[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fuvumb4xdCpx00dLLdPS2y9E71WydHwSUfB3MPts3ySc":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},998,"What tools can export saved Firefox passwords, and what are their limitations with Master Passwords?","Common tools include `WebBrowserPassView`, `firepwd.py`, `LaZagne`, and `firefox_decrypt.py`. `WebBrowserPassView` supports command-line export but cannot decrypt with a Master Password. `firepwd.py` can handle key3.db with a Master Password but has a bug with key4.db. `firefox_decrypt.py` uses Network Security Services (NSS) and supports both key3.db and key4.db Master Password decryption, though it requires matching Python and Firefox architectures. For a deeper dive into the NSS method, see [Exporting saved passwords from Firefox browser via Network Security Services](\u002Fnews\u002Fexporting-saved-passwords-from-firefox-browser-via-network-security-services).","\u003Cp>Common tools include `WebBrowserPassView`, `firepwd.py`, `LaZagne`, and `firefox_decrypt.py`. `WebBrowserPassView` supports command-line export but cannot decrypt with a Master Password. `firepwd.py` can handle key3.db with a Master Password but has a bug with key4.db. `firefox_decrypt.py` uses Network Security Services (NSS) and supports both key3.db and key4.db Master Password decryption, though it requires matching Python and Firefox architectures. For a deeper dive into the NSS method, see [Exporting saved passwords from Firefox browser via Network Security Services](\u002Fnews\u002Fexporting-saved-passwords-from-firefox-browser-via-network-security-services).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-exporting-saved-passwords-from-firefox-browser\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-tools-can-export-saved-firefox-passwords-and-what-are-their-limitations-wit-1777481096076","WebBrowserPassView, firepwd, LaZagne, firefox_decrypt, Master Password, NSS",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},245,"Penetration Techniques - Exporting Saved Passwords from Firefox Browser","penetration-techniques-exporting-saved-passwords-from-firefox-browser","Learn how to export saved passwords from Firefox browser, including storage methods, decryption principles, and tools like WebBrowserPassView for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Penetration Techniques - Exporting Saved Passwords from Chrome Browser', the principles and exploitation methods for exporting Chrome browser passwords were introduced. This article will introduce the principles and exploitation methods for exporting Firefox browser passwords, analyzing the exploitation approach.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Password Storage Methods\u003C\u002Fli>\u003Cli>Principle Introduction\u003C\u002Fli>\u003Cli>Common Export Tools\u003C\u002Fli>\u003Cli>Exploitation Approach\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Password Storage Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>When normal users visit websites, they can choose to have the Firefox browser save their login credentials, allowing Firefox to automatically fill in the passwords during subsequent logins.\u003C\u002Fp>\u003Cp>These can be viewed by selecting Logins and Passwords, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016179920_0_2b4674b8c9.jpeg\">\u003C\u002Fp>\u003Cp>Includes the following information:\u003C\u002Fp>\u003Cul>\u003Cli>Website address\u003C\u002Fli>\u003Cli>Username\u003C\u002Fli>\u003Cli>Password\u003C\u002Fli>\u003Cli>Created\u003C\u002Fli>\u003Cli>Last modified\u003C\u002Fli>\u003Cli>Last used\u003C\u002Fli>\u003C\u002Ful>\u003Cp>All records are stored in the same file, specifically located at: %APPDATA%\\Mozilla\\Firefox\\Profiles\\xxxxxxxx.default\\\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>xxxxxxxx is an 8-character random combination of letters and numbers\u003C\u002Fp>\u003Cp>The file name for saving records varies across different versions of Firefox, with specific differences as follows:\u003C\u002Fp>\u003Cul>\u003Cli>For versions greater than or equal to 32.0, the file for saving records is logins.json\u003C\u002Fli>\u003Cli>For versions greater than or equal to 3.5 but less than 32.0, the file for saving records is signons.sqlite\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For more detailed file descriptions, refer to:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fkb.mozillazine.org\u002FProfile_folder_-_Firefox\u003C\u002Fp>\u003Cp>Download links for different versions of Firefox:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fftp.mozilla.org\u002Fpub\u002Ffirefox\u002Freleases\u002F\u003C\u002Fp>\u003Cp>To locate the