network in Response to His ICMP Packets..This gives u a Glimpse of Dos Attacks
YES NIGGAS..! SECURE IT BY NOW…..
[i] 3 Scenarios about Yo And Ur SSID:
 Yes we can, Set the SSID Manually
 When yo Buy a Router it Burned With MAC Address, And SSID That is always as “default” name
 Manufacturer of Router Provides a methodology to change ur SSID To secure the Network, Follow that,And Change it With Mixed Alphas Like THIS(H4CK07IC)


[ii] WEP Encryption “TURN ON “ For GodSake..
WEP Encrytion is the standard Encryption scheme for all OSI Network Complicance Products, It comes With Encryption, But doesn’t” TURNED ON” Automatically, Do it And Change all the defaults in the Newly purchased Router..So yo have changed SSID, And Turned On WEP…. I Assume.

[iii] MAC Address Filtering Set ur MAC Address Not Broadcast


This can be done by Entering your MAC Address into your Network access point devices.Doin this Ensures Great level of security..

[iv] DUMP THE DEFAULTS  Change all your defaults passwords.And keep this Security checklist With you…! Which also Includes Changing the Default Subnet that is 192.168.1.0



If you don’t experience routine changes in your network,once in a 3 months keep this checklist and review how your network security is Doing ! Such check ups not only help you to check its tampered or not , But help you to have a peace of mind that you all doing well By Showing ur middle finger Who tryina gain acess..!!

Drop yo comments to interact !!

Tuesday, January 11, 2011

15 Facts about STEVE JOBS

The Apple’s CEO Steve Jobs sells dreams not products. He is one of the greatest corporate storyteller on world stage. People love everything about him whether its his presentation style, quotes or facts about his personal and professional life. There are many amazing and interesting facts about Steve Jobs life and work and 15 of them are here for yo

u.


Steve Jobs Facts

1. Steve was adopted by Justin and Clara Jobs of California
2. Steve Jobs founded Apple in 1976 and he was fired from Apple (the company he founded himself) in 1984 (the same year that Apple introduced Macintosh)
3. Steve founded NeXt, an highly experimental and technologically advanced computer company that introduced embedded graphics that was a step forward towards personal computing.
4. In 1996, Apple bought NeXt and Steve Jobs returned to Apple.
5. In 2000 at MacWorld Expo, Steve became the permanent CEO of Apple.
6. Steve’s Appearance: Slender; wears jeans, with a black turtleneck and running shoes. Many things around on why he chooses the same clothes everyday.
7. He loves Beatles and claim they have inspired his business model.
8. He is a Steve Jobs Facts.
9. His first apartment in New York was later sold to Bono of U2.
10. Steve has big feet, size 14 big.
11. As the Chairman and CEO of Apple Computers, he pays himself an annual salary of $1 per year.
12. He was named The Most Powerful person in Business by Fortune Magazine in 2007.
13. Steve has many awards including National Medal of Technology that he received from the President Ronald Reagen in 1985.
14. His favorite catch phrases are: “Un-be-lievable”; “Mere mortals”; “It’s huge” & “Wouldn’t it be great”.
15. Steve is probably the only corporate honcho to have the displeasure of reading his own obituary, which was fired by financial newswire Bloomberg to its subscribers.


FUNNY GUY.............^_^

Friday, January 7, 2011

PandaLabs Annual Report 2010

In 2010, cyber-criminals have created and distributed a third of all existing viruses. That is, in just 12 months, they have created 34 percent of all malware that has ever existed and has been classified by the company. Furthermore, the Collective Intelligence system, which automatically detects, analyzes and classifies 99.4 percent of all malware received, currently stores 134 million unique files, out of which 60 million are malware (viruses, worms, Trojans and other computer threats).


Topics covered:



* Threats in 2010
* Stuxnet, Iran and nuclear plants
* Cyber war
* Aurora
* Cyber-crime
* Cyber-protests
* Mariposa
* Social networks
* Rogueware
* 2010 in figures
* More BlackHat SEO
* Windows 7 vs Mac OS X Snow Leopard
* Cell phone security
* Spam in 2010
* Vulnerabilities in 2010
* Trends in 2011
* Conclusion


Trojans still dominate the ranking of new malware that has appeared in 2010 (56 percent of all samples), followed by viruses and worms. It is interesting to note that 11.6 percent of all the malware gathered in the Collective Intelligence database is rogueware or fake antivirus software, a malware category that despite appearing only four years ago is creating much havoc among users.


Click here to read full report

Monday, January 3, 2011

Registry/Registrar Separation Coming to an End?

