About Firefox blocking all current Java versions

Bug reports and enhancement requests
Post Reply
rick
Junior Member
Posts: 21
Joined: Fri Feb 03, 2012 6:02 pm

About Firefox blocking all current Java versions

Post by rick »

Greetings

Firefox in order to pretect users, they have enabled Click To Play for recent versions of Java on all platforms (Java 7u9, 7u10, 6u37, 6u38)
Firefox Blocks All Current Java Versions to Block Zero-Day

But, when you have Noscript installed,
the placeholder that Noscript shows for every java content that it blocks
doesn't contain the message that this plugin has been blocked by Firefox, as security vulnerable.


To reproduce:
in a clean FF profile without Noscript installed
visit a page with java content,
you'll get this message:
Image

But, with Noscript installed
if you visit the page
you'll get this instead:
Image


I'd suggest that,
for any content blocked by Noscript for which the plugin is blocked by Firefox,
Noscript to show the placeholder of screenshot2 with the text addition "This plugin has security vunrabilities".
Mozilla/5.0 (Windows NT 6.2; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: About Firefox blocking all current Java versions

Post by Thrawn »

Interesting idea.

However, if someone is using NoScript to block Java, then they are already choosing to mistrust Java in general, and only allow it on sites that they trust not to misuse it. And those sites presumably aren't going to exploit this zero-day. So I'm not sure that there's a strong enough benefit to be worth the extra effort. It's up to Giorgio to decide, of course.

Thanks for highlighting the issue, though. It's a good demonstration of exactly why NoScript uses default-deny, and why it markets itself as protecting you against even unknown threats.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:18.0) Gecko/20100101 Firefox/18.0
User avatar
Giorgio Maone
Site Admin
Posts: 9527
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: About Firefox blocking all current Java versions

Post by Giorgio Maone »

I'll see what I can do, but doesn't seem easy.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0
User avatar
therube
Ambassador
Posts: 7971
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: About Firefox blocking all current Java versions

Post by therube »

For the moment (don't sneeze) it may be immaterial (assuming you've now updated & assuming Mozilla revises their blocklist, if need be).

Java 0-Day patched as Java 7 U 11 released
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:20.0) Gecko/20100101 Firefox/20.0 SeaMonkey/2.17a2
Post Reply