logins.json file via cmd command, the content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir %APPDATA%\\Mozilla\\Firefox\\Profiles\\*logins.json \u002Fs \u002Fb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View the content of the logins.json file, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016181785_1_8663279370.jpeg\">\u003C\u002Fp>\u003Cp>The encryptedUsername and encryptedPassword are encrypted content; decryption requires obtaining the key file (key and iv) and performing 3DES-CBC decryption\u003C\u002Fp>\u003Cp>The location of the key file varies across different versions of Firefox, with specific differences as follows:\u003C\u002Fp>\u003Cul>\u003Cli>For versions less than 58.0.2, the key file is key3.db\u003C\u002Fli>\u003Cli>For versions greater than or equal to 58.0.2, the key file is key4.db\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The version distinction between key3.db and key4.db originates from https:\u002F\u002Fgithub.com\u002Flclevy\u002Ffirepwd\u002Fblob\u002Fmaster\u002Ffirepwd.py#L236\u003C\u002Fp>\u003Cp>In my test system (Win7x64) with 64-bit Firefox installed, the test results differ, specifically as follows:\u003C\u002Fp>\u003Cul>\u003Cli>If the Firefox version is below 58.0, the key file is key3.db\u003C\u002Fli>\u003Cli>If Firefox is a higher version, the key file is key4.db\u003C\u002Fli>\u003C\u002Ful>\u003Cp>By default, the current user's permissions allow viewing all passwords saved in the Firefox browser. To enhance security, Firefox supports adding extra protection for saved passwords: setting a Master Password\u003C\u002Fp>\u003Cp>The specific location is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016182756_2_b588354a99.jpeg\">\u003C\u002Fp>\u003Cp>After adding a Master Password, viewing saved passwords requires entering the Master Password\u003C\u002Fp>\u003Cp>Decryption process:\u003C\u002Fp>\u003Col>\u003Cli>Read the key file (key4.db or key3.db) to obtain the key and iv\u003C\u002Fli>\u003Cli>Read the contents of the record file (logins.json or signons.sqlite)\u003C\u002Fli>\u003Cli>If no Master Password is set, use the key and iv to perform 3DES-CBC decryption on the encrypted content in the record file\u003C\u002Fli>\u003C\u002Fol>\u003Cp>If a Master Password is set, the plaintext Master Password must also be obtained to proceed with decryption\u003C\u002Fp>\u003Ch2>0x03 Export Tools\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. WebBrowserPassView.exe\u003C\u002Fh3>\u003Cp>Download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.nirsoft.net\u002Futils\u002Fweb_browser_password.html\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This version does not support command-line operations\u003C\u002Fp>\u003Cp>The command-line version needs to be downloaded from another address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.nirsoft.net\u002Fpassword_recovery_tools.html\u003C\u002Fp>\u003Cp>Usage in command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>WebBrowserPassView.exe \u002FLoadPasswordsFirefox 1 \u002Fshtml \"c:\\test\\passwords.html\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is saved in c:\\test\\passwords.html, with content as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016184183_3_fa692c7d8e.jpeg\">\u003C\u002Fp>\u003Cp>Can obtain complete information, including the following categories:\u003C\u002Fp>\u003Cul>\u003Cli>Website address\u003C\u002Fli>\u003Cli>Username\u003C\u002Fli>\u003Cli>Password\u003C\u002Fli>\u003Cli>Created\u003C\u002Fli>\u003Cli>Last modified\u003C\u002Fli>\u003Cli>Last used\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Decryption using Master Password is not supported\u003C\u002Fp>\u003Ch3>2. firepwd.py\u003C\u002Fh3>\u003Cp>Address: https:\u002F\u002Fgithub.com\u002Flclevy\u002Ffirepwd\u003C\u002Fp>\u003Cp>Dependencies need to be installed:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pip install pyasn1\u003Cbr>pip install pycrypto\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Can obtain partial information, including the following categories:\u003C\u002Fp>\u003Cul>\u003Cli>Website address\u003C\u002Fli>\u003Cli>Username\u003C\u002Fli>\u003Cli>Password\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>firepwd.py -d C:\\Users\\a\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\5a4gs6zh.default-release\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016185505_4_3ba24833c8.jpeg\">\u003C\u002Fp>\u003Cp>Decryption using Master Password is supported\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In my own testing environment, firepwd.py only supports Master Password decryption for key3.db; there is a bug in Master Password decryption