XSS Alert for AT&T Wireless, False Positive?

Ask for help about NoScript, no registration needed to post
User avatar
GµårÐïåñ
Lieutenant Colonel
Posts: 3371
Joined: Fri Mar 20, 2009 5:19 am
Location: PST - USA
Contact:

XSS Alert for AT&T Wireless, False Positive?

Post by GµårÐïåñ »

I have been using their website for a very long time, it was Cingular at the time, and their code has changed very little over the last few years. Anyway, I have NEVER gotten an XSS warning until earlier today (around 2:30 AM) and no matter which page of the site I am on, it gives me an XSS warning, what's up?

Here is the screenshot of the message as well as the console report. I didn't want to put every single error here, it would be VERY long. I'd appreciate knowing if the site is really messed up, the developer pulled some kind of a bonehead move or is it just a false positive that can be corrected please. TIA

Image
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10
Tom T.
Field Marshal
Posts: 3620
Joined: Fri Mar 20, 2009 6:58 am

Re: XSS Alert for AT&T Wireless, False Positive?

Post by Tom T. »

GµårÐïåñ wrote:I have been using their website for a very long time, it was Cingular at the time, and their code has changed very little over the last few years. Anyway, I have NEVER gotten an XSS warning ...
I too have used Cing / ATT, never had a problem, went there now, logged in, checked account, logged out.
Unable to reproduce.
F2.0.0.20 reminder.
Original/exact URL of the example? (minus personal ID info, of course.)
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US at an expert level; rv:1.8.1.20) Gecko/20081217 Firefox/2.0.0.20 diehard
User avatar
GµårÐïåñ
Lieutenant Colonel
Posts: 3371
Joined: Fri Mar 20, 2009 5:19 am
Location: PST - USA
Contact:

Re: XSS Alert for AT&T Wireless, False Positive?

Post by GµårÐïåñ »

After I posted this, I updated to 1.9.3.3 and now the damn thing won't reproduce but as you can see in the picture, it was doing it and it was doing it consistently. Both my account AND my wife's. I don't know if updating to 1.9.3.3 fixed it or what.

I guess the only thing I can do is wait and see if it happens again. The link on which it was happening in the example posted is right there in the screenshot where it goes to after you login and the dancing AT&T flash validation is done (before used to be Cingular jumping orange man) and then it gave the XSS and then from that point each and every link would do the same thing.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10
Tom T.
Field Marshal
Posts: 3620
Joined: Fri Mar 20, 2009 6:58 am

Re: XSS Alert for AT&T Wireless, False Positive?

Post by Tom T. »

GµårÐïåñ wrote:...the dancing AT&T flash validation is done (before used to be Cingular jumping orange man)
I have Flash blocked at that entire domain. Also have scripting blocked from liveperson.net. Could these be possible causes?
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US at an expert level; rv:1.8.1.20) Gecko/20081217 Firefox/2.0.0.20 diehard
User avatar
GµårÐïåñ
Lieutenant Colonel
Posts: 3371
Joined: Fri Mar 20, 2009 5:19 am
Location: PST - USA
Contact:

Re: XSS Alert for AT&T Wireless, False Positive?

Post by GµårÐïåñ »

I suppose its possible but I have always had liveperson blocked on all domains and although flash is allowed on that domain, never been an issue before and doesn't seem to be now either, which bothers me. I don't like not knowing why a problem came and went, it leaves me feeling like I missed something.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10
Post Reply