Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts

Tuesday, February 5, 2008

How to recover saved firefox passwords

There are many different software packages on the market designed to recover saved Firefox passwords. In this article I will explain how to view saved Firefox passwords without any special software. We will let Firefox do all the work for us.

Method 1:
If you have access to the windows account where the passwords are saved then the solution can be simple. Open Firefox and go to tools>options>security>show passwords. This will list all of the accounts with saved passwords. If you click the show passwords button it will display all of the correlating passwords.

Method 2:
This method is a little more advanced, but can be used to recover the passwords of any account on the machine. The passwords are saved in the directory \Documents and Settings\\Application Data\Mozilla\Firefox\Profiles\. The files that store the passwords are signons2.txt and keys3.db. If these files are taken and put in the above path of another machine the can be viewed using method 1. The password is recovered and no fancy software was needed.

Attack Mitigation:

Use a master password in your Firefox browser. Go to Firefox>tools>options>security and check the use master password box. This will cause Firefox to ask for a master password before displaying the saved passwords. There are some software packages capable of recovering the passwords even with the master password set, but this will stop casual hackers.