Error Console question

Ask for help about NoScript, no registration needed to post
jeno

Error Console question

Post by jeno »

Using latest version of Noscript...
What is the signifigance of this in Error Console?

addons.mozilla.org : potentially vulnerable to CVE-2009-3555
[NoScript HTTPS] AUTOMATIC SECURE on https://addons.mozilla.org: X-Mapping-kgbglcod=5DCE4DD3FC98BAC9D6709B5FB9B0CF35; domain=addons.mozilla.org; path=/; Secure

aus2.mozilla.org : potentially vulnerable to CVE-2009-3555
services.addons.mozilla.org : potentially vulnerable to CVE-2009-3555
versioncheck.addons.mozilla.org : potentially vulnerable to CVE-2009-3555
versioncheck.addons.mozilla.org : potentially vulnerable to CVE-2009-3555
sb-ssl.google.com : potentially vulnerable to CVE-2009-3555
[NoScript HTTPS] AUTOMATIC SECURE on https://sb-ssl.google.com: PREF=ID=1f9ed71077578558:TM=1269464180:LM=1269464180:S=oSiKyasD5S9XocmF; domain=.google.com; path=/; Secure

jeno
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.2) Gecko/20100316 Firefox/3.6.2
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Error Console question

Post by Giorgio Maone »

jeno wrote:addons.mozilla.org : potentially vulnerable to CVE-2009-3555
This means that you've got some other add-on (not NoScript) which is scanning any web server you connect to for possible vulnerabilities (CVE-2009-3555 was the TLS negotiation injection bug).
jeno wrote: [NoScript HTTPS] AUTOMATIC SECURE on https://addons.mozilla.org: X-Mapping-kgbglcod=5DCE4DD3FC98BAC9D6709B5FB9B0CF35; domain=addons.mozilla.org; path=/; Secure
This means that you enabled automatic secure cookie management and NoScript promoted the X-Mapping-kgbglcod cookie to HTTPS-Only.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.2.2) Gecko/20100316 Firefox/3.6.2
jeno

Re: Error Console question

Post by jeno »

Only Add-ons are Noscript and Element Properties 6...
IIRC, I got the first message right before I downloaded Element Properties 6???

jeno
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.2) Gecko/20100316 Firefox/3.6.2
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Error Console question

Post by Giorgio Maone »

jeno wrote:Only Add-ons are Noscript and Element Properties 6...
Are you double-sure? it would be very weird...
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.2.2) Gecko/20100316 Firefox/3.6.2
jeno

Re: Error Console question

Post by jeno »

Yes... positive!

jeno
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.2) Gecko/20100316 Firefox/3.6.2
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Error Console question

Post by Giorgio Maone »

Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.2.2) Gecko/20100316 Firefox/3.6.2
jeno

Re: Error Console question

Post by jeno »

Thank you so much, Giorgio! Looks like some servers need fixed, huh? :o
So I've no problems here then?

jeno
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.2) Gecko/20100316 Firefox/3.6.2
User avatar
therube
Ambassador
Posts: 7969
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: Error Console question

Post by therube »

Just a while ago I had been reading Security:Renegotiation & trying to figure out why security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref was set to 'True'. Apparently it is True on the Branch & False (as the wiki says it should be) on the Trunk. Giorgio's link my provide the reason for that?

(Enable security.ssl.treat_unsafe_negotiation_as_broken & watch all the broken padlock icons ;-).)
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.10pre) Gecko/20100323 SeaMonkey/2.0.5pre
justsomebloke

Re: Error Console question

Post by justsomebloke »

therube proposed:
Enable security.ssl.treat_unsafe_negotiation_as_broken & watch all the broken padlock icons ;-).)
Yep, that red icon is the throbber here ;-)

What would a person really need secure connections for?
money, the internets, secure mail, to list the obvious.
So far, not the bank, the isp, the mighty gmail, that I've messaged about compliance have lifted a finger to comply.

Check certificates then, they say.
Oh ha ha.
ssl is so broken.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.9.2.2) Gecko/20100316 Firefox/3.6.2
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Error Console question

Post by Giorgio Maone »

jeno wrote:So I've no problems here then?
Apparently not.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.2.2) Gecko/20100316 Firefox/3.6.2
turnerharry69@yahoo.com

Re: Error Console question

Post by turnerharry69@yahoo.com »

So is this bad it seems to pop up with the add on Microsoft.net framework assistant 1.0
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
Post Reply