for key4.db\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Cp>Using the test file mozilla_db (key3.db), with Master Password as MISC*, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python firepwd.py -p 'MISC*' -d mozilla_db\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is normal, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016186625_5_255ff0d1af.jpeg\">\u003C\u002Fp>\u003Cp>In my testing environment (key4.db), with Master Password as 12345678, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>firepwd.py -d C:\\Users\\a\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\5a4gs6zh.default-release\\ -p \"12345678\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>There is a bug in decryption, prompting password failure, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016187118_6_f23b31e719.jpeg\">\u003C\u002Fp>\u003Ch3>3.Lazagne\u003C\u002Fh3>\u003Cp>Address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FAlessandroZ\u002FLaZagne\u002F\u003C\u002Fp>\u003Cp>The code for exporting Firefox browser comes from https:\u002F\u002Fgithub.com\u002Flclevy\u002Ffirepwd\u003C\u002Fp>\u003Cp>Same result as above, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016187579_7_25ee0f6b5d.jpeg\">\u003C\u002Fp>\u003Ch3>4.firefox_decrypt.py\u003C\u002Fh3>\u003Cp>Address: https:\u002F\u002Fgithub.com\u002Funode\u002Ffirefox_decrypt\u003C\u002Fp>\u003Cp>Uses NSS (Network Security Services) for decryption, supports Master Password decryption for key3.db and key4.db\u003C\u002Fp>\u003Cp>Can obtain partial information, including the following categories:\u003C\u002Fp>\u003Cul>\u003Cli>Website address\u003C\u002Fli>\u003Cli>Username\u003C\u002Fli>\u003Cli>Password\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Test results as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016187964_8_78e5a738be.jpeg\">\u003C\u002Fp>\u003Cp>On 64-bit systems, the Python and Firefox versions must match (both 32-bit or both 64-bit), otherwise it will prompt ERROR - Problems opening 'nss3.dll' required for password decryption\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The next article 'Exporting Passwords Saved in Firefox Browser via Network Security Services' will detail the specifics of decryption via NSS\u003C\u002Fp>\u003Ch3>5.Firefox Browser\u003C\u002Fh3>\u003Cp>By exporting configuration files\u003C\u002Fp>\u003Cp>Need to obtain the record file (logins.json or signons.sqlite) and the key file (key4.db or key3.db), saved in the local folder C:\\test\\data1\u003C\u002Fp>\u003Cp>Start Firefox using the -profile parameter:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>firefox.exe -profile C:\\test\\data1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Enter the correct Master Password to successfully obtain the information saved by the Firefox browser\u003C\u002Fp>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If Firefox has a Master Password set, using the above tools to attempt to export passwords will show 0 results, so it is necessary to first read the record file to confirm if records exist\u003C\u002Fp>\u003Cp>The Firefox version can be obtained by querying the registry, refer to previously open-source code: an open-source project\u003C\u002Fp>\u003Cp>Different versions of Firefox correspond to different record files, with specific differences as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Version greater than or equal to 32.0, the record file saved is logins.json\u003C\u002Fli>\u003Cli>Version greater than or equal to 3.5, less than 32.0, the record file saved is signons.sqlite\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The command to locate the logins.json file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir %APPDATA%\\Mozilla\\Firefox\\Profiles\\*logins.json \u002Fs \u002Fb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command to locate the signons.sqlite file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir %APPDATA%\\Mozilla\\Firefox\\Profiles\\*signons.sqlite \u002Fs \u002Fb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If records exist, you can then use tools to attempt export\u003C\u002Fp>\u003Cp>The following issues need attention during offline export:\u003C\u002Fp>\u003Ch4>1. No Master Password set\u003C\u002Fh4>\u003Cp>Only need to obtain the record file (logins.json or signons.sqlite) and the key file (key4.db or key3.db)\u003C\u002Fp>\u003Cp>Use firepwd.py or import the configuration file into the Firefox browser\u003C\u002Fp>\u003Ch4>2. Master Password set\u003C\u002Fh4>\u003Cp>(1) Only obtain the record file (logins.json or signons.sqlite) and the key file (key4.db or key3.db)\u003C\u002Fp>\u003Cp>Import the