NoRedirect Fx extension - ? exploitable gatekeeper

General discussion about web technology.
Post Reply
Grumpy Old Lady
Senior Member
Posts: 240
Joined: Fri Jul 03, 2009 7:20 am

NoRedirect Fx extension - ? exploitable gatekeeper

Post by Grumpy Old Lady »

The proliferation of url shortening use by correspondents and many of the feeds I subscribe to makes previewing tinyurl.com and bit.ly one of the bottlenecks in a browser session for me.
I dislike having to hand over usage information to these services, and the roadblock of setting a new cookie at every visit is a slow-down, just to get a preview, so I've looked for an extension to smooth the preview path.
http://code.kliu.org/noredirect/

What kinds of exploits am I opening Fx up to by giving Kai Liu the previewing task?
If any softness, is there anything NS/ABE can help with?
On my dumb reading of it, kliu.org is as straightforward as tinyurl.com and bit.ly for previewing redirection of urls.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2
User avatar
Giorgio Maone
Site Admin
Posts: 9454
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: NoRedirect Fx extension - ? exploitable gatekeeper

Post by Giorgio Maone »

Looks a cool complement to NoScript (BTW, did you notice the plug in the "Miscellanea" section?)
Unless it has coding vulnerability of its own (e.g. insufficient sanitization of the URLs), it seems better to have than not.
I'll try to perform a quick code review ASAP.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2 (.NET CLR 3.5.30729)
User avatar
Giorgio Maone
Site Admin
Posts: 9454
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: NoRedirect Fx extension - ? exploitable gatekeeper

Post by Giorgio Maone »

Code review performed, looks kosher and safe.
Installing for myself too :)
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2 (.NET CLR 3.5.30729)
dhouwn
Bug Buster
Posts: 968
Joined: Thu Mar 19, 2009 12:51 pm

Re: NoRedirect Fx extension - ? exploitable gatekeeper

Post by dhouwn »

Compatible with Firefox 4 now.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0) Gecko/20100101 Firefox/4.0
Post Reply