"Signed out*" of yahoo &...
Code: Select all
[NoScript InjectionChecker] JavaScript Injection in ///_ylt=At_ic0tRpmwzS4OCfWdAV.../SIG=14s5ts.../EXP=1347478466/**http%3A//login.yahoo.com/config/login%3Flogout=1%26.direct=2%26.done=http%3A//www.yahoo.com%26amp;.src=ym%26amp;.intl=us%26amp;.lang=en-US
(function anonymous() {
EXP=1347478.../**http`//login.yahoo.com/config/login`=1%26.direct=2%26.done=http`//www.yahoo.com`;.src=ym` /* COMMENT_TERMINATOR */
DUMMY_EXPR
})
Code: Select all
[NoScript XSS] Sanitized suspicious request. Original URL [http://us.lrd.yahoo.com/_ylt=At_ic0tRpmwzS4OCfWdAV.../SIG=14s5ts.../EXP=1347478.../**http%3A//login.yahoo.com/config/login%3Flogout=1%26.direct=2%26.done=http%3A//www.yahoo.com%26amp;.src=ym%26amp;.intl=us%26amp;.lang=en-US] requested from [http://us.mc1614.mail.yahoo.com/mc/welcome?.gx=1&.tm=1346268...&.rand=43in9dbqu2...]. Sanitized URL: [http://us.lrd.yahoo.com/_ylt%20At_ic0tRpmwzS4OCfWdAV......./SIG%2014s5tsn5r/EXP%201347478.../**http://login.yahoo.com/config/login%3Flogout%201&.direct%202&.done%20http://www.yahoo.com&.src%20ym&.intl%20us&.lang%20en-US#793610026257...].
(I did nothing with the XSS prompt warning.)
It does go to a "login" page, https://login.yahoo.com/config/login_verify2?logout%201&.direct%202&.done%20http://www.yahoo.com&.src%20ym&.intl%20us&.lang%20en-US#786451552263..., but in fact you are not logged out at that point.
On this screen, there is again a "Sign out" link, & if you then click that, there is no XSS warning, & you are in fact logged out at that point: