FireFox Forensics

Windows Forensics: FireFox

Possible FireFox Evidence Items

  • Installation artifacts: Files and data created during the installation of FireFox.

  • User artifacts: Data generated by user activity within the browser.

  • Accounts: User account information stored by FireFox.

  • Settings/Preferences: Customized settings configured by the user.

  • History: Records of websites visited by the user.

  • Typed URLs: URLs manually entered by the user.

  • Bookmarks: Saved website links.

  • Cookies: Small files stored by websites to track user preferences and activity.

  • Internet cache: Temporary files (images, scripts, etc.) of visited websites.

  • Downloads: Records of files downloaded by the user.

  • Auto-complete/Form Data: Data automatically filled in forms based on previous entries.

  • Searching: Search queries made by the user.

  • Password Recovery: Information related to saved passwords.

Installation Artifacts: Program Files

  • FireFox installs programmatic items in the following locations:

    • \Program Files\Mozilla FireFox

    • \Program Files (x86)\Mozilla FireFox

  • Typical installation-related items, such as .dll, .ini, and .exe files, are located in these directories.

  • The End User License Agreement (EULA), ReadMe file, Profile Manager, and installation logs can be recovered.

  • Preloaded/default plug-ins, browser bookmarks, and thematic files are also installed in these locations during installation.

Installation Artifacts: Program Files - Location Example

  • Computer Local Disk (C:) > Program Files (x86) > Mozilla Firefox

  • Contents include folders like browser, defaults, dictionaries, plugins, uninstall, webapprt, and files like AccessibleMarshal.dll, application.ini, breakpadinjector.dll, crashreporter.exe, etc.

Installation Log File

  • The install.log file, located in the Mozilla Firefox folder, identifies the date and time when the application was installed on the local machine.

  • Information found in the log includes:

    • Destination path for all installed programmatic resources.

    • Specific components that were installed.

    • Local machine date/time when the installation was completed.

Installation Log File - Details

  • Example entries in the install.log include:

    • Mozilla Firefox Installation Started: 2009-04-06 13:22:23

    • Installation Details:

      • Install Dir: C:\Program Files\Mozilla Firefox

      • Locale : en-US

      • App Version: 3.0.8

      • GRE Version: 1.9.0.8

    • Entries detailing the installation of specific files and creation of directories.

Firefox Artifacts: User Directory

  • The basic user account structure is created at:

    • Users\username\AppData\local\Mozilla

    • Users\username\AppData\Roaming\Mozilla

  • This is where artifacts such as browsing history, passwords, cached temporary Internet files, download settings, and preferences are stored.

Preferences: General

  • Users can adjust the form and function of FireFox using Tools > Options.

  • The preferences with the forensic impact are General, Content, Privacy, Security, and Advanced.

  • The General preference tab lists the home page and download settings.

Preferences: Privacy

  • The Privacy tab identifies the preferences for the storage of a user’s history, cookies, and personal information.

Preferences: Security

  • The Security tab provides users with access to password management.

  • When a user visits a Web site for the first time that requires a username and password, FireFox presents three choices:

    • Remember Passwords (default): Information about the Web site username and password is written to the Signons.sqlite or Signons.txt file.

    • Never For this Site: Only the Web site’s URL is recorded in the Signons.sqlite or Signons.txt file.

    • Not Now: No data is written to the Signons.sqlite or Signons.txt file.

Preferences: Security (Master Password)

  • Another security option is the application of a Master Password.

  • If used, the Master Password must be entered in order for FireFox to remember the password for a given Web site.

  • When a Master Password is used, the user’s credentials from the key3.db file are used as part of the encryption algorithm.

Stored Web Site Authentication

  • By default, the Remember password option is enabled in FireFox.

  • The username and password information is stored in an encrypted format in the signons.txt or signons.sqlite file.

  • The algorithm used by FireFox to encrypt the data also uses user-specific data stored in a key3.db file.

  • AccessData’s PRTK can decrypt the information.

Formhistory.sqlite: Personal Data

  • Formhistory.sqlite stores auto-complete form data.

  • When a user visits a site that requires the entry of personal information, FireFox can automatically populate the necessary fields with user data.

  • When this feature is enabled, the formhistory.sqlite file is used.

Places.sqlite: Bookmarks/History

  • Browser history and bookmarks are stored within the places.sqlite file.

  • FTK parses the entries in an HTML file.

Cookies.sqlite

  • FireFox cookies are tracked in the cookies.sqlite file.

  • FTK parses the cookie information into an HTML file.

  • Each cookie record entry tracks:

    • Web site that generated the cookie.

    • Expiration date.

    • Proprietary data of the stored cookie.

Prefs.js: Browser Preferences

  • The FireFox preferences for the user are tracked in the prefs.js file.

  • The JavaScript file lists:

    • Default download directory for the user.

    • Home page for the FireFox browser.

    • Network/proxy setting if present.

  • If a user chooses to download a file to a directory other than the default directory:

    • user_pref(“browser.download.usedownloaddir”,false);

  • Privacy settings:

    • user_pref("privacy.clearOnShutdown.offlineApps", true);

    • user_pref("privacy.clearOnShutdown.passwords", true);

    • user_pref("privacy.clearOnShutdown.siteSettings", true);

    • user_pref("privacy.sanitize.sanitizeOnShutdown", true);

Downloads.sqlite

  • FireFox downloads are tracked in the Downloads.sqlite file.

  • Each downloaded file entry includes information on the source of the download and the local machine destination directory for the downloaded file.

FireFox Stored Content: Cache

  • The FireFox Cache folder is the equivalent of IE’s Temporary Internet Files directory.

  • The components of downloaded Web pages can be found here.

  • The FireFox Cache folder is located at:

    • Users\username\AppData\Local\Mozilla\FireFox\Profiles\randomID.profilename\Cache