querying file://

Ask for help about NoScript, no registration needed to post
greenhatch
Posts: 9
Joined: Thu Mar 19, 2009 6:11 pm

querying file://

Post by greenhatch »

What is file:// that now appears as temporary allowed every time I open Firefox (since last few development builds)?
[NS 1.9.4.1]
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.1b99) Gecko/20090605 Firefox/3.5b99
Alan Baxter
Ambassador
Posts: 1586
Joined: Fri Mar 20, 2009 4:47 am
Location: Colorado, USA

Re: querying file://

Post by Alan Baxter »

For me, pressing NoScript Options Reset causes file:// to appear as a permanently whitelisted entry. To reproduce something similar to greenhatch's issue I did the following.
- load http://noscript.net/
- temporarily allow buysellads.com
Result: file:// and buysellads.com both appear as temporarily allowed in NoScript Options > Whitelist
- exit Firefox and restart
Result: both temporarily allowed items are gone, as expected
- load http://noscript.net/ again and temporarily allow doubleclick.net
Result: file:// and doubleclick.net both appear as temporarily allowed in NoScript Options > Whitelist
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
greenhatch
Posts: 9
Joined: Thu Mar 19, 2009 6:11 pm

Re: querying file://

Post by greenhatch »

so basically file:// is not a good thing i presume (just noticed the 1.9.4.1 dev build thread)...
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.1b99) Gecko/20090605 Firefox/3.5b99
User avatar
therube
Ambassador
Posts: 7929
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: querying file://

Post by therube »

What is file:// that now appears as temporary allowed every time I open Firefox
A bug, http://forums.informaction.com/viewtopi ... 5884#p5884.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1pre) Gecko/20090608 SeaMonkey/2.0b1pre
toolazytoregister

Re: querying file://

Post by toolazytoregister »

Most often when I visit the website for Dell it seems I get some syntactically odd items added to the Whitelist tab of NoScript, some are allowed and some are temporarily allowed.

I have the NoScript temporarily allow top-level sites by default option enabled using base 2nd level domains.

I get to the Dell website by following the second link shown on a yahoo search results page for “Dell.” Then I look at some configurations of Dell systems for sale. Afterwards I notice the weird NoScript items.

For example, without my approval

“ f i l e : / / ” gets temporarily whitelisted,

“ 1 ” gets whitelisted, and

two schemes // authorities / partial paths for dell.com get whitelisted as well, one is http and the other is https.

This has been an issue for more than a year, in some form or another. Only recently was lucky enough to identify Dell website as an apparent source of the issue.

What is the risk of the "f i l e : // " one? Would blacklisting it be a work-around?
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11 (.NET CLR 3.5.30729)
Locked