[FIXED] Credit card stripe.com on Humblebundle blocked

Ask for help about NoScript, no registration needed to post
User avatar
therube
Ambassador
Posts: 7991
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: Credit card stripe.com on Humblebundle blocked

Post by therube »

Without knowing, I'd try, or start with, this set:?

Code: Select all

+youtube.com
+gstatic.com
+ytimg.com
+pubnub.a.ssl.fastly.net
+googleusercontent.com
+akamaihd.net
+pubnub.com
+stripe.com
+google.com
+humblebundle.com
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:26.0) Gecko/20100101 Firefox/26.0 SeaMonkey/2.23a2
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: Credit card stripe.com on Humblebundle blocked

Post by Thrawn »

And does anything appear in the Browser Console (Ctrl+Shift+J) when you do this?
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:25.0) Gecko/20100101 Firefox/25.0
ableeker

Re: Credit card stripe.com on Humblebundle blocked

Post by ableeker »

@therube That's a good start indeed, but that didn't work.

@Thrawn The console shows one interesting error:

Code: Select all

[Exception... "'NoScript aborted redirection to https://js.stripe.com/v1/' when calling method: [nsIChannelEventSink::asyncOnChannelRedirect]"  nsresult: "0x8057001e (NS_ERROR_XPC_JS_THREW_STRING)"  location: "native frame :: <unknown filename> :: <TOP_LEVEL> :: line 0"  data: no]
And after that I get a lot of these:

Code: Select all

https://humble.pubnub.com/subscribe/6b5eeae3-796b-11df-8b2d-ef048cc31d2e/humblewarnerbrothers%5Fbundle/0/13839017431273532?uuid=0e5fe0eb ... &pnsdk=PubNub-JS-Web%2F3%2E5%2E4 [HTTP/1.1 200 OK 4110ms]
It just keeps doing that, and the process keeps spinning.
Mozilla/5.0 (Windows NT 6.1; rv:25.0) Gecko/20100101 Firefox/25.0
User avatar
Giorgio Maone
Site Admin
Posts: 9557
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Credit card stripe.com on Humblebundle blocked

Post by Giorgio Maone »

Are you double sure stripe.com is whitelisted?
[Edit]
I could reproduce it, and seems a side effect of the way the stripe.com script is included, which causes the XSS filter trigger for a reflected script inclusion.
Investigating and looking for a work-around.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
User avatar
Giorgio Maone
Site Admin
Posts: 9557
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Credit card stripe.com on Humblebundle blocked

Post by Giorgio Maone »

Please check latest development build 2.6.8.5rc2, thank you.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
ableeker

Re: Credit card stripe.com on Humblebundle blocked

Post by ableeker »

Thanks man, that worked beautifully!
Mozilla/5.0 (Windows NT 6.1; rv:25.0) Gecko/20100101 Firefox/25.0
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: [FIXED] Credit card stripe.com on Humblebundle blocked

Post by Thrawn »

Giorgio, should something be said to the webmaster about their script inclusion methods, or were they simply unusual?
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:25.0) Gecko/20100101 Firefox/25.0
User avatar
Giorgio Maone
Site Admin
Posts: 9557
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: [FIXED] Credit card stripe.com on Humblebundle blocked

Post by Giorgio Maone »

Thrawn wrote:Giorgio, should something be said to the webmaster about their script inclusion methods, or were they simply unusual?
Cruel and unusual.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
Guest

Re: [FIXED] Credit card stripe.com on Humblebundle blocked

Post by Guest »

I am having trouble getting the Humble Bundle site to work properly also. I experimented allowing all scripts it shows on their page except twitter and facebook but it still doesn't work as it should. I can't select a custom amount, clicking the game images won't open their trailers and additional info, etc.

I have tried emailing them about it a couple of times but I am apparently not explaining my issue properly as they only say they will pass the info along.

Is this an issue on my end, though I have it on multiple computers (with NS and ABP on both so I figure it has something to do with one of them)? Any help is appreciated.

Their site used to work fine for me but they changed something a few months back and I have had issues ever since.
Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
Post Reply