NoScript causing hang on lloydstsb UK Bank?

Post a reply


In an effort to prevent automatic submissions, we require that you complete the following challenge.
Smilies
:D :) ;) :( :o :shock: :? 8-) :lol: :x :P :oops: :cry: :evil: :twisted: :roll: :!: :?: :idea: :arrow: :| :mrgreen: :geek: :ugeek:

BBCode is ON
[img] is ON
[flash] is OFF
[url] is ON
Smilies are ON

Topic review
   

Expand view Topic review: NoScript causing hang on lloydstsb UK Bank?

Re: NoScript causing hang on lloydstsb UK Bank?

by ricky » Thu Mar 08, 2018 10:32 am

Solution to Halifax problem, given by leamphil (2nd email in this thread) worked for me today. Thanks Phil!

Re: NoScript causing hang on lloydstsb UK Bank?

by didier » Fri Mar 18, 2016 11:28 pm

I confirm the problem with LCL and SG

my solution

I put the following lines in my .host to blacklist

0.0.0.0 tech.lcl.fr
0.0.0.0 img-fdb.lcl.fr
0.0.0.0 docsp.par.societegenerale.fr
0.0.0.0 statsp.par.societegenerale.fr

it seems ok

Re: NoScript causing hang on lloydstsb UK Bank?

by Thrawn » Tue Mar 01, 2016 10:08 pm

NS001 wrote:I will just have to disable NoScript when online banking.

It's usually better to create a second profile for online banking. If you know what you're doing, it's even possible to run two profiles in two separate instances of Firefox at the same time.

Re: NoScript causing hang on lloydstsb UK Bank?

by NS001 » Tue Mar 01, 2016 5:18 pm

Exactly same problem as reported for https://www.bancsabadell.com/

viewtopic.php?f=7&t=21629

Did look at this topic before posting under general.

There are no about:crashes reports. It hangs and have to forcibly shut down FF.

I will just have to disable NoScript when online banking.

Re: NoScript causing hang on lloydstsb UK Bank?

by barbaz » Fri Feb 26, 2016 6:29 pm

Nothing to address in NoScript. Instructions what to do about your specific site have already been given in this thread: viewtopic.php?p=80079#p80079

Re: NoScript causing hang on lloydstsb UK Bank?

by MJV » Fri Feb 26, 2016 8:29 am

The issue is still unresolved for the site of French bank Societe generale : https://particuliers.societegenerale.fr/

The main domain (societegenerale.fr) is on my whitelist and I even tried with NS in "Scripts Globally Allowed" mode, but there's nothing to do, accessing the page still completely blocks Firefox.

Could this be addressed in the next update please...? I really hate using IE every time I have to check my account...

Re: NoScript causing hang on lloydstsb UK Bank?

by Guest » Tue Dec 08, 2015 2:52 pm

bgiles wrote:Does the following not work for other Lloyds Bank customers using NoScript?

Allow: secure.lloydsbank.co.uk (i.e. added to whitelist)
Remove all other entries containing lloydsbank.co.uk from whitelist.

I've been using this arrangement for a few days now, loads normally, and without any apparent side effects.


Hi bgiles, thanks a lot for this solution, I can confirm that it works fine for me :)

Re: NoScript causing hang on lloydstsb UK Bank?

by Thrawn » Sun Dec 06, 2015 10:01 pm

NoScript can't fix the bank's problem; the best you can do is isolate the bank website so it's harder for other sites to tamper with it. That's where a separate profile may be helpful. Alternatively, you could try writing ABE rules to deny cross-site access.

Re: NoScript causing hang on lloydstsb UK Bank?

by Gloops » Thu Dec 03, 2015 9:11 pm

barbaz wrote:???
What does this have to do with the NoScript team? You mean the bank's IT/webmaster team?


For sure that would be best :)

Re: NoScript causing hang on lloydstsb UK Bank?

by barbaz » Mon Nov 30, 2015 7:31 pm

???
What does this have to do with the NoScript team? You mean the bank's IT/webmaster team?

Re: NoScript causing hang on lloydstsb UK Bank?

by Gloops » Mon Nov 30, 2015 7:26 pm

Oh ... I am afraid the only thing I can do is to wait for the NoScript team to find a more secure protocol ...

Re: NoScript causing hang on lloydstsb UK Bank?

by barbaz » Mon Nov 30, 2015 6:08 pm

The problem is that they are using a highly insecure means to pass data around (any site can read it and tamper with it), and that data looks like it could potentially be XSS, meaning that attackers may potentially be able to sabotage that data such that they get to run arbitrary attack script in the context of your bank site and do all sorts of nasty stuff. Not good.

Re: NoScript causing hang on lloydstsb UK Bank?

by Gloops » Mon Nov 30, 2015 3:37 pm

barbaz wrote:
Gloops wrote:I saw a white list in the options of NoScript, but no black list.

It's not available via the NoScript Options. You either need to Mark it as Untrusted in the GUI (make sure you have 'NoScript Options > Appearance > Full Domains' checked) while visiting the site, or edit about:config > noscript.untrusted and insert that domain in alphabetical order.


OK I checked full domains, and so discovered that we also have a call to much more other domains than I first thought (including weborama, google ...)

par.societegenerale.fr has two sub-domains that are also called. I marked par.societegenerale.fr as untrusted, I hope I shall not have any complain that the user could not connect :)

Do you have any idea what par.societegenerale.fr does, and why it is so dangerous as you say ?

Re: NoScript causing hang on lloydstsb UK Bank?

by barbaz » Sun Nov 29, 2015 3:42 pm

Gloops wrote:I saw a white list in the options of NoScript, but no black list.

It's not available via the NoScript Options. You either need to Mark it as Untrusted in the GUI (make sure you have 'NoScript Options > Appearance > Full Domains' checked) while visiting the site, or edit about:config > noscript.untrusted and insert that domain in alphabetical order.

Re: NoScript causing hang on lloydstsb UK Bank?

by Gloops » Sun Nov 29, 2015 3:28 pm

therube wrote:
I authorized par.societegenerale.fr, and it freezed

Well you'd want to do the opposite.
You'd want to Forbid par.societegenerale.fr.


I saw a white list in the options of NoScript, but no black list.
Do you propose something in the hosts file ?

Top