help making XSS exception

Ask for help about NoScript, no registration needed to post
Gazer75

help making XSS exception

Post by Gazer75 »

I have no idea how to do regex so need help making the following website work. Assuming the issue is XSS. Its working fine only when I allow scripts globally.
Really love NoScript, but its making way to many government sites not work properly. Guess its because of the way they connect to each other with scripts.

Link

The numbers behind appid= and webmap= will obviously change.

Thank you
Last edited by Thrawn on Sat May 25, 2013 3:50 am, edited 1 time in total.
Reason: Fixed truncated link
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:21.0) Gecko/20100101 Firefox/21.0
User avatar
therube
Ambassador
Posts: 7991
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: help making XSS exception

Post by therube »

Looks to work for me by allowing:

Code: Select all

+eu-west-1.elb.amazonaws.com
+arcgisonline.com
+arcgis.com
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:22.0) Gecko/20100101 SeaMonkey/2.19a2
Gazer75

Re: help making XSS exception

Post by Gazer75 »

Only a blank page for me...
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:21.0) Gecko/20100101 Firefox/21.0
Gazer75

Re: help making XSS exception

Post by Gazer75 »

AdBlock sees the following with NoScript enabled

Code: Select all

http://serverapi.arcgisonline.com/jsapi/arcgis/3.5/js/dojo/dijit/themes/tundra/tundra.css
http://serverapi.arcgisonline.com/jsapi/arcgis/3.5/js/esri/css/esri.css
http://serverapi.arcgisonline.com/jsapi/arcgis/3.5compact
http://vegvesenet.maps.arcgis.com/apps/SimpleMapViewer/javascript/desktopUtils.js
http://vegvesenet.maps.arcgis.com/apps/SimpleMapViewer/javascript/geolocateUtils.js
http://vegvesenet.maps.arcgis.com/apps/SimpleMapViewer/javascript/layout.js
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:21.0) Gecko/20100101 Firefox/21.0
Gazer75

Re: help making XSS exception

Post by Gazer75 »

Anyone else have any ideas?
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:21.0) Gecko/20100101 Firefox/21.0
User avatar
Giorgio Maone
Site Admin
Posts: 9557
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: help making XSS exception

Post by Giorgio Maone »

I can't see any XSS issue.
Anyway, I got a blank page too (and also a strange error message window about security permission) until I allowed all the following:
  1. arcgis.com
  2. geodataonline.no
  3. arcgisonline.com
Then the map worked just fine.
Did you try with all these permissions?
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:21.0) Gecko/20100101 Firefox/21.0
Gazer75

Re: help making XSS exception

Post by Gazer75 »

Thanks for looking at this.

I have all three are in my whitelist and still nothing but a blank page :(
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:21.0) Gecko/20100101 Firefox/21.0
User avatar
Giorgio Maone
Site Admin
Posts: 9557
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: help making XSS exception

Post by Giorgio Maone »

Gazer75 wrote:Thanks for looking at this.

I have all three are in my whitelist and still nothing but a blank page :(
Could you try on a clean profile with just NoScript installed?
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:21.0) Gecko/20100101 Firefox/21.0
Post Reply