Disqus + Patheos = constant Clearclick Clickjacking popups

Ask for help about NoScript, no registration needed to post
El Cid

Disqus + Patheos = constant Clearclick Clickjacking popups

Post by El Cid »

This is even with *.disqus.com/*/reply.html?* in the clearclick subexceptions. How do I FIX this?! I don't want to set clearclick protection off for trusted sites just to get rid of this.
Mozilla/5.0 (Windows NT 6.0; Win64; x64; rv:8.0.1) Gecko/20111117 Firefox/8.0.1
User avatar
Giorgio Maone
Site Admin
Posts: 9528
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Disqus + Patheos = constant Clearclick Clickjacking popu

Post by Giorgio Maone »

Could you please use the "Report" button and give me a report ID? Thanks.
Mozilla/5.0 (Windows NT 5.2; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
El Cid

Re: Disqus + Patheos = constant Clearclick Clickjacking popu

Post by El Cid »

Report ID 127485 just submitted.
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:8.0.1) Gecko/20111117 Firefox/8.0.1
Dwedit
Posts: 5
Joined: Sat Jun 20, 2009 1:34 pm

Re: Disqus + Patheos = constant Clearclick Clickjacking popu

Post by Dwedit »

I have also encountered ClearClick warnings on Betanews.com. That website also uses Disqus for its topics. Setting the option to "disable clearclick warnings for Whitelisted pages" was successful at stopping the warning prompts. But I'm afraid that setting the option to disable warnings might expose me to click-jacking attacks on normal 'Script Allowed' pages. I feel I might be more comfortable with a separate exceptions list for ClearClick than applying it to every website with Scripts Allowed.

Edit: The first post in the topic mentions a "clearclick subexceptions" list. This isn't shown anywhere in the UI of the program. Sounds like a serious problem, where features of the program are hidden from the users. I think I found it in "about:config", but adding *.disqus.com did not stop warnings for that site.
Mozilla/5.0 (Windows NT 5.1; rv:12.0a1) Gecko/20120102 Firefox/12.0a1
User avatar
Giorgio Maone
Site Admin
Posts: 9528
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Disqus + Patheos = constant Clearclick Clickjacking popu

Post by Giorgio Maone »

Work-around: change the aforementioned noscript.clearClick.subexceptions entry into

Code: Select all

*.disqus.com/*/reply.html
This will be made the default in next release.
Dwedit wrote:Edit: The first post in the topic mentions a "clearclick subexceptions" list. This isn't shown anywhere in the UI of the program. Sounds like a serious problem, where features of the program are hidden from the users. I think I found it in "about:config", but adding *.disqus.com did not stop warnings for that site.
This is not hidden, it's just not shown in the UI to reduce clutter, like many other preferences which are supposed to be edited only in exceptional cases like this.
In order to access them, you just need to open about:config.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
El Cid

Re: Disqus + Patheos = constant Clearclick Clickjacking popu

Post by El Cid »

Hi,

This has not been fixed. I have just clean installed Firefox 10.0.1 and NoScript 2.3.1 onto a new Win7 box, and the popups are still coming on a disqus+patheos site even though you have altered the exceptions table in NoScript.
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:10.0.1) Gecko/20120212 Firefox/10.0.1
El Cid

Re: Disqus + Patheos = constant Clearclick Clickjacking popu

Post by El Cid »

El Cid wrote:Hi,

This has not been fixed. I have just clean installed Firefox 10.0.1 and NoScript 2.3.1 onto a new Win7 box, and the popups are still coming on a disqus+patheos site even though you have altered the exceptions table in NoScript.
Report ID 256891 FYI.
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:10.0.1) Gecko/20120212 Firefox/10.0.1
User avatar
therube
Ambassador
Posts: 7972
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: Disqus + Patheos = constant Clearclick Clickjacking popu

Post by therube »

I don't know if 2.3.1 is the same as the #dev version 2.3.1rc4, but is there any difference if you use the #dev version?

#dev: v 2.3.1rc4.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0a2) Gecko/20120220 Firefox/12.0a2 SeaMonkey/2.9a2
El Cid

Re: Disqus + Patheos = constant Clearclick Clickjacking popu

Post by El Cid »

This is still not fixed. Every time I click the "reply" box on a disqus based blog hosted on patheos.com, I get the damn popup. Report ID 330700.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:11.0) Gecko/20100101 Firefox/11.0
El Cid

Re: Disqus + Patheos = constant Clearclick Clickjacking popu

Post by El Cid »

Resolved. I modified the default subexceptions list as follows:

^http://bit(?:ly\.com|\.ly)/a/sidebar\?u= http://*.uservoice.com/*/popin.html?* http://w.sharethis.com/share3x/lightbox.html?* http://disqus.com/embed/* *.disqus.com/*/reply.html *.disqus.com/*/reply.html* http://www.feedly.com/mini abine:*
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:11.0) Gecko/20120313 Firefox/11.0
User avatar
Giorgio Maone
Site Admin
Posts: 9528
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Disqus + Patheos = constant Clearclick Clickjacking popu

Post by Giorgio Maone »

Thank you, I incorporated a variant of your fix in latest development build 2.3.6rc3.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:11.0) Gecko/20100101 Firefox/11.0
Post Reply