The Chrome browser has the possibility to add plugins, but when it comes to security auditing plugins the main browser you think of is Firefox. In this post Cyberwarzone will provide you multiple tools that you can use for auditing environments with Google Chrome.
The tools are all pretty fast forward and they do their job quite well.
Web developer
The Web Developer extension adds a toolbar button to the browser with various web developer tools. This is the official port of the Web Developer extension for Firefox.
User Agent add-on
Spoofs & Mimics User-Agent strings. Ever needed to quickly switch between user-agent strings on the fly? Developing a site that needs to work on both mobile browsers and desktop browsers? Sick of some archaic site blocking you because you’re not using Netscape 4? The User-Agent Switcher for Chrome is the answer. With this extension, you can quickly and easily switch between user-agent strings. Also, you can set up specific URLs that you want to spoof every time. This version is new and improved, and not only modifies the user-agent sent with the HTTP requests, but also the Javascript objects in the page. NOTE: if Google sites / YouTube have problems after using a mobile user-agent, you may need to switch the user-agent back to Chrome *and* clear your cookies for the sites to treat the browser normally again.
Modify Headers
Add and modify the HTTP request headers sent to web servers. Requires: Chrome 17 or above.
** Permissions ** ModHeader currently requires 4 permissions: 1, “webRequest” 2, “webRequestBlocking” 3, “<all_urls>” 4, “tabs” (new in 1.2.4)
The first 2 are required in order for request headers modification to work. Because ModHeader doesn’t know ahead of time which website the modification should apply to, it needs to request permissions for all URLs (3).
The last one is used to update the ModHeader icon when the filters are active/inactive. ** Basic usage ** – Add the name/value request header pairs to the popup. – Click on “Add Header” if you need to modify more request header. – To remove a request header, add the header name, but leave the value empty. – To disable a request header modification, uncheck the checkbox on the left. – To delete a request header modification, click on the “X” on the right.
** Profiles ** – Only the request headers in the active profile is modified. – You can use up to 4 profiles.
** Filters ** – Filters can be used to limit when a profile is active. – Filters are evaluated in sequential order. e.g., if you have the following filters: *google.com* ALLOW *mail.google.com* BLOCK Then your profile will be active on all google.com domain except mail.google.com –
When a profile is inactive due to filters, the icon will be gray out.
Custom Posts and Gets
An extension for editing custom request(GET or POST) to web server.
An extension for editing custom request(GET or POST) to web server.
1. Auto extract forms from the web page.
2. You can modify the form method.
3. You can modify the form action.
4. You can add or remove the <name, value> pair.
5. You can edit the <name, value> pair
Ghostery
DETECT: Ghostery sees the “invisible” web, detecting trackers, web bugs, pixels, and beacons placed on web pages by Facebook, Google Analytics, and over 500 other ad networks, behavioral data providers, web publishers – all companies interested in your activity. LEARN: After showing you who operates behind the scenes, Ghostery also gives you the opportunity to learn more about each company it identifies, including links to their privacy policy and opt-out options.
CONTROL: Ghostery allows you to block scripts, images, iframes and objects/embeds from companies that you don’t trust.
COLLABORATE: Ghostery also includes the optional, opt-in feature called GhostRank, which sends Ghostery servers anonymous information about the trackers you encounter and where you encounter them. This helps us improve and support Ghostery. More information in our FAQ.
PROTECT YOUR PRIVACY: Ghostery is built and maintained for users that care about their online privacy, and is engineered with privacy as a primary goal. Ghostery use is anonymous. No registrations or sign-ups are required.
The Ghostery plug-in does not place session cookies into your browser. Neither the Ghostery application nor Evidon receives any data from Ghostery users unless the user opts-in to participate in GhostRank.
GhostRank data is anonymous, it is NEVER used for advertising targeting purposes, and is only shared in an aggregated, non-personal, statistical form.
Download links:
Webdeveloper:https://chrome.google.com/webstore/detail/bfbameneiokkgbdmiekhjnmfkcnldhhm/
User-Agent:
https://chrome.google.com/webstore/detail/djflhoibgkdhkhhcedjiklpkjnoahfmg/
Modify-headers:
https://chrome.google.com/webstore/detail/idgpnmonknjnojddfkpgkljpfnnfcklj/
Custom Posts and Gets:
https://chrome.google.com/webstore/detail/klaecimjlbpfompicealiiifcdjnkbpn/
Cookie editor:
https://chrome.google.com/webstore/detail/fngmhnnpilhplaeedifhccceomclgfbg/
Ghostery:
https://chrome.google.com/webstore/detail/ghostery/mlomiejdfkolichcflejc…