If I enable TimesPeople on my NYTimes.com account and follow someone, I get a large "[NoScript XSS]: sanitized window.name" entry in the error console when I am on the nytimes.com pages except when I am on "http://timespeople.nytimes.com/". I am not sure how to write an anti-xss exception rule. Note: if you don't follow anyone there isn't a problem. This should be reproducible but I can PM you the entire noscript xss entry from the error console if needed.
NoScript 1.9.5.6
NYTimes TimesPeople Vs. XSS
NYTimes TimesPeople Vs. XSS
Last edited by Jim Too on Mon Jul 06, 2009 4:09 pm, edited 1 time in total.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2a1pre) Gecko/20090706 Minefield/3.6a1pre
- Giorgio Maone
- Site