Search found 41 matches

by pal1000
Wed Jun 17, 2020 9:28 pm
Forum: NoScript Development
Topic: GET request over file protocol glitch
Replies: 0
Views: 198

GET request over file protocol glitch

Create a HTML document and open it over file protocol with a random GET request payload, per testcase itself: <html> <head> <title>NoScript - GET request over file protocol glitch</title> </head> <body> <script> document.write('Open this page with a random GET request and this active content won&apo...
by pal1000
Fri Jun 14, 2019 7:49 pm
Forum: NoScript Support
Topic: [Answered] What happened with NoScript json options xssBlockUnscannedPOST and xssScanRequestBody
Replies: 3
Views: 499

Re: Asking about NoScript json options xssBlockUnscannedPOST and xssScanRequestBody

Thanks both for answering. It looks like my guess was right. I marked this question topic as answered.
by pal1000
Fri Jun 14, 2019 10:54 am
Forum: NoScript Support
Topic: [Answered] What happened with NoScript json options xssBlockUnscannedPOST and xssScanRequestBody
Replies: 3
Views: 499

[Answered] What happened with NoScript json options xssBlockUnscannedPOST and xssScanRequestBody

I have a relatively old noscript_data.txt from 10.6.2 release candidates period backed up with these 2 options: xssScanRequestBody is true and xssBlockUnscannedPOST is false. I also noticed that a fresh copy of Noscript 10.6.3rc7 doesn't create these options in its configuration json anymore and the...
by pal1000
Fri May 24, 2019 7:01 am
Forum: NoScript Support
Topic: [Resolved] Just a false positive please ignore
Replies: 2
Views: 473

Re: Some sites require some permissions in default preset to work even if same permissions are granted by trusted preset

Well, this is embarrassing. I got the impression that allowing www.googleapis.com didn't help but I was wrong.
by pal1000
Thu May 23, 2019 11:04 am
Forum: NoScript Support
Topic: [Resolved] Just a false positive please ignore
Replies: 2
Views: 473

[Resolved] Just a false positive please ignore

I personally believe this is a bug. It only affects Firefox. Some examples to reproduce with: - https://storage.googleapis.com/chromium-browser-snapshots/index.html - https://commondatastorage.googleapis.com/chromium-browser-snapshots/index.html For any of these 2 pages if default preset doesn't hav...
by pal1000
Sun Jul 29, 2018 9:14 am
Forum: NoScript Development
Topic: [FIXED]Cannot act on unprivileged content in privileged page
Replies: 1
Views: 3027

[FIXED]Cannot act on unprivileged content in privileged page

It is possible for privileged pages to load unprivileged content. Most obvious example that comes to mind is a web page served over file protocol. It can contain anything so it can load unprivileged content. Noscript should be able to act on unprivileged content and notify the user that there is pri...
by pal1000
Fri Apr 27, 2018 3:22 pm
Forum: NoScript Development
Topic: [Fixed] 10.1.8.1RC3 - Missing frames popup content
Replies: 2
Views: 1337

Re: [Fixed] 10.1.8.1RC3 - Missing frames popup content

Thanks for the quick fix. It appears I was beaten to it when reporting this, but it's unsurprising considering this was a pretty nasty one as it breaks most HTML5 videos and audio.
by pal1000
Fri Apr 27, 2018 2:21 pm
Forum: NoScript Development
Topic: [Fixed] 10.1.8.1RC3 - Missing frames popup content
Replies: 2
Views: 1337

[Fixed] 10.1.8.1RC3 - Missing frames popup content

The popup list no longer shows domains accessed from frames. This is a regression in 10,1.8.1rc3. I was able to easily reproduce this here: https://www.helpnetsecurity.com/2018/04/27/fortanix-runtime-encryption/ There is a soundcloud player in an iframe there but you won't be able to activate it usi...
by pal1000
Sat Apr 14, 2018 8:43 am
Forum: NoScript Support
Topic: [RESOLVED] NoScript Update feed
Replies: 20
Views: 6299

Re: NoScript Update feed

This is the one I was looking at https://noscript.net/feed?all You linked it somewhere on 1st page, maybe it was a mistake or you made changes to feeds location and the post became out-of-date. Here is the post I am talking about: https://forums.informaction.com/viewtopic.php?f=7&t=24136#p96028 Anyw...
by pal1000
Fri Apr 13, 2018 8:46 am
Forum: NoScript Support
Topic: [RESOLVED] NoScript Update feed
Replies: 20
Views: 6299

Re: NoScript Update feed

The all releases feed is broken. It shows the same content as stable feed.
by pal1000
Thu Apr 05, 2018 1:21 pm
Forum: NoScript Development
Topic: NS10: TRUSTED<->TEMP TRUSTED no reload needed
Replies: 5
Views: 2419

NS10: TRUSTED<->TEMP TRUSTED no reload needed

There is no need to reload the webpage when permission change from trusted to temp trusted or other way around.
by pal1000
Thu Apr 05, 2018 1:15 pm
Forum: NoScript Development
Topic: NS10 - Add a filter to popup site list
Replies: 0
Views: 1345

NS10 - Add a filter to popup site list

10.1.8.1rc2 has 3 buttons on left edge and 4 on right edge of the popup site list and enough room in the middle to add a filter just like one from the Options page. It would really help with large websites to sweep though more quickly especially for known websites or websites that embed content from...
by pal1000
Tue Mar 20, 2018 11:29 am
Forum: NoScript Development
Topic: [FIXED] NoScript 10.1.7.3 causes Firefox 59.0.1 to freeze
Replies: 10
Views: 2830

Re: NoScript 10.1.7.3 causes Firefox 59.0.1 to freeze

I was looking into this as well. This issue can be reproduced with default settings. Version 10.1.7.4rc1 is affected. This can be reproduced on Windows as well. - Visit https://www.huffingtonpost.com.au/2017/01/03/centrelink-phone-lines-jammed-people-forced-to-call-hundreds-of_a_21646943/ - Trust hu...