Firefox ๋ธŒ๋ผ์šฐ์ € ๋ถ€๊ฐ€ ๊ธฐ๋Šฅ
  • ํ™•์žฅ ๊ธฐ๋Šฅ
  • ํ…Œ๋งˆ
    • Firefox์šฉ
    • ์‚ฌ์ „ ๋ฐ ์–ธ์–ด ํŒฉ
    • ๋‹ค๋ฅธ ๋ธŒ๋ผ์šฐ์ € ์‚ฌ์ดํŠธ
    • Android ๋ถ€๊ฐ€ ๊ธฐ๋Šฅ
๋กœ๊ทธ์ธ
DotDrop - Secret Files Detector ๋ฏธ๋ฆฌ๋ณด๊ธฐ

DotDrop - Secret Files Detector ์ œ์ž‘์ž: Interzone

Detects exposed sensitive files like .git, .env, SSH keys, and configuration files. Features: traffic light alerts, scan progress, severity filtering, batch scanning, and export to JSON/CSV/Markdown

0 (๋ฆฌ๋ทฐ 0๊ฐœ)0 (๋ฆฌ๋ทฐ 0๊ฐœ)
์‚ฌ์šฉ์ž 2๋ช…์‚ฌ์šฉ์ž 2๋ช…
Firefox๋ฅผ ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  ํ™•์žฅ ๊ธฐ๋Šฅ์„ ๋ฐ›์œผ์„ธ์š”
ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ

ํ™•์žฅ ๋ฉ”ํƒ€ ๋ฐ์ดํ„ฐ

์Šคํฌ๋ฆฐ์ƒท
์ •๋ณด
DotDrop - Sensitive File Detector

Automatically scan websites for exposed sensitive files and security vulnerabilities. Perfect for security researchers, developers, and bug bounty hunters.

๐Ÿ” What It Detects

DotDrop scans for 80+ types of exposed files including:
  • Version Control: .git/, .svn/, .hg/
  • Credentials: .env, .htpasswd, SSH keys (id_rsa)
  • Cloud Keys: AWS, GCP, Azure credentials
  • Database Files: SQL dumps, MongoDB backups
  • Configuration: Docker, Kubernetes, CI/CD configs
  • Backups: ZIP, TAR, SQL backup files

โœจ Key Features
  • Traffic Light System: ๐ŸŸข Safe / ๐ŸŸ  Not Scanned / ๐Ÿ”ด Vulnerable
  • Real-time Scan Progress: See exactly what's being checked
  • One-Click Copy: Export findings as formatted Markdown reports
  • Detection Age Tracking: "2h ago", "3d ago" timestamps
  • Stealth Mode: Slower scanning to avoid rate limiting
  • Batch Scanning: Test multiple domains at once
  • Export Options: JSON, CSV, or Markdown formats
  • Statistics Dashboard: Track vulnerable sites and severity breakdown
  • 100% Local: Zero data collection, complete privacy

๐Ÿ”’ Privacy & Security

โœ… All processing happens locally on your device
โœ… No data sent to external servers
โœ… No analytics or tracking
โœ… Open source - inspect the code yourself
โœ… Minimal permissions (only what's needed)

๐ŸŽฏ Perfect For
  • Security researchers conducting vulnerability assessments
  • Developers checking their own sites for exposed files
  • Bug bounty hunters finding security issues
  • DevOps teams auditing infrastructure
  • Anyone concerned about web security

๐Ÿš€ How It Works
  1. Browse normally - DotDrop scans automatically
  2. Check the icon - Color indicates security status
  3. Click to view - See detailed findings
  4. Export results - Copy or download reports

๐Ÿ›ก๏ธ False Positive Prevention

Advanced 5-layer validation system ensures accurate detection:
- HTTP 200 status verification
- Content-Type checking
- File size validation
- HTML error page detection
- Content pattern analysis

๐Ÿ“Š Professional Features
  • Severity Levels: Critical, Medium, Low color-coded alerts
  • Pattern Groups: Enable/disable specific detection categories
  • Detection History: Track all findings over time
  • Customizable Settings: Auto-scan, critical-only mode
  • Badge Counter: Shows number of exposed files found

๐ŸŒ Use Cases

For Developers:
Test your own websites before deployment to catch exposed configuration files, credentials, or backup files that shouldn't be public.

For Security Researchers:
Quickly identify common security misconfigurations during reconnaissance. Export findings for professional reports.

For Bug Bounty Hunters:
Automate the detection of low-hanging fruit vulnerabilities. Copy findings directly to bug reports with one click.

โšก Lightweight & Fast
  • Minimal resource usage
  • Fast parallel scanning
  • Clean, professional UI
  • No bloat or unnecessary features

๐Ÿ”ง Technical Details
  • Manifest V3 compliant
  • Works on all HTTP/HTTPS sites
  • Respects browser security policies
  • Compatible with Firefox 109+

๐Ÿ“ Open Source

Fully open source on GitHub. Contributions welcome!