configuration file locally into the Firefox browser and enter the Master Password\u003C\u002Fp>\u003Cp>(2) Need to obtain the complete configuration file\u003C\u002Fp>\u003Cp>Must include the following files:\u003C\u002Fp>\u003Cul>\u003Cli>%APPDATA%\\Mozilla\\Firefox\\profiles.ini\u003C\u002Fli>\u003Cli>Files in %APPDATA%\\Mozilla\\Firefox\\Profiles\\xxxxxxxx.default\\\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Use firefox_decrypt.py, command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>firefox_decrypt.py C:\\test\\data1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the principles and exploitation methods for exporting Firefox browser passwords, analyzing the details to note when decrypting with a Master Password.\u003C\u002Fp>\u003Cp>For regular users, to enhance password security, it is recommended to set a Master Password.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Penetration Techniques - Exporting Saved Passwords from Chrome Browser', the principles and exploitation methods for exporting Chrome browser passwords were introduced. This article will introduce the principles and exploitation methods for exporting Firefox browser passwords, analyzing the exploitation approach.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Password Storage Methods\u003C\u002Fli>\u003Cli>Principle Introduction\u003C\u002Fli>\u003Cli>Common Export Tools\u003C\u002Fli>\u003Cli>Exploitation Approach\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Password Storage Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>When normal users visit websites, they can choose to have the Firefox browser save their login credentials, allowing Firefox to automatically fill in the passwords during subsequent logins.\u003C\u002Fp>\u003Cp>These can be viewed by selecting Logins and Passwords, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016179920_0_2b4674b8c9-1.jpeg\">\u003C\u002Fp>\u003Cp>Includes the following information:\u003C\u002Fp>\u003Cul>\u003Cli>Website address\u003C\u002Fli>\u003Cli>Username\u003C\u002Fli>\u003Cli>Password\u003C\u002Fli>\u003Cli>Created\u003C\u002Fli>\u003Cli>Last modified\u003C\u002Fli>\u003Cli>Last used\u003C\u002Fli>\u003C\u002Ful>\u003Cp>All records are stored in the same file, specifically located at: %APPDATA%\\Mozilla\\Firefox\\Profiles\\xxxxxxxx.default\\\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>xxxxxxxx is an 8-character random combination of letters and numbers\u003C\u002Fp>\u003Cp>The file name for saving records varies across different versions of Firefox, with specific differences as follows:\u003C\u002Fp>\u003Cul>\u003Cli>For versions greater than or equal to 32.0, the file for saving records is logins.json\u003C\u002Fli>\u003Cli>For versions greater than or equal to 3.5 but less than 32.0, the file for saving records is signons.sqlite\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For more detailed file descriptions, refer to:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fkb.mozillazine.org\u002FProfile_folder_-_Firefox\u003C\u002Fp>\u003Cp>Download links for different versions of Firefox:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fftp.mozilla.org\u002Fpub\u002Ffirefox\u002Freleases\u002F\u003C\u002Fp>\u003Cp>To locate the logins.json file via cmd command, the content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir %APPDATA%\\Mozilla\\Firefox\\Profiles\\*logins.json \u002Fs \u002Fb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View the content of the logins.json file, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016181785_1_8663279370-1.jpeg\">\u003C\u002Fp>\u003Cp>The encryptedUsername and encryptedPassword are encrypted content; decryption requires obtaining the key file (key and iv) and performing 3DES-CBC decryption\u003C\u002Fp>\u003Cp>The location of the key file varies across different versions of Firefox, with specific differences as follows:\u003C\u002Fp>\u003Cul>\u003Cli>For versions less than 58.0.2, the key file is key3.db\u003C\u002Fli>\u003Cli>For versions greater than or equal to 58.0.2, the key file is key4.db\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The version distinction between key3.db and key4.db originates from https:\u002F\u002Fgithub.com\u002Flclevy\u002Ffirepwd\u002Fblob\u002Fmaster\u002Ffirepwd.py#L236\u003C\u002Fp>\u003Cp>In my test system (Win7x64) with 64-bit Firefox installed, the test results differ, specifically as follows:\u003C\u002Fp>\u003Cul>\u003Cli>If the Firefox version is below 58.0, the key file is key3.db\u003C\u002Fli>\u003Cli>If Firefox is a higher version, the key file is key4.db\u003C\u002Fli>\u003C\u002Ful>\u003Cp>By default, the current user's permissions