Well, I don't care what Mozilla or 'The Shaver' says. If I know one thing, it will be that anonymity in Firefox is impossible. Before I'm going to repeat myself, here is another trick to de-anonymize someone which can come in quite handy if you are interested in reconnaissance. This function makes use of --yep here we go again-- the resource:/// scheme. This time we compare the locale and user-agent string available in Javascript space to the initial settings by Mozilla in their public files. It means that if you change your user-agent string in Firefox in about:config or through some extension, it will not override the file in the resource:/// directory because it's the default preference file we read out. See, stuff can work backwards if you don't pay attention. So every Firefox extension --I counted 14-- that tries to spoof the user-agent, or change the locale to spoof your current location will be completely useless. And so the quest continues, until next time; watch out with that Fox.
Total Recall On Firefox Part 2
By secgeeks - Posted on February 29th, 2008
Tagged:
85
vote
http://www.secgeeks.com/trackback/1505
















