noscript update splash page serves malware?

Ask for help about NoScript, no registration needed to post
r8limiter

noscript update splash page serves malware?

Post by r8limiter »

Hi - after updating noscript and restarting my browser today I was presented with the release notes page as usual (http://noscript.net/?ver=2.6.8.4&prev=2.6.7.1).

What was unusual was that the page contained an iframe whos source was blocked by my company's web security appliance due to it being used to serve malware.

After refreshing the page, the iframe disappeared. I'm wondering if anyone else is seeing this?

Thanks
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:24.0) Gecko/20100101 Firefox/24.0
r8limiter

Re: noscript update splash page serves malware?

Post by r8limiter »

I have the malware url and diffs of the html served for the clean page and the malware page if that's helpful.

It seems this may just be a fundamental issue with http though - perhaps I was MITM'd. Time to make noscript.net https?

Thanks
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:24.0) Gecko/20100101 Firefox/24.0
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: noscript update splash page serves malware?

Post by Thrawn »

I haven't seen this occur, no.

Giorgio does serve the actual addons over https (on secure.informaction.com), but not the NoScript or Flashgot websites.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:25.0) Gecko/20100101 Firefox/25.0
User avatar
Giorgio Maone
Site Admin
Posts: 9557
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: noscript update splash page serves malware?

Post by Giorgio Maone »

I heard about ESET false positives about AfterDownload ad units (which are loaded in iframes), recently. Nothing to be worried about.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
Post Reply