Since 1998, there has been a separation between domain registries that manage and operate Top Level Domains (TLD ) and the registrars that sell domain names. That policy of separation will not be carried forward for a new generation of TLDs ,set to emerge over the course of the next several years.
A number of domain name industry stakeholders — including the .org registry and TLD operator Afilias – opposed the move to remove the separation of registries from registrars. They argued that having cross-ownership could lead to abuses and lack of competition. With a new ICANN policy set to enable cross-ownership, consumer protections will be put in place which may help alleviate those concerns.
“After much debate on the issue of vertical integration, this month the ICANN board voted to allow registrars own new TLD registries,” Roland LaPlante, senior vice-president and chief marketing officer at Afilias told InternetNews.com. “To be clear, Afilias raised concerns about whether adequate consumer protection could be assured in vertically integrated registries/registrars.   ICANN has adopted specific mechanisms designed to guard against abusive practices that could harm domain name registrants.”
With the new ICANN policy, there is now an opportunity for Afilias to profit from the new rules. LaPlante noted that many registrars have already approached Afilias as a potential back-end service for TLDs they plan to apply for.
On the issue of trying to prevent potential abuse of the registry/registrar cross-ownership, LaPlante said that governance of registrar/registry ownership is an ICANN issue. That said, he added that Afilias has a positive track record of ensuring that all registrars have equal access to its registry system. According to LaPlante, it is Afilias’ intention to continue to be vigilant in that area.
While ICANN has opened the door to cross-ownership, potential domain registry operators will need to overcome a number of technical challenges.  That’s where Afilias is looking to profit, with services for potential new TLD registry/registrar owners.
“Afilias is offering a white-labeled registry service to registrars that seek to launch new TLDs in this upcoming round,” LaPlante said. “We also offer this service, as we do for 15 other TLDs, to corporations or communities looking to launch their new TLD bids.”
As part of the new round of TLDs from ICANN, Afilias has previously announced that it is part of a bid for the .eco TLD. With cross-ownership now possible, the ownership landscape of the overall domain name industry could be shifting as well.
“There are a variety of models that may come about from this new TLD round for Afilias or other registry providers – whether as simply service providers, joint ventures, or applying for new TLDs directly,” LaPlante said. “We will be making some exciting announcements as the new TLD application timeframe is finalized.”
ICANN is now in the public comment phase for the final Applicant Guidebook for new generic TLDs.  The public comment period ends on December 10th, after which ICANN plans on spending four months on market outreach about the new TLDs application process.

Sunday, December 26, 2010

Penetration Testing Add-ons for Firefox


In this post, I just wanted to enumerate a few Firefox add-ons that I thought were very useful in conducting penetration tests. I’d be really interested to hear what Firefox extensions other people are using for pen testing. So here it goes!
AddnEdit Cookies: This add-on allows you to easily add, delete and edit cookies in your browser.  (http://addneditcookies.mozdev.org/) Unfortunately, the latest version does not support the newer Firefox 3, until the maintainer updates the package, I’ve edited the latest XPI to work with the latest versions of Firefox. A copy of it can be found here.
DT Whois – Allows quick domaintools.com lookups for the page you are looking at (http://www.beysim.net/dtwhois/)
Firebug – Allows you to read, debug and locally tweak HTML, Javascript and CSS right in Firefox (http://getfirebug.com/)
HackBar – The toolbar that tries to do it all! (http://devels-playground.blogspot.com/)
Leet Key – an add on that makes it trivial to convert text in various formats back and forth.  For example, URL Encode, Base64, Hex and even morse code. |\|347! (http://leetkey.mozdev.org/)
Live HTTP Headers – Allows you to watch, edit and replay HTTP requests (http://livehttpheaders.mozdev.org/)
SQL Inject Me, XSS Me, Access Me - Those are 3 separate add-ons from Seccom Labs that try to make it easy to test Sql Injection, XSS vulnerabilities and Access vulnerabilities. (http://labs.securitycompass.com/index.php/exploit-me/)
SwitchProxy Tool – If you find yourself switching from no proxy, to burp proxy to paros proxy, etc a lot then you will enjoy switch proxy. It will allow you to switch proxy settings with just a few clicks! (http://mozmonkey.com/switchproxy/)
Tamper Data – It will allow you to selectively intercept HTTP and HTTPS traffic and tamper with the requests via it’s nice user interface. It will let you tamper with http headers, post and get requests. (http://tamperdata.mozdev.org/)
Torbutton – If you need to hide behind Tor, it can be only a click away with Torbutton (https://www.torproject.org/torbutton/)
User Agent Switcher - Need to change your user-agent string in a jiffy? Want to look like a robot? User Agent Switcher is here for that! (http://chrispederick.com/work/user-agent-switcher/)
exploit-db Search – Lets you search the exploit-db database right in the firefox search box (https://addons.mozilla.org/en-US/firefox/addon/50241)
SecurityWire Search – Lets you search the top security sites on the web right in the Firefox search box. All sites in the index have been handpicked by the SecurityWire Team. (https://addons.mozilla.org/en-US/firefox/addon/58686)
For a listing and easy installation of all these  on the mozilla ad-ons site. simply follow this link: https://addons.mozilla.org/en-US/firefox/collection/pentesterstools
Hope you enjoy the add-ons, next post will be about general security add-ons for Firefox.



For More Search in Firefox Site underr "web app security and pen testing"