Need to remove a Javascript pop-up notice
Need to remove a Javascript pop-up notice
Hi, I've used No-Script on Firefox for quite a few years now and it's been excellent with no problems at all.
However I started having problems recently with a JavaScript pop-up notice that kept appearing and causing slowing down or crashing of the browser page. I got in touch with Firefox help desk about this who then told me to individually isolate all the extensions to trace which one was at fault. It turned out that for some reason it was "No Script" which when disabled removed the pop-up notice immediately. Unfortunately however I can't find anywhere to upload and attach a screen pic of it ?
Much appreciate any help to resolve this as I'd like to re-install "No-Script" again as soon as possible.....
Thanks in advance
However I started having problems recently with a JavaScript pop-up notice that kept appearing and causing slowing down or crashing of the browser page. I got in touch with Firefox help desk about this who then told me to individually isolate all the extensions to trace which one was at fault. It turned out that for some reason it was "No Script" which when disabled removed the pop-up notice immediately. Unfortunately however I can't find anywhere to upload and attach a screen pic of it ?
Much appreciate any help to resolve this as I'd like to re-install "No-Script" again as soon as possible.....
Thanks in advance
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
Re: Need to remove a Javascript pop-up notice
Just what is this popup notice, what does it say?
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:38.0) Gecko/20100101 SeaMonkey/2.35
Re: Need to remove a Javascript pop-up notice
Unfortunately as I can't find a way to upload on here I've had to post a screen pic of it on photobucket....
http://i356.photobucket.com/albums/oo5/ ... dhqjfk.jpg
http://i356.photobucket.com/albums/oo5/ ... dhqjfk.jpg
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
Re: Need to remove a Javascript pop-up notice
My browser says the image cannot be displayed because it contains errors
*Always* check the changelogs BEFORE updating that important software!
-
Re: Need to remove a Javascript pop-up notice
If you mean the image in Photobucket mine's fine....
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
Re: Need to remove a Javascript pop-up notice
Yes the one on Photobucket. Still same deal here but if I download it then I can view it in my system's image viewer.
see viewtopic.php?f=7&t=21192 ?
see viewtopic.php?f=7&t=21192 ?
*Always* check the changelogs BEFORE updating that important software!
-
Re: Need to remove a Javascript pop-up notice
I'm guessing that there will be something in the Browser Console (Ctrl+Shift+J) when this occurs. Probably either the XSS filter or the Cross-Site Inclusion Filter.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:40.0) Gecko/20100101 Firefox/40.0
Re: Need to remove a Javascript pop-up notice
Sorry way, way above my head.... !
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
Re: Need to remove a Javascript pop-up notice
Reproduce the problem, hit Ctrl-Shift-J, and post all messages you see starting with "[NoScript".
*Always* check the changelogs BEFORE updating that important software!
-
Re: Need to remove a Javascript pop-up notice
browser.xul
Key event not available on some keyboard layouts: key="c" modifiers="accel,alt" browser.xul
Key event not available on some keyboard layouts: key="i" modifiers="accel,alt,shift" browser.xul