allow viewing all passwords saved in the Firefox browser. To enhance security, Firefox supports adding extra protection for saved passwords: setting a Master Password\u003C\u002Fp>\u003Cp>The specific location is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016182756_2_b588354a99-1.jpeg\">\u003C\u002Fp>\u003Cp>After adding a Master Password, viewing saved passwords requires entering the Master Password\u003C\u002Fp>\u003Cp>Decryption process:\u003C\u002Fp>\u003Col>\u003Cli>Read the key file (key4.db or key3.db) to obtain the key and iv\u003C\u002Fli>\u003Cli>Read the contents of the record file (logins.json or signons.sqlite)\u003C\u002Fli>\u003Cli>If no Master Password is set, use the key and iv to perform 3DES-CBC decryption on the encrypted content in the record file\u003C\u002Fli>\u003C\u002Fol>\u003Cp>If a Master Password is set, the plaintext Master Password must also be obtained to proceed with decryption\u003C\u002Fp>\u003Ch2>0x03 Export Tools\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. WebBrowserPassView.exe\u003C\u002Fh3>\u003Cp>Download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.nirsoft.net\u002Futils\u002Fweb_browser_password.html\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This version does not support command-line operations\u003C\u002Fp>\u003Cp>The command-line version needs to be downloaded from another address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.nirsoft.net\u002Fpassword_recovery_tools.html\u003C\u002Fp>\u003Cp>Usage in command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>WebBrowserPassView.exe \u002FLoadPasswordsFirefox 1 \u002Fshtml \"c:\\test\\passwords.html\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is saved in c:\\test\\passwords.html, with content as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016184183_3_fa692c7d8e-1.jpeg\">\u003C\u002Fp>\u003Cp>Can obtain complete information, including the following categories:\u003C\u002Fp>\u003Cul>\u003Cli>Website address\u003C\u002Fli>\u003Cli>Username\u003C\u002Fli>\u003Cli>Password\u003C\u002Fli>\u003Cli>Created\u003C\u002Fli>\u003Cli>Last modified\u003C\u002Fli>\u003Cli>Last used\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Decryption using Master Password is not supported\u003C\u002Fp>\u003Ch3>2. firepwd.py\u003C\u002Fh3>\u003Cp>Address: https:\u002F\u002Fgithub.com\u002Flclevy\u002Ffirepwd\u003C\u002Fp>\u003Cp>Dependencies need to be installed:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pip install pyasn1\u003Cbr>pip install pycrypto\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Can obtain partial information, including the following categories:\u003C\u002Fp>\u003Cul>\u003Cli>Website address\u003C\u002Fli>\u003Cli>Username\u003C\u002Fli>\u003Cli>Password\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>firepwd.py -d C:\\Users\\a\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\5a4gs6zh.default-release\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016185505_4_3ba24833c8-1.jpeg\">\u003C\u002Fp>\u003Cp>Decryption using Master Password is supported\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In my own testing environment, firepwd.py only supports Master Password decryption for key3.db; there is a bug in Master Password decryption for key4.db\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Cp>Using the test file mozilla_db (key3.db), with Master Password as MISC*, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python firepwd.py -p 'MISC*' -d mozilla_db\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is normal, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016186625_5_255ff0d1af-1.jpeg\">\u003C\u002Fp>\u003Cp>In my testing environment (key4.db), with Master Password as 12345678, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>firepwd.py -d C:\\Users\\a\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\5a4gs6zh.default-release\\ -p \"12345678\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>There is a bug in decryption, prompting password failure, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016187118_6_f23b31e719-1.jpeg\">\u003C\u002Fp>\u003Ch3>3.Lazagne\u003C\u002Fh3>\u003Cp>Address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FAlessandroZ\u002FLaZagne\u002F\u003C\u002Fp>\u003Cp>The code for exporting Firefox browser comes from https:\u002F\u002Fgithub.com\u002Flclevy\u002Ffirepwd\u003C\u002Fp>\u003Cp>Same result as above, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016187579_7_25ee0f6b5d-1.jpeg\">\u003C\u002Fp>\u003Ch3>4.firefox_decrypt.py\u003C\u002Fh3>\u003Cp>Address: https:\u002F\u002Fgithub.com\u002Funode\u002Ffirefox_decrypt\u003C\u002Fp>\u003Cp>Uses NSS (Network