Disclaimer: This tool is for ethical security research and educational purposes only. Always obtain proper authorization before testing websites you don't own.
0๋ช…์ด 0์ ์œผ๋กœ ํ‰๊ฐ€ํ•จ
๋กœ๊ทธ์ธํ•˜์—ฌ ์ด ํ™•์žฅ ๊ธฐ๋Šฅ์˜ ํ‰์ ์„ ๋‚จ๊ฒจ์ฃผ์„ธ์š”
์•„์ง ํ‰์ ์ด ์—†์Šต๋‹ˆ๋‹ค

๋ณ„์  ์ €์žฅ๋จ

5
0
4
0
3
0
2
0
1
0
์•„์ง ๋ฆฌ๋ทฐ ์—†์Œ
๊ถŒํ•œ ๋ฐ ๋ฐ์ดํ„ฐ

ํ•„์ˆ˜ ๊ถŒํ•œ:

  • ๋ชจ๋“  ์›น์‚ฌ์ดํŠธ์—์„œ ์‚ฌ์šฉ์ž์˜ ๋ฐ์ดํ„ฐ์— ์ ‘๊ทผ

์„ ํƒ์  ๊ถŒํ•œ:

  • ๋ชจ๋“  ์›น์‚ฌ์ดํŠธ์—์„œ ์‚ฌ์šฉ์ž์˜ ๋ฐ์ดํ„ฐ์— ์ ‘๊ทผ
๋” ์•Œ์•„๋ณด๊ธฐ
์ถ”๊ฐ€ ์ •๋ณด
๋ถ€๊ฐ€ ๊ธฐ๋Šฅ ๋งํฌ
  • ์ง€์› ์ด๋ฉ”์ผ
๋ฒ„์ „
1.1.1
ํฌ๊ธฐ
32.56 KB
๋งˆ์ง€๋ง‰ ์—…๋ฐ์ดํŠธ
16์ผ ์ „ (2025๋…„ 11์›” 1์ผ)
๊ด€๋ จ ์นดํ…Œ๊ณ ๋ฆฌ
  • ๊ฐœ์ธ ์ •๋ณด ๋ณดํ˜ธ ๋ฐ ๋ณด์•ˆ
๋ผ์ด์„ ์Šค
MIT ๋ผ์ด์„ ์Šค
๋ฒ„์ „ ๋ชฉ๋ก
  • ๋ชจ๋“  ๋ฒ„์ „ ๋ณด๊ธฐ
๋ชจ์Œ์ง‘์— ์ถ”๊ฐ€
์ด ๋ถ€๊ฐ€ ๊ธฐ๋Šฅ ์‹ ๊ณ 
Mozilla ํ™ˆํŽ˜์ด์ง€๋กœ ์ด๋™

๋ถ€๊ฐ€ ๊ธฐ๋Šฅ

  • ์†Œ๊ฐœ
  • Firefox ๋ถ€๊ฐ€ ๊ธฐ๋Šฅ ๋ธ”๋กœ๊ทธ
  • ํ™•์žฅ ๊ธฐ๋Šฅ ์›Œํฌ์ƒต
  • ๊ฐœ๋ฐœ์ž ํ—ˆ๋ธŒ
  • ๊ฐœ๋ฐœ์ž ์ •์ฑ…
  • ์ปค๋ฎค๋‹ˆํ‹ฐ ๋ธ”๋กœ๊ทธ
  • ํฌ๋Ÿผ
  • ๋ฒ„๊ทธ ์‹ ๊ณ 
  • ๋ฆฌ๋ทฐ ์ง€์นจ

๋ธŒ๋ผ์šฐ์ €

  • Desktop
  • Mobile
  • Enterprise

์ œํ’ˆ

  • Browsers
  • VPN
  • Relay
  • Monitor
  • Pocket
  • Bluesky (@firefox.com)
  • Instagram (Firefox)
  • YouTube (firefoxchannel)
  • ๊ฐœ์ธ ์ •๋ณด
  • ์ฟ ํ‚ค
  • ๋ฒ•๋ฅ 

ํŠน๋ณ„ํ•œ ๊ณ ์ง€๊ฐ€ ์—†๋Š” ํ•œ, ๋ณธ ์‚ฌ์ดํŠธ์˜ ์ฝ˜ํ…์ธ ๋Š” Commons Attribution Share-Alike License v3.0 ๋˜๋Š” ๊ทธ ์ดํ›„ ๋ฒ„์ „์— ๋”ฐ๋ผ ์‚ฌ์šฉ์ด ํ—ˆ๊ฐ€๋ฉ๋‹ˆ๋‹ค.