Wacky XSS Script HELP SOS!

Post a reply

Smilies
:D :) ;) :( :o :shock: :? 8-) :lol: :x :P :oops: :cry: :evil: :twisted: :roll: :!: :?: :idea: :arrow: :| :mrgreen: :geek: :ugeek:

BBCode is ON
[img] is ON
[url] is ON
Smilies are ON

Topic review
   

Expand view Topic review: Wacky XSS Script HELP SOS!

Re: Wacky XSS Script HELP SOS!

by SlowSKier505 » Wed Dec 06, 2017 4:44 pm

This happens to me too. I'm using 10.1.5.5. It's almost always a Facebook request from a news site (The NYT, Washington Post, etc.). No matter what I select, Allow, Block, Always Allow, or Always Block (Always Block is what I want), it continues to periodically repeat the warning.

Here's an example:

https://i.imgur.com/bw6CRT7.jpg

Re: Wacky XSS Script HELP SOS!

by SyberCorp » Tue Dec 05, 2017 6:39 pm

barbaz wrote:Your duplicate cross-post in https://forums.informaction.com/viewtop ... =7&t=24067 has been deleted. Consider this a warning per Forum Rules #8.
Sad Big Daddy wrote:I get this warning and another similar one, with a different website. It continuously pops up, no matter what I do. The two pop ups have occurred about 100 times between them.

Please save us and may God have mercy on our souls.
Which NoScript version are you using?
What site are you on when you see the warning you posted? Or do you have the New Tab page (or similar) open?
It happens to me, too. It has happened from 10.1.3 to 10.1.5.5, that I've noticed. Every time I visit IMDB (http://www.imdb.com), for example, I get multiple popup windows about XSS attacks between IMDB and facebook.com, followed by IMDB to amazon-adsystem.com or something like that. Sometimes they're between IMDB and other parts of IMDB for image hosting. I hit "Always allow" on the first one, and "Always block" on the second one (or any about ads), but they come back upon every visit, like NoScript isn't properly saving user responses about XSS.

These are the 2 warnings that I get just from visiting imdb.com (without even getting as far as searching for anything).

https://imgur.com/a/PcLPD

https://imgur.com/a/8GfIx

It doesn't matter if I always allow the request, I will get them again once I close my browser and I go to the site.

Re: Wacky XSS Script HELP SOS!

by barbaz » Tue Dec 05, 2017 3:48 pm

Your duplicate cross-post in https://forums.informaction.com/viewtop ... =7&t=24067 has been deleted. Consider this a warning per Forum Rules #8.
Sad Big Daddy wrote:I get this warning and another similar one, with a different website. It continuously pops up, no matter what I do. The two pop ups have occurred about 100 times between them.

Please save us and may God have mercy on our souls.
Which NoScript version are you using?
What site are you on when you see the warning you posted? Or do you have the New Tab page (or similar) open?

Wacky XSS Script HELP SOS!

by Sad Big Daddy » Tue Dec 05, 2017 2:48 pm

NoScript XSS Warning

NoScript detected a potential Cross-Site Scripting attack

from [...] to https://fthmb.tqn.com.

Suspicious data:

(URL) https://fthmb.tqn.com/Q-GOXtgRsPkQrcfH9YIs_iZ3eYc=/1001x1001/filters:fill(auto,1)/lifewire_pin_default-5...

Block this request
Always block document requests from [...] to https://fthmb.tqn.com
Allow this request
Always allow document requests from [...] to https://fthmb.tqn.com

I get this warning and another similar one, with a different website. It continuously pops up, no matter what I do. The two pop ups have occurred about 100 times between them.

Please save us and may God have mercy on our souls.

Top