[dba-Tech] FireFox SavePwd extentions

Stuart McLachlan stuart at lexacorp.com.pg
Sun Aug 8 18:40:23 CDT 2004


On 8 Aug 2004 at 15:49, Rocky Smolin - Beach Access S wrote:

> Are you certain that this extension is only saving your password on your
> computer and not someone else's as well?  I'm getting real paranoid in my
> old age about spyware.
> 
Certain. If you are in any doubt, save the "Always Save Password" to disk. 
It's actually called  "password.xpi".  Open it with Winzip or similar. 
Examine all of the files except password.jar with a text viewer.   Then 
open "password.jar" inside the archive with Winzip. Examine the included 
files in the same way. 

As you can see, there's no hidden payload anywhere. Apart from two jpegs, 
it's all plain XML or JavaScript in a couple of layers of zip wrapping.







-- 
Stuart





More information about the dba-Tech mailing list