SecOceans logoSecOceans
Back to Blog

February 27, 2021

Extract Information from Firefox Browser

By Mr Singh

Digital ForensicsBrowser ForensicsTool Tutorial
Extract Information from Firefox Browser

Hello Everyone! Dumpzilla is a forensic tool written in Python 3 used to extract interesting information from the browser — a browser forensic tool. It is a command line tool available for Kali Linux, Windows, and Mac (32/64-bit) systems. With this tool you can extract information from three browsers: Firefox, Iceweasel, and Seamonkey. The information dumps can be redirected via pipes to tools such as grep, awk, cut, sed etc.

You can extract a lot of information including history, bookmarks, downloads, passwords, add-ons, cookies, and more. After extraction you can export the data as JSON or plain text.

You can extract: Downloads, History, Bookmarks; Cookies, session data, browser saved data; Add-ons, user preferences; Web forms (searches, emails, comments); URLs open in each tab; and other web form data.

Installation: install Dumpzilla via command line (sudo apt-get install dumpzilla) or download it manually. After downloading, give it permission with sudo chmod +x dumpzilla.py.

Run it with sudo python dumpzilla.py. There are many options to extract information — use --All to extract everything, or specific options like --history to extract only history.

You need to give it a Firefox profile path to extract data. On Kali Linux, the Firefox browser path is typically /home/$USER/.mozilla/firefox/xxxx.default.

The command would be: sudo python dumpzilla.py /home/$user/.mozilla/firefox/xxx.default/ --All — this retrieves all available information. You can also export to a JSON file with the --Export argument, or extract specific data like bookmarks with --Bookmarks.

To export as plain text: sudo python dumpzilla.py /home/$user/.mozilla/firefox/xxx.default/ --All | tee /root/Desktop/mozilla

Thank you for Reading.