Ask for help about NoScript, no registration needed to post
g113
Post
by g113 » Tue Apr 07, 2009 5:53 pm
good evening,
i'm french please excuse my english, but i have a problem with my web page, i have this alert and i don't now what doing !
thanks
Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9.0.8) Gecko/2009032609 Firefox/2.0.0.7
therube
Ambassador
Posts: 7972 Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA
Post
by therube » Tue Apr 07, 2009 6:13 pm
Check Error Console & see if it provides further information on the (potential) XSS & post the information here.
Link: Netvibes
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.21) Gecko/20090403 SeaMonkey/1.1.16
g113
Post
by g113 » Wed Apr 08, 2009 7:43 pm
up !
Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9.0.8) Gecko/2009032609 Firefox/2.0.0.7 (.NET CLR 3.5.30729)
Giorgio Maone
Site Admin
Posts: 9530 Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:
Post
by Giorgio Maone » Wed Apr 08, 2009 9:07 pm
NoScript is correct.
That page is actually vulnerable to XSS: try to open
this url on a browser without NoScript.
IE8 will detect the XSS. Other browsers (including Firefox without NoScript) will show a XSS popup I'm injecting on the target page.
I strongly advidse to disable the Good Planet widget.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.8) Gecko/2009032609 Firefox/3.0.8 (.NET CLR 3.5.30729)
g113
Post
by g113 » Thu Apr 09, 2009 3:12 pm
thanks, but i can't disable this widget
Opera/9.64 (Windows NT 6.0; U; fr) Presto/2.1.1
Giorgio Maone
Site Admin
Posts: 9530 Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:
Post
by Giorgio Maone » Thu Apr 09, 2009 3:31 pm
g113 wrote: thanks, but i can't disable this widget
Then the less risky thing you can do then is granting the netvibes.com main page a free pass for sending XSS like request, by adding the following line in
NoScript Options|Advanced|XSS|Exceptions :
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.8) Gecko/2009032609 Firefox/3.0.8 (.NET CLR 3.5.30729)
g113
Post
by g113 » Thu Apr 09, 2009 6:21 pm
thank you very much
it works
Mozilla/5.0 (Windows; U; Windows NT 6.0; fr; rv:1.9.0.8) Gecko/2009032609 Firefox/2.0.0.7