Search found 49 matches

by johnscript
Tue Dec 13, 2016 11:38 am
Forum: Security
Topic: Firefox 0day in the wild is being used to attack Tor users
Replies: 13
Views: 6552

Re: Firefox 0day in the wild is being used to attack Tor use

Thanks, Giorgio - I was looking in the wrong place. It states it consists of one HTML and one CSS file I'll admit my ignorance here: these files weren't just floating around somewhere on the internet, for them to work they had to be maybe injected in some websites, either on the fly by MTM or tamper...
by johnscript
Tue Dec 06, 2016 11:45 am
Forum: NoScript Development
Topic: ABE seems to be broken since the latest release [2.9.5.1]
Replies: 25
Views: 12653

Re: ABE seems to be broken since the latest release [2.9.5.1

Adding Accept from chrome: right after the domain, as you suggested, does work. Still, the only error message that I can see without that line is the one I've posted above, there's nothing like that long message you've posted - maybe there's also some interaction with uBlock or some other addon at p...
by johnscript
Tue Dec 06, 2016 11:33 am
Forum: Security
Topic: Firefox 0day in the wild is being used to attack Tor users
Replies: 13
Views: 6552

Re: Firefox 0day in the wild is being used to attack Tor use

(..) Word of the previously unknown Firefox vulnerability first surfaced in this post on the official Tor website . It included several hundred lines of JavaScript and an introduction that warned: "This is an [sic] JavaScript exploit actively used against TorBrowser NOW." Tor cofounder Ro...
by johnscript
Mon Dec 05, 2016 9:10 pm
Forum: Web Tech
Topic: The Future of Developing Firefox Add-ons
Replies: 32
Views: 21010

Re: The Future of Developing Firefox Add-ons

I can't say for sure, but I'm afraid that in their view some legitimate extensions (=never so far involved in compromises/attacks) do cross this ideal line and should therefore be axed just to avoid any potential issue in the future. They seem to have been grown kinda intolerant of what some extensi...
by johnscript
Mon Dec 05, 2016 8:57 pm
Forum: NoScript Development
Topic: ABE seems to be broken since the latest release [2.9.5.1]
Replies: 25
Views: 12653

Re: ABE seems to be broken since the latest release [2.9.5.1

This is the error message in the console NS_ERROR_NOT_AVAILABLE: Component returned failure code: 0xxxxxx (NS_ERROR_NOT_AVAILABLE) [nsIHttpChannel.responseStatus] the actual number would be 0x80040111 but that is triggering the forum antispam filter. which appears related to this line aRequest.respo...
by johnscript
Mon Dec 05, 2016 8:54 pm
Forum: NoScript Development
Topic: ABE seems to be broken since the latest release [2.9.5.1]
Replies: 25
Views: 12653

Re: ABE seems to be broken since the latest release [2.9.5.1

OK, thanks for the info. There is a security issue (as pointed out here https://forums.informaction.com/viewtopic.php?f=23&t=8870#p45810) with just having a rule of "Accept from moz-nullprincipal:" I thought so, even if it was just a hunch - I don' t really understand this stuff... but...
by johnscript
Sat Dec 03, 2016 7:53 pm
Forum: NoScript Development
Topic: ABE seems to be broken since the latest release [2.9.5.1]
Replies: 25
Views: 12653

Re: ABE seems to be broken since the latest release [2.9.5.1

I was going to report this issue, looks like it's still there in NoScript 2.9.5.2rc5 . With a simple rule such as Site .informaction.com Accept from SELF .noscript.net Deny at first just eliminating the leading dot on the first line seems to work, but then eventually ABE will unexpectedly trigger a ...
by johnscript
Sat Dec 03, 2016 7:38 pm
Forum: Web Tech
Topic: The Future of Developing Firefox Add-ons
Replies: 32
Views: 21010

Re: The Future of Developing Firefox Add-ons

(...) What sorts of existing extensions will not be possible to port, exactly? And if these are not (all) malicious extensions, why can't WebExtensions provide the needed functionality? My suspicion is that, apart from the general will to over-simplify and flatten the browser, they probably don't w...
by johnscript
Mon Aug 01, 2016 9:19 pm
Forum: ABE
Topic: How to export all surrogate lines from about:config?
Replies: 8
Views: 5832

Re: How to export all surrogate lines from about:config?

On a related note, I can't actually see in the prefs.js files all the surrogate entries that are visible in about:config using the "surrogate" keyword in the search field.
by johnscript
Mon Aug 01, 2016 9:13 pm
Forum: ABE
Topic: Can websites somehow detect your ABE rules?
Replies: 8
Views: 5450

Re: Can websites somehow detect your ABE rules?

But that's what I meant exactly: my apologies if it wasn't so clear... the "free stuff" thing was actually referred to them. And thinking of it again, if *I* thought about this, they No need to give away free help and code samples to people who want to fingerprint you . must have figured t...
by johnscript
Sat Jul 30, 2016 10:52 am
Forum: NoScript Surrogates
Topic: Disable plugin enumeration using NoScript surrogates?
Replies: 5
Views: 109306

Re: Disable plugin enumeration using NoScript surrogates?

Ok, but could you explain in layman's terms if this feature could be considered a drop-in replacement for the original (removed) Firefox feature? Furthermore, the code looks a bit different to me: noscript.surrogate.noplugin.exceptions = noscript.surrogate.noplugin.replacement = Object.definePropert...
by johnscript
Sat Jul 30, 2016 10:24 am
Forum: ABE
Topic: Can websites somehow detect your ABE rules?
Replies: 8
Views: 5450

Re: Can websites somehow detect your ABE rules?

barbaz wrote:Yes and no. It depends on the purpose of your ABE rules.
I'm not giving more information in a public thread.
Well yes, I can understand that: no need to give away free stuff.
by johnscript
Sat Jul 30, 2016 10:22 am
Forum: ABE
Topic: Can websites somehow detect your ABE rules?
Replies: 8
Views: 5450

Re: Can websites somehow detect your ABE rules?

How would someone detect ABE rules? I can detect Javascript on/off and the NoScript addon, but not ABE rules. I think this is impossible. This is the same with iptables rules. Maybe not : although ABE is generally described as a firewall for convenience, I think it's not just comparable to an iptab...
by johnscript
Wed Jul 27, 2016 10:34 am
Forum: ABE
Topic: Can websites somehow detect your ABE rules?
Replies: 8
Views: 5450

Can websites somehow detect your ABE rules?

We know that websites can kinda easily detect if you are using NoScript (well, scripts are blocked...) so much so that I often spot some specific "noscript" elements in page sources (maybe they are adding those to "unbreak" the page if scripts are blocked?) : but can they also de...