~kris/dots

srice

srice/profiles/pentest/.config/qutebrowser/config.py -rw-r--r-- 6.3 KiB
e98f3b03 — Kris Yotam chore: sync local state after restore (push updates, no pull) a month ago
                                                                                
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
# ============================================================================
# qutebrowser Hardened config.py -- Pentesting + Privacy Profile
# Place in: ~/.config/qutebrowser/config.py
# ============================================================================

config.load_autoconfig(False)  # ignore autoconfig, this file is authoritative

# === CONTENT BLOCKING ===
c.content.blocking.method = "both"                    # use both adblock methods
c.content.blocking.adblock.lists = [                  # comprehensive blocklists
    "https://easylist.to/easylist/easylist.txt",
    "https://easylist.to/easylist/easyprivacy.txt",
    "https://easylist.to/easylist/fanboy-social.txt",
    "https://secure.fanboy.co.nz/fanboy-annoyance.txt",
    "https://easylist-downloads.adblockplus.org/abp-filters-anti-cv.txt",
    "https://pgl.yoyo.org/adservers/serverlist.php?hostformat=hosts&showintro=1&mimetype=plaintext",
    "https://raw.githubusercontent.com/uBlockOrigin/uAssets/master/filters/filters.txt",
    "https://raw.githubusercontent.com/uBlockOrigin/uAssets/master/filters/badware.txt",
    "https://raw.githubusercontent.com/uBlockOrigin/uAssets/master/filters/privacy.txt",
    "https://raw.githubusercontent.com/uBlockOrigin/uAssets/master/filters/resource-abuse.txt",
]
c.content.blocking.hosts.lists = [                    # hosts-based blocking
    "https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts",
]

# === JAVASCRIPT ===
c.content.javascript.enabled = False                  # JS off by default (whitelist per-domain)
# whitelist JS for specific domains:
# config.set("content.javascript.enabled", True, "*://github.com/*")
# config.set("content.javascript.enabled", True, "*://app.hackthebox.com/*")
# config.set("content.javascript.enabled", True, "*://tryhackme.com/*")

# === COOKIES ===
c.content.cookies.accept = "no-3rdparty"              # block third-party cookies
c.content.cookies.store = False                       # session-only cookies

# === WEBRTC (IP leak prevention) ===
c.content.webrtc_ip_handling_policy = "disable-non-proxied-udp"  # prevent IP leaks
c.content.webgl = False                               # disable WebGL fingerprinting

# === CANVAS / FINGERPRINTING ===
c.content.canvas_reading = False                      # block canvas fingerprinting
c.content.reading_order = False                       # no reading order detection

# === HEADERS / REFERRER ===
c.content.headers.referer = "same-domain"             # only same-domain referrers
c.content.headers.do_not_track = True                 # send DNT header
c.content.headers.custom = {                          # custom headers
    "https://*": {
        "Accept-Language": "en-US,en;q=0.5",          # generic accept-language
    }
}
c.content.headers.user_agent = "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"  # spoof as Firefox

# === DNS ===
c.content.dns_prefetch = False                        # no DNS prefetching

# === NOTIFICATIONS / PERMISSIONS ===
c.content.notifications.enabled = False               # block all notifications
c.content.geolocation = False                         # block geolocation
c.content.media.audio_capture = False                 # block microphone
c.content.media.video_capture = False                 # block camera
c.content.media.audio_video_capture = False           # block both
c.content.autoplay = False                            # no autoplay

# === PLUGINS / FEATURES ===
c.content.plugins = False                             # no plugins
c.content.pdfjs = False                               # no built-in PDF viewer

# === DOWNLOADS ===
c.downloads.location.prompt = True                    # always ask download location
c.downloads.location.directory = "~/downloads"        # download directory
c.downloads.remove_finished = 5000                    # remove from list after 5s

# === NETWORK / PROXY ===
# Uncomment for Burp Suite proxy:
# c.content.proxy = "http://127.0.0.1:8080"
# Uncomment for Tor SOCKS5:
# c.content.proxy = "socks5://127.0.0.1:9050"
c.content.proxy = "system"                            # use system proxy by default

# === TLS / SSL ===
c.content.tls.certificate_errors = "ask-block-thirdparty"  # ask on cert errors, block 3rd party

# === CACHE / STORAGE ===
c.content.cache.size = 52428800                       # 50MB cache max
c.content.local_storage = False                       # disable localStorage by default

# === COMPLETION / HISTORY ===
c.completion.web_history.max_items = 0                # no web history in completion
c.completion.cmd_history_max_items = 100              # keep command history
c.history_gap_interval = -1                           # no history gap detection

# === URL / SEARCH ===
c.url.start_pages = ["about:blank"]                   # blank start page
c.url.default_page = "about:blank"                    # blank default page
c.url.searchengines = {                               # search engines
    "DEFAULT": "https://searxng.site/search?q={}",   # SearXNG privacy search
    "g": "https://www.google.com/search?q={}",
    "ddg": "https://duckduckgo.com/?q={}",
    "gh": "https://github.com/search?q={}",
    "htb": "https://app.hackthebox.com/search?q={}",
    "cve": "https://nvd.nist.gov/vuln/search/results?query={}&search_type=all",
    "exploit": "https://www.exploit-db.com/search?q={}",
    "gtfo": "https://gtfobins.github.io/#{}",
    "shodan": "https://www.shodan.io/search?query={}",
}

# === KEYBINDINGS (pentesting shortcuts) ===
config.bind(",p", "set content.proxy http://127.0.0.1:8080")   # toggle Burp proxy
config.bind(",P", "set content.proxy system")                   # back to system proxy
config.bind(",t", "set content.proxy socks5://127.0.0.1:9050") # toggle Tor
config.bind(",j", "set content.javascript.enabled true")        # enable JS for current tab
config.bind(",J", "set content.javascript.enabled false")       # disable JS
config.bind(",c", "set content.cookies.store true")             # enable persistent cookies
config.bind(",C", "set content.cookies.store false")            # session-only cookies
config.bind(",u", "spawn --userscript view-source")             # view source
config.bind(",h", "devtools")                                    # toggle devtools

# === COLORS (dark theme) ===
c.colors.webpage.preferred_color_scheme = "dark"      # prefer dark mode
c.colors.webpage.darkmode.enabled = True              # force dark mode