Search found 2 matches

by crunchysuperman
Wed Sep 18, 2013 4:44 pm
Forum: NoScript Support
Topic: XSS on YouTube
Replies: 45
Views: 20215

Re: XSS on YouTube

The tricky thing here is that the site is actually passing entire JavaScript functions around inside URLs, which is exactly what triggers NoScript's anti-XSS filter by design. I wouldn't be surprised if making an exception for this specific Google API usage scenario would allow real XSS abuse. I've...
by crunchysuperman
Wed Sep 18, 2013 1:55 pm
Forum: NoScript Support
Topic: XSS on YouTube
Replies: 45
Views: 20215

Re: XSS on YouTube

I also registered to post here. Same thing, but it hosed YT functionality for me.