noscript xss issues with bookmarklets
-
pinboarder
noscript xss issues with bookmarklets
Hello,
I have 2 bookmarklets from pinboard (here - popup and popump with tags.in that I am having problems using with noscript.
If I use noscript with script blocking enabled the bookmarklets works
If I disable noscript script blocking but keep other protections the bookmarklets do not work until I either disable XSS protections or reset noscript to defaults.
is there a way to work around this so I can use the bookmarklets and noscript with script blocking disabled?
I have 2 bookmarklets from pinboard (here - popup and popump with tags.in that I am having problems using with noscript.
If I use noscript with script blocking enabled the bookmarklets works
If I disable noscript script blocking but keep other protections the bookmarklets do not work until I either disable XSS protections or reset noscript to defaults.
is there a way to work around this so I can use the bookmarklets and noscript with script blocking disabled?
Mozilla/5.0 (Windows NT 6.1; rv:38.0) Gecko/20100101 Firefox/38.0
Re: noscript xss issues with bookmarklets
What do you mean by this? "Scripts Globally Allowed"? There isn't a checkbox to switch off script-blocking.pinboarder wrote: If I disable noscript script blocking
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:44.0) Gecko/20100101 Firefox/44.0
Re: noscript xss issues with bookmarklets
What happens if you only Allow pinboard.in ?
Or both pinboard.in & the domain you run the bookmarklet from?
Guessing that is what is needed?
Or both pinboard.in & the domain you run the bookmarklet from?
Guessing that is what is needed?
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:42.0) Gecko/20100101 Firefox/42.0 SeaMonkey/2.39
Re: noscript xss issues with bookmarklets
I'm guessing yes, that they disabled NoScript from the Add-ons Manager and instead of confirming at NoScript's warning, selected the "No, just stop blocking scripts" option.Thrawn wrote:What do you mean by this? "Scripts Globally Allowed"? There isn't a checkbox to switch off script-blocking.pinboarder wrote: If I disable noscript script blocking
*Always* check the changelogs BEFORE updating that important software!
-
-
pinboarder
Re: noscript xss issues with bookmarklets
barbaz wrote:I'm guessing yes, that they disabled NoScript from the Add-ons Manager and instead of confirming at NoScript's warning, selected the "No, just stop blocking scripts" option.Thrawn wrote:What do you mean by this? "Scripts Globally Allowed"? There isn't a checkbox to switch off script-blocking.pinboarder wrote: If I disable noscript script blocking
Barbaz: yes this is what I meant sorry if not clear.therube wrote:What happens if you only Allow pinboard.in ?
Or both pinboard.in & the domain you run the bookmarklet from?
Guessing that is what is needed?
Mozilla/5.0 (Windows NT 6.1; rv:38.0) Gecko/20100101 Firefox/38.0
-
pinboarder
Re: noscript xss issues with bookmarklets
Pinboard.in is whitelisted already. I have tried whitelisting a page and testing a bookmarklet but it still does not work. It would not be a great solution though if it did as the idea of pinboard is it is an online bookmark service so i could be bookmarking for any site on internettherube wrote:What happens if you only Allow pinboard.in ?
Or both pinboard.in & the domain you run the bookmarklet from?
Guessing that is what is needed?
Mozilla/5.0 (Windows NT 6.1; rv:38.0) Gecko/20100101 Firefox/38.0
Re: noscript xss issues with bookmarklets
Is that the same as 'Allow Script Globally'?"No, just stop blocking scripts"
What is "popup" supposed to do?
With scripts Allow Globally, popup bookmarklet pops up a window asking me to login.
(It may have been that after first "No, just stop blocking scripts", that at that point, the popup did not work ? not sure, but there was one point in time when it did not. Possible that either a new window or browser restart was required?)
If you Reset NoScript, then XSS is enabled, so I'm not quite following?until I either disable XSS protections or reset noscript to defaults.
You've tested with a new, clean Profile?
Only change is to install NoScript, then set "No, just stop blocking scripts".
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:42.0) Gecko/20100101 SeaMonkey/2.39
-
pinboarder
Re: noscript xss issues with bookmarklets
Yes as far as I can telltherube wrote:Is that the same as 'Allow Script Globally'?"No, just stop blocking scripts"
popup = opens a window, adds a bookmark of the current page to my pinboard.in account, closes window. No user action needed for thistherube wrote: What is "popup" supposed to do?
popup with tags = opens a window as above but stays open until you add tags for the bookmark and save
With scripts Allow Globally, popup bookmarklet pops up a window asking me to login.
Yes this does seem to be the case, some times even a few times it will work before breaking again.therube wrote: (It may have been that after first "No, just stop blocking scripts", that at that point, the popup did not work ? not sure, but there was one point in time when it did not. Possible that either a new window or browser restart was required?)
The problem with the bookmarklet can be resolved by eithertherube wrote:If you Reset NoScript, then XSS is enabled, so I'm not quite following?until I either disable XSS protections or reset noscript to defaults.
1. disabling XSS protection when "Allow Scripts Globally" is set
2. resetting noscript to defaults; which enables XSS protection and Blocks Scripts (I need to whitelist pinboard.in after reset)
Yes, I've tried this, always one I allow scripts globally it will shortly fail and stay broken until either xss protection is turned off or script blocking is turned back on (withtherube wrote: You've tested with a new, clean Profile?
Only change is to install NoScript, then set "No, just stop blocking scripts".
Mozilla/5.0 (Windows NT 6.1; rv:38.0) Gecko/20100101 Firefox/38.0
Re: noscript xss issues with bookmarklets
XSS protection should log InjectionChecker and/or XSS messages.
Please check the Browser Console (Ctrl-Shift-J) when this issue happens and post here any messages related to NoScript.
(related messages usually start with either "[NoScript" or "[ABE]"; if you don't know what's related, turn off CSS warnings and post everything else you see)
Please check the Browser Console (Ctrl-Shift-J) when this issue happens and post here any messages related to NoScript.
(related messages usually start with either "[NoScript" or "[ABE]"; if you don't know what's related, turn off CSS warnings and post everything else you see)
*Always* check the changelogs BEFORE updating that important software!
-
-
pinboarder
Re: noscript xss issues with bookmarklets
Error I get in console CSS
Content Security Policy: The page's settings blocked the loading of a resource at self ("script-src 'unsafe-eval' *").
Content Security Policy: The page's settings blocked the loading of a resource at self ("script-src 'unsafe-eval' *").
Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0
-
pinboarder
Re: noscript xss issues with bookmarklets
I should say that there are no other errors in the console. just that
Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0