data: URI & NoScript Icon Indicator

Ask for help about NoScript, no registration needed to post
User avatar
therube
Ambassador
Posts: 7972
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

data: URI & NoScript Icon Indicator

Post by therube »

data: URI & NoScript Icon Indicator

"URL:" http://pastebin.com/pdkzuPjJ

NoScript shows the top level domain to be wikimedia.com
Allow wikimedia.com

NoScript icon unchanged, still shows all to be blocked

Allow http://http

NoScript icon now shows nothing blocked
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:17.0) Gecko/17.0 Firefox/17.0 SeaMonkey/2.14a2
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: data: URI & NoScript Icon Indicator

Post by Thrawn »

Yeah, I can confirm the behaviour (after overriding the warning), but I'd say it's probably not worth fixing. Data uris aren't normal...
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (Linux; U; Android 2.2.1; en-gb; GT-S5570 Build/FROYO) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1
User avatar
therube
Ambassador
Posts: 7972
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: data: URI & NoScript Icon Indicator

Post by therube »

Data uris aren't normal
Precisely the reason why it is even more important.
Plus, not normal for who, you or I perhaps, but for a browser it is as normal as html.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:17.0) Gecko/17.0 Firefox/17.0 SeaMonkey/2.14a2
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: data: URI & NoScript Icon Indicator

Post by Thrawn »

It's just cosmetic, though, isn't it? NoScript being a bit confused about what constitutes the top-level document? And NoScript blocks you from entering a data URI unless you edit about:config.

Is there an actual security hole here? If so, please elaborate.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:15.0) Gecko/20100101 Firefox/15.0
User avatar
therube
Ambassador
Posts: 7972
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: data: URI & NoScript Icon Indicator

Post by therube »

> It's just cosmetic

Not at all.

> NoScript blocks you from entering a data URI

True (with exceptions).
But the data: URI need not be necessarily be "added" by you, it could be in a link you clicked.

And just what site are we looking at here?
Take a look. It is not wikipedia.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:17.0) Gecko/17.0 Firefox/17.0 SeaMonkey/2.14a2
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: data: URI & NoScript Icon Indicator

Post by Thrawn »

therube wrote: And just what site are we looking at here?
Take a look. It is not wikipedia.
No, but it tries to import a script from bits.wikimedia.org, which is why NoScript blocks & reports that. The inline scripts (of which there are several) are presumably represented by the

Code: Select all

http://http
entry. So, that looks a bit funky, and even when you allow one or the other of the two script sources, the icon still reports that the top-level document is blocked, but NoScript is still apparently detecting and blocking everything.

Btw, I had spam filter trouble when posting this, even when I disabled automatic URL parsing and wrapped URLs in code tags, so I removed most of them. Not sure whether the angle brackets also contributed?
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:15.0) Gecko/20100101 Firefox/15.0
Post Reply