[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fm4XNYC4l5dWumtXSOjJFgksTqm0xomptvdde4iVhZJU":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":50,"createdAt":50,"_status":49},978,"What files are required for NSS initialization when exporting Firefox passwords, and how do they differ across Firefox versions?","NSS initialization requires three files: `cert9.db`, `key4.db`, and `logins.json`, all located in the Firefox profile folder (e.g., `%APPDATA%\\Mozilla\\Firefox\\Profiles\\xxxxxxxx.default`). For Firefox versions 32.0 and above, login data is stored in `logins.json`; for versions 3.5 to 32.0, the file is `signons.sqlite`. The article notes that the Python code sets the profile path and calls `NSS_Init(profilePath)` using these files.","\u003Cp>NSS initialization requires three files: `cert9.db`, `key4.db`, and `logins.json`, all located in the Firefox profile folder (e.g., `%APPDATA%\\Mozilla\\Firefox\\Profiles\\xxxxxxxx.default`). For Firefox versions 32.0 and above, login data is stored in `logins.json`; for versions 3.5 to 32.0, the file is `signons.sqlite`. The article notes that the Python code sets the profile path and calls `NSS_Init(profilePath)` using these files.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fexporting-saved-passwords-from-firefox-browser-via-network-security-services\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-files-are-required-for-nss-initialization-when-exporting-firefox-passwords--1777480972074","cert9.db, key4.db, logins.json, signons.sqlite, Firefox profile, NSS_Init",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":46,"updatedAt":47,"createdAt":48,"_status":49},239,"Exporting saved passwords from Firefox browser via Network Security Services","exporting-saved-passwords-from-firefox-browser-via-network-security-services","Learn to export saved Firefox passwords using Network Security Services (NSS) with Python. Includes Master Password verification, NSS initialization, and decryption steps.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Penetration Techniques - Exporting Saved Passwords from Firefox Browser', common methods for exporting Firefox browser passwords were introduced. Among them, firefox_decrypt.py uses NSS (Network Security Services) for decryption, supporting Master Password decryption for key3.db and key4.db. This article will explain the principles involved, develop test code to achieve Master Password verification, and share details of script development.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Network Security Services\u003C\u002Fli>\u003Cli>Exporting Firefox browser passwords via Python calls to Network Security Services\u003C\u002Fli>\u003Cli>Open-source Python scripts\u003C\u002Fli>\u003Cli>Implementation of brute-force scripts\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Network Security Services\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Network Security Services (NSS) is a set of libraries designed to support cross-platform development of secure client and server applications.\u003C\u002Fp>\u003Cp>Reference documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdeveloper.mozilla.org\u002Fen-US\u002Fdocs\u002FMozilla\u002FProjects\u002FNSS\u003C\u002Fp>\u003Cp>The Firefox browser uses NSS as the foundational library for encryption algorithms and secure network protocols, employing the PKCS#11 standard for credential encryption and decryption.\u003C\u002Fp>\u003Cp>Reference documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdeveloper.mozilla.org\u002Fen-US\u002Fdocs\u002FMozilla\u002FProjects\u002FNSS\u002FPKCS11\u003C\u002Fp>\u003Ch2>0x03 Exporting passwords from the Firefox browser by calling Network Security Services via Python\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Funode\u002Ffirefox_decrypt\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FKerisa\u002FBrowserPasswordDump\u002Fblob\u002Fmaster\u002FMozillaPwd.py\u003C\u002Fp>\u003Cp>The decryption process on Windows systems is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Load the nss3.dll required by Network Security Services\u003C\u002Fli>\u003Cli>Call NSS_Init() for initialization\u003C\u002Fli>\u003Cli>Call PK11_GetInternalKeySlot() to obtain the internal slot (used for verifying the Master Password)\u003C\u002Fli>\u003Cli>Call PK11_CheckUserPassword() to verify the Master Password\u003C\u002Fli>\u003Cli>Read logins.json to obtain encrypted data\u003C\u002Fli>\u003Cli>Call PK11SDR_Decrypt() for decryption\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Specific issues to note are as follows:\u003C\u002Fp>\u003Ch3>1. Python and Firefox versions must be consistent\u003C\u002Fh3>\u003Cp>On 64-bit systems, both must be either 32-bit or 64-bit\u003C\u002Fp>\u003Ch3>2. Add Firefox installation path to environment variables for easy invocation\u003C\u002Fh3>\u003Cp>The Firefox installation directory contains the nss3.dll we need to call, so you can add the Firefox installation path to the PATH environment variable. The corresponding Python code is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import os\u003Cbr>firefoxPath = \"C:\\Program Files\\Mozilla Firefox\"\u003Cbr>os.environ[\"PATH\"] = ';'.join([firefoxPath, os.environ[\"PATH\"]])\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>On 64-bit operating systems, the default installation directory for 64-bit Firefox is C:\\Program Files\\Mozilla Firefox, and for 32-bit Firefox it is C:\\Program Files (x86)\\Mozilla Firefox\u003C\u002Fp>\u003Cp>The Python code to call nss3.dll is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import ctypes\u003Cbr>NssDll = ctypes.CDLL(\"nss3.dll\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. NSS initialization requires three files\u003C\u002Fh3>\u003Cp>The specific location is: %APPDATA%\\Mozilla\\Firefox\\Profiles\\xxxxxxxx.default\\\u003C\u002Fp>\u003Cp>The following three files are required:\u003C\u002Fp>\u003Cul>\u003Cli>cert9.db\u003C\u002Fli>\u003Cli>key4.db\u003C\u002Fli>\u003Cli>logins.json\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The above three files can be saved in the same folder, for example, c:\\test\\data\u003C\u002Fp>\u003Cp>The code for NSS initialization is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>profilePath = \"C:\\\\test\\\\data\"\u003Cbr>NssDll.NSS_Init(profilePath)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Read logins.json to obtain encrypted data\u003C\u002Fh3>\u003Cp>The encryptedUsername and encryptedPassword entries are encrypted data and need to be decrypted using NSS\u003C\u002Fp>\u003Cp>Before decryption, base64 decoding is required first, then call PK11SDR_Decrypt() to decrypt and obtain the plaintext\u003C\u002Fp>\u003Cp>The timeCreated, timeLastUsed, and timePasswordChanged entries are in Epoch Time format (total seconds from 00:00:00 on January 1, 1970, Coordinated Universal Time to the present, excluding leap seconds), which can be converted to actual time via the following website:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fesqsoft.com\u002Fjavascript_examples\u002Fdate-to-epoch.htm\u003C\u002Fp>\u003Cp>The Python code for converting the time format is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>from datetime import datetime\u003Cbr>def timestamp_to_strtime(timestamp):\u003Cbr>\treturn datetime.fromtimestamp(timestamp \u002F 1000.0).strftime('%Y-%m-%d %H:%M:%S')\u003Cbr>print timestamp_to_strtime(1580901797579)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Different versions of Firefox save records in different file names, with specific differences as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Version greater than or equal to 32.0, the file for saving records is logins.json\u003C\u002Fli>\u003Cli>Version greater than or equal to 3.5, less than 32.0, the file for saving records is signons.sqlite\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For more detailed file descriptions, refer to:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>http:\u002F\u002Fkb.mozillazine.org\u002FProfile_folder_-_Firefox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Open-source Python Script\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Funode\u002Ffirefox_decrypt\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FKerisa\u002FBrowserPasswordDump\u002Fblob\u002Fmaster\u002FMozillaPwd.py\u003C\u002Fp>\u003Cp>My test code has been uploaded to GitHub, the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Test environment:\u003C\u002Fp>\u003Cul>\u003Cli>64-bit Windows operating system with 64-bit Firefox browser installed\u003C\u002Fli>\u003Cli>The default installation path for Firefox is \"C:\\Program Files\\Mozilla Firefox\"\u003C\u002Fli>\u003Cli>The profile path is \"C:\\\\Users\\\\a\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\2yi8qmhz.default-beta\", including the following three files:\u003C\u002Fli>\u003Cli>cert9.db\u003C\u002Fli>\u003Cli>key4.db\u003C\u002Fli>\u003Cli>logins.json\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The code supports two functions:\u003C\u002Fp>\u003Ch3>1. Verify Master Password\u003C\u002Fh3>\u003Cp>Corresponding sub-function checkMasterPassword(MasterPassword)\u003C\u002Fp>\u003Cp>If the MasterPassword is correct, display the correct MasterPassword and return TRUE\u003C\u002Fp>\u003Cp>If the MasterPassword is incorrect, return FALSE\u003C\u002Fp>\u003Cp>This can be used to implement brute-force attacks on the Master Password\u003C\u002Fp>\u003Ch3>2. Export saved passwords from Firefox browser\u003C\u002Fh3>\u003Cp>Corresponding sub-function ExportData(MasterPassword)\u003C\u002Fp>\u003Cp>If no Master Password is set, set the MasterPassword parameter to \"\"\u003C\u002Fp>\u003Cp>If a Master Password is set, the correct Master Password must be entered to decrypt and obtain the actual data\u003C\u002Fp>\u003Cp>Specifically, the following information can be exported:\u003C\u002Fp>\u003Cul>\u003Cli>url\u003C\u002Fli>\u003Cli>username\u003C\u002Fli>\u003Cli>password\u003C\u002Fli>\u003Cli>timeCreated\u003C\u002Fli>\u003Cli>timePasswordChanged\u003C\u002Fli>\u003Cli>timeLastUsed\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of exporting Firefox browser passwords by calling Network Security Services via Python, sharing script development details.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",4,"published","2026-02-02T07:25:19.986Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Export Firefox Passwords via NSS: Master Password Decryption Guide","Firefox password export, NSS decryption, Master Password, key4.db, logins.json, Python NSS, browser security, password recovery",false,[],{"docs":41,"hasNextPage":38},[42,4,43,44,45],979,977,976,975,{"title":30,"description":30,"image":30},"2026-07-24T02:07:16.056Z","2026-07-23T16:02:21.513Z","draft","2026-07-23T16:15:53.455Z"]