X
Tap here to go to the mobile version of the site.

Support Forum

Can I use seprate firefox profiles to protect against CSRF, XSS and DNS Re-binding?

Posted

I read here (http://security.stackexchange.com/questions/106333/is-binding-all-private-services-to-the-127-0-0-1-address-and-then-accessing-them/106340?noredirect=1#comment187952_106340) that I should use separate security profiles for different sorts of things; accessing sensitive information, doing system administration vs. opening links from emails.

I know that different instances of Firefox can be run from specifying different profiles to start up the browser with. As long as these are limited to accessing a certain type of site; can they provide protection against CSRF, XSS, and DNS Re-binding?

Also, can these profiles be limited to visiting only certain sites? Can they also exclude certain sites to prevent for instance sites in private profiles (your bank, system administration) from being visited using a public profile (links in an email)?

I read here (http://security.stackexchange.com/questions/106333/is-binding-all-private-services-to-the-127-0-0-1-address-and-then-accessing-them/106340?noredirect=1#comment187952_106340) that I should use separate security profiles for different sorts of things; accessing sensitive information, doing system administration vs. opening links from emails. I know that different instances of Firefox can be run from specifying different profiles to start up the browser with. As long as these are limited to accessing a certain type of site; can they provide protection against CSRF, XSS, and DNS Re-binding? Also, can these profiles be limited to visiting only certain sites? Can they also exclude certain sites to prevent for instance sites in private profiles (your bank, system administration) from being visited using a public profile (links in an email)?

Additional System Details

Installed Plug-ins

  • DivX Web Player version 1.4.0.233
  • The Videos 3.10.1 plugin handles video and audio streams.
  • This plug-in detects the presence of iTunes when opening iTunes Store URLs in a web page with Firefox.

Application

  • User Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:42.0) Gecko/20100101 Firefox/42.0

More Information

Question owner

P.S. I use Linux and Windows.

P.S. I use Linux and Windows.
FredMcD
  • Top 10 Contributor
4267 solutions 59839 answers

https://support.mozilla.org/en-US/kb/profile-manager-create-and-remove-firefox-profiles

You can have as many profiles as you want. When you create new profiles, give them a name that shows that each is for.

I have this shortcut on my Windows desk top; "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -p

Yours may be different. Note the quotes and that the -p is on the outside.

'''https://support.mozilla.org/en-US/kb/profile-manager-create-and-remove-firefox-profiles''' You can have as many profiles as you want. When you create new profiles, give them a name that shows that each is for. I have this shortcut on my Windows desk top; "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -p Yours may be different. Note the quotes and that the '''-p''' is on the outside.
cor-el
  • Top 10 Contributor
  • Moderator
17569 solutions 158910 answers
See also: *https://developer.mozilla.org/Mozilla/Multiple_Firefox_Profiles