[NoScript InjectionChecker] JavaScript Injection in qp=si=1&e=https%3A%2F%2Fonline.lloydsbank.co.uk&LSESSIONID=jLd1o6QZ44QndCuBLhsp2TwMpfOSpn%2FZXEiyEXavFtPX08UvNMN04sU%3D&t=xpost&pd=d=JTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uZGl2JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMndyYXBwZXIlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjElMjUyQyUyNTIyJTI1MjIlMjUyQyUyNTIyb3V0ZXIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyaGVhZGVyJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIzJTI1MkMlMjUyMiUyNTIyJTI1MkMlMjUyMmNsZWFyZml4JTI1MjIlMjU1RCUyNTJDJTI1NUI0JTI1MkMlMjUyMiUyNTIyJTI1MkMlMjUyMnNlY3VyZU1zZyUyNTIyJTI1NUQlMjUyQyUyNTVCNSUyNTJDJTI1MjIlMjUyMiUyNTJDJTI1MjJsb2dnZWRJbiUyNTIyJTI1NUQlMjUyQyUyNTVCNiUyNTJDJTI1MjIlMjUyMiUyNTJDJTI1MjJwYWdlV3JhcCUyNTIyJTI1NUQlMjUyQyUyNTVCNyUyNTJDJTI1MjJwYWdlJTI1MjIlMjUyQyUyNTIyY29udGVudCUyNTIyJTI1NUQlMjUyQyUyNTVCOCUyNTJDJTI
[NoScript XSS]: sanitized window.name, "qp=si%3D1%26e%3Dhttps%253A%252F%252Fonline.lloydsbank.co.uk%26LSESSIONID%3DjLd1o6QZ44QndCuBLhsp2TwMpfOSpn%252FZXEiyEXavFtPX08UvNMN04sU%253D%26t%3Dxpost&pd=d%3DJTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uZGl2JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMndyYXBwZXIlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjElMjUyQyUyNTIyJTI1MjIlMjUyQyUyNTIyb3V0ZXIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyaGVhZGVyJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIzJTI1MkMlMjUyMiUyNTIyJTI1MkMlMjUyMmNsZWFyZml4JTI1MjIlMjU1RCUyNTJDJTI1NUI0JTI1MkMlMjUyMiUyNTIyJTI1MkMlMjUyMnNlY3VyZU1zZyUyNTIyJTI1NUQlMjUyQyUyNTVCNSUyNTJDJTI1MjIlMjUyMiUyNTJDJTI1MjJsb2dnZWRJbiUyNTIyJTI1NUQlMjUyQyUyNTVCNiUyNTJDJTI1MjIlMjUyMiUyNTJDJTI1MjJwYWdlV3JhcCUyNTIyJTI1NUQlMjUyQyUyNTVCNyUyNTJDJTI1MjJwYWdlJTI1MjIlMjUyQyUyNTIyY29udGVudCUyNTIyJTI1NUQlMjUyQyUyN
https://marketing.lloydsbank.co.uk//llo ... %3DPLO0512
about:blank
Overriding failed (2147500037) redirect callback for 12: https://aa.online-metrix.net/fpc.swf?se ... 3a3a3d3135 -> https://aa.online-metrix.net/fpc.swf?se ... 3a3a3d3135 - 2
This site makes use of a SHA-1 Certificate; it's recommended you use certificates with signature algorithms that use hash functions stronger than SHA-1.[Learn More] update.xm
Key event not available on some keyboard layouts: key="c" modifiers="accel,alt" browser.xul
Key event not available on some keyboard layouts: key="i" modifiers="accel,alt,shift" browser.xul
[NoScript InjectionChecker] JavaScript Injection in qp=si=1&e=https%3A%2F%2Fonline.lloydsbank.co.uk&LSESSIONID=jLd1o6QZ44QndCuBLhsp2TwMpfOSpn%2FZXEiyEXavFtPX08UvNMN04sU%3D&t=xpost&pd=d=JTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uZGl2JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMndyYXBwZXIlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjElMjUyQyUyNTIyJTI1MjIlMjUyQyUyNTIyb3V0ZXIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyaGVhZGVyJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIzJTI1MkMlMjUyMiUyNTIyJTI1MkMlMjUyMmNsZWFyZml4JTI1MjIlMjU1RCUyNTJDJTI1NUI0JTI1MkMlMjUyMiUyNTIyJTI1MkMlMjUyMnNlY3VyZU1zZyUyNTIyJTI1NUQlMjUyQyUyNTVCNSUyNTJDJTI1MjIlMjUyMiUyNTJDJTI1MjJsb2dnZWRJbiUyNTIyJTI1NUQlMjUyQyUyNTVCNiUyNTJDJTI1MjIlMjUyMiUyNTJDJTI1MjJwYWdlV3JhcCUyNTIyJTI1NUQlMjUyQyUyNTVCNyUyNTJDJTI1MjJwYWdlJTI1MjIlMjUyQyUyNTIyY29udGVudCUyNTIyJTI1NUQlMjUyQyUyNTVCOCUyNTJDJTI
[NoScript XSS]: sanitized window.name, "qp=si%3D1%26e%3Dhttps%253A%252F%252Fonline.lloydsbank.co.uk%26LSESSIONID%3DjLd1o6QZ44QndCuBLhsp2TwMpfOSpn%252FZXEiyEXavFtPX08UvNMN04sU%253D%26t%3Dxpost&pd=d%3DJTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uZGl2JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMndyYXBwZXIlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjElMjUyQyUyNTIyJTI1MjIlMjUyQyUyNTIyb3V0ZXIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyaGVhZGVyJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIzJTI1MkMlMjUyMiUyNTIyJTI1MkMlMjUyMmNsZWFyZml4JTI1MjIlMjU1RCUyNTJDJTI1NUI0JTI1MkMlMjUyMiUyNTIyJTI1MkMlMjUyMnNlY3VyZU1zZyUyNTIyJTI1NUQlMjUyQyUyNTVCNSUyNTJDJTI1MjIlMjUyMiUyNTJDJTI1MjJsb2dnZWRJbiUyNTIyJTI1NUQlMjUyQyUyNTVCNiUyNTJDJTI1MjIlMjUyMiUyNTJDJTI1MjJwYWdlV3JhcCUyNTIyJTI1NUQlMjUyQyUyNTVCNyUyNTJDJTI1MjJwYWdlJTI1MjIlMjUyQyUyNTIyY29udGVudCUyNTIyJTI1NUQlMjUyQyUyN
https://marketing.lloydsbank.co.uk//llo ... %3DPLO0512
about:blank
Overriding failed (2147500037) redirect callback for 12: https://aa.online-metrix.net/fpc.swf?se ... 3a3a3d3135 -> https://aa.online-metrix.net/fpc.swf?se ... 3a3a3d3135 - 2