Security Services) for decryption, supports Master Password decryption for key3.db and key4.db\u003C\u002Fp>\u003Cp>Can obtain partial information, including the following categories:\u003C\u002Fp>\u003Cul>\u003Cli>Website address\u003C\u002Fli>\u003Cli>Username\u003C\u002Fli>\u003Cli>Password\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Test results as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016187964_8_78e5a738be-1.jpeg\">\u003C\u002Fp>\u003Cp>On 64-bit systems, the Python and Firefox versions must match (both 32-bit or both 64-bit), otherwise it will prompt ERROR - Problems opening 'nss3.dll' required for password decryption\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The next article 'Exporting Passwords Saved in Firefox Browser via Network Security Services' will detail the specifics of decryption via NSS\u003C\u002Fp>\u003Ch3>5.Firefox Browser\u003C\u002Fh3>\u003Cp>By exporting configuration files\u003C\u002Fp>\u003Cp>Need to obtain the record file (logins.json or signons.sqlite) and the key file (key4.db or key3.db), saved in the local folder C:\\test\\data1\u003C\u002Fp>\u003Cp>Start Firefox using the -profile parameter:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>firefox.exe -profile C:\\test\\data1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Enter the correct Master Password to successfully obtain the information saved by the Firefox browser\u003C\u002Fp>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If Firefox has a Master Password set, using the above tools to attempt to export passwords will show 0 results, so it is necessary to first read the record file to confirm if records exist\u003C\u002Fp>\u003Cp>The Firefox version can be obtained by querying the registry, refer to previously open-source code: an open-source project\u003C\u002Fp>\u003Cp>Different versions of Firefox correspond to different record files, with specific differences as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Version greater than or equal to 32.0, the record file saved is logins.json\u003C\u002Fli>\u003Cli>Version greater than or equal to 3.5, less than 32.0, the record file saved is signons.sqlite\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The command to locate the logins.json file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir %APPDATA%\\Mozilla\\Firefox\\Profiles\\*logins.json \u002Fs \u002Fb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command to locate the signons.sqlite file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir %APPDATA%\\Mozilla\\Firefox\\Profiles\\*signons.sqlite \u002Fs \u002Fb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If records exist, you can then use tools to attempt export\u003C\u002Fp>\u003Cp>The following issues need attention during offline export:\u003C\u002Fp>\u003Ch4>1. No Master Password set\u003C\u002Fh4>\u003Cp>Only need to obtain the record file (logins.json or signons.sqlite) and the key file (key4.db or key3.db)\u003C\u002Fp>\u003Cp>Use firepwd.py or import the configuration file into the Firefox browser\u003C\u002Fp>\u003Ch4>2. Master Password set\u003C\u002Fh4>\u003Cp>(1) Only obtain the record file (logins.json or signons.sqlite) and the key file (key4.db or key3.db)\u003C\u002Fp>\u003Cp>Import the configuration file locally into the Firefox browser and enter the Master Password\u003C\u002Fp>\u003Cp>(2) Need to obtain the complete configuration file\u003C\u002Fp>\u003Cp>Must include the following files:\u003C\u002Fp>\u003Cul>\u003Cli>%APPDATA%\\Mozilla\\Firefox\\profiles.ini\u003C\u002Fli>\u003Cli>Files in %APPDATA%\\Mozilla\\Firefox\\Profiles\\xxxxxxxx.default\\\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Use firefox_decrypt.py, command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>firefox_decrypt.py C:\\test\\data1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the principles and exploitation methods for exporting Firefox browser passwords, analyzing the details to note when decrypting with a Master Password.\u003C\u002Fp>\u003Cp>For regular users, to enhance password security, it is recommended to set a Master Password.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",473,"Onedaysec",6,"published","2026-02-02T07:25:19.986Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Export Firefox Passwords: Penetration Techniques & Tools Guide","Firefox password export, penetration testing, browser security, password decryption, logins.json, key3.db, key4.db, WebBrowserPassView",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4,47],1001,1000,999,997,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.311Z","2026-07-23T16:02:24.323Z","draft","2026-07-23T16:15:59.300Z"]