FireFox Forensics
Windows Forensics: FireFox
Possible FireFox Evidence Items
Installation artifacts: Files and data created during the installation of FireFox.
User artifacts: Data generated by user activity within the browser.
Accounts: User account information stored by FireFox.
Settings/Preferences: Customized settings configured by the user.
History: Records of websites visited by the user.
Typed URLs: URLs manually entered by the user.
Bookmarks: Saved website links.
Cookies: Small files stored by websites to track user preferences and activity.
Internet cache: Temporary files (images, scripts, etc.) of visited websites.
Downloads: Records of files downloaded by the user.
Auto-complete/Form Data: Data automatically filled in forms based on previous entries.
Searching: Search queries made by the user.
Password Recovery: Information related to saved passwords.
Installation Artifacts: Program Files
FireFox installs programmatic items in the following locations:
\Program Files\Mozilla FireFox\Program Files (x86)\Mozilla FireFox
Typical installation-related items, such as
.dll,.ini, and.exefiles, are located in these directories.The End User License Agreement (EULA), ReadMe file, Profile Manager, and installation logs can be recovered.
Preloaded/default plug-ins, browser bookmarks, and thematic files are also installed in these locations during installation.
Installation Artifacts: Program Files - Location Example
Computer Local Disk (C:) > Program Files (x86) > Mozilla FirefoxContents include folders like
browser,defaults,dictionaries,plugins,uninstall,webapprt, and files likeAccessibleMarshal.dll,application.ini,breakpadinjector.dll,crashreporter.exe, etc.
Installation Log File
The
install.logfile, located in the Mozilla Firefox folder, identifies the date and time when the application was installed on the local machine.Information found in the log includes:
Destination path for all installed programmatic resources.
Specific components that were installed.
Local machine date/time when the installation was completed.
Installation Log File - Details
Example entries in the
install.loginclude:Mozilla Firefox Installation Started: 2009-04-06 13:22:23Installation Details:
Install Dir: C:\Program Files\Mozilla FirefoxLocale : en-USApp Version: 3.0.8GRE Version: 1.9.0.8
Entries detailing the installation of specific files and creation of directories.
Firefox Artifacts: User Directory
The basic user account structure is created at:
Users\username\AppData\local\MozillaUsers\username\AppData\Roaming\Mozilla
This is where artifacts such as browsing history, passwords, cached temporary Internet files, download settings, and preferences are stored.
Preferences: General
Users can adjust the form and function of FireFox using
Tools > Options.The preferences with the forensic impact are General, Content, Privacy, Security, and Advanced.
The General preference tab lists the home page and download settings.
Preferences: Privacy
The Privacy tab identifies the preferences for the storage of a user’s history, cookies, and personal information.
Preferences: Security
The Security tab provides users with access to password management.
When a user visits a Web site for the first time that requires a username and password, FireFox presents three choices:
Remember Passwords (default): Information about the Web site username and password is written to the
Signons.sqliteorSignons.txtfile.Never For this Site: Only the Web site’s URL is recorded in the
Signons.sqliteorSignons.txtfile.Not Now: No data is written to the
Signons.sqliteorSignons.txtfile.
Preferences: Security (Master Password)
Another security option is the application of a Master Password.
If used, the Master Password must be entered in order for FireFox to remember the password for a given Web site.
When a Master Password is used, the user’s credentials from the
key3.dbfile are used as part of the encryption algorithm.
Stored Web Site Authentication
By default, the Remember password option is enabled in FireFox.
The username and password information is stored in an encrypted format in the
signons.txtorsignons.sqlitefile.The algorithm used by FireFox to encrypt the data also uses user-specific data stored in a
key3.dbfile.AccessData’s PRTK can decrypt the information.
Formhistory.sqlite: Personal Data
Formhistory.sqlitestores auto-complete form data.When a user visits a site that requires the entry of personal information, FireFox can automatically populate the necessary fields with user data.
When this feature is enabled, the
formhistory.sqlitefile is used.
Places.sqlite: Bookmarks/History
Browser history and bookmarks are stored within the
places.sqlitefile.FTK parses the entries in an HTML file.
Cookies.sqlite
FireFox cookies are tracked in the
cookies.sqlitefile.FTK parses the cookie information into an HTML file.
Each cookie record entry tracks:
Web site that generated the cookie.
Expiration date.
Proprietary data of the stored cookie.
Prefs.js: Browser Preferences
The FireFox preferences for the user are tracked in the
prefs.jsfile.The JavaScript file lists:
Default download directory for the user.
Home page for the FireFox browser.
Network/proxy setting if present.
If a user chooses to download a file to a directory other than the default directory:
user_pref(“browser.download.usedownloaddir”,false);
Privacy settings:
user_pref("privacy.clearOnShutdown.offlineApps", true);user_pref("privacy.clearOnShutdown.passwords", true);user_pref("privacy.clearOnShutdown.siteSettings", true);user_pref("privacy.sanitize.sanitizeOnShutdown", true);
Downloads.sqlite
FireFox downloads are tracked in the
Downloads.sqlitefile.Each downloaded file entry includes information on the source of the download and the local machine destination directory for the downloaded file.
FireFox Stored Content: Cache
The FireFox Cache folder is the equivalent of IE’s Temporary Internet Files directory.
The components of downloaded Web pages can be found here.
The FireFox Cache folder is located at:
Users\username\AppData\Local\Mozilla\FireFox\Profiles\randomID.profilename\Cache