This site makes use of a SHA-1 Certificate; it's recommended you use certificates with signature algorithms that use hash functions stronger than SHA-1.[Learn More] update.xm
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
Re: Need to remove a Javascript pop-up notice
How's things going any luck yet....?
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
Re: Need to remove a Javascript pop-up notice
barbaz wrote:see viewtopic.php?f=7&t=21192 ?
*Always* check the changelogs BEFORE updating that important software!
-
Re: Need to remove a Javascript pop-up notice
Apologies but I haven't the slightest idea what any of it means or what to do Wouldn't it be simplest to just turn off No Script altogether.... ?
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
Re: Need to remove a Javascript pop-up notice
Contact the site and tell them what they are doing is very unsafe and should be changed ASAP?arcadian wrote:Apologies but I haven't the slightest idea what any of it means or what to do
The reason why it's unsafe is they are putting data where *any* site you visit in the same tab/iframe/whatever can access it, so if you were to later visit an attack site, or have already visited an attack site which planted specially crafted payload there...
Or perhaps you can block the script causing this message, using ABE or a surrogate script?
(XSS exception is *not* safe here IMO.)
Do you really think there is any way that it'd be simpler to deal with the after-effects of being XSS'ed, clickjacked, etc., some of which may be used as a malware delivery vector or means to steal money from you, rather than troubleshoot this problem?arcadian wrote:Wouldn't it be simplest to just turn off No Script altogether.... ?
It's not a matter of "if" you'll run into an attack situation on the Internet; it's a matter of when it happens...
*Always* check the changelogs BEFORE updating that important software!
-
Re: Need to remove a Javascript pop-up notice
Great finally got a little clearer idea of things now, so grateful thanks indeed and apols for the dumb final question.... !
Although I've had NS for ages firstly I've never really understood what it was all about as I'm far too busy, so when a friend recommended me to use it to begin with that was good enough for me. Secondly I'm not a techie at all and never will be, and finally when I did try to find out anything it was sheer information overload with no idea of where or how to start. So is there any simple basic info for us types anywhere I can read as to what NS does and aims to do ? Also what does ABE and XXXs mean ?
Anyway first thing I did when it happened was to contact the bank who said it was nothing to do with them, which with hindsight was ridiculous given what you've just told me. Instead they should have automatically told me to immediately report it as a security breach but they didn't ! So now to report it to the bank as I simply daren't tamper with anything....
Again many thanks will keep you posted....!!!!!!
Although I've had NS for ages firstly I've never really understood what it was all about as I'm far too busy, so when a friend recommended me to use it to begin with that was good enough for me. Secondly I'm not a techie at all and never will be, and finally when I did try to find out anything it was sheer information overload with no idea of where or how to start. So is there any simple basic info for us types anywhere I can read as to what NS does and aims to do ? Also what does ABE and XXXs mean ?
Anyway first thing I did when it happened was to contact the bank who said it was nothing to do with them, which with hindsight was ridiculous given what you've just told me. Instead they should have automatically told me to immediately report it as a security breach but they didn't ! So now to report it to the bank as I simply daren't tamper with anything....
Again many thanks will keep you posted....!!!!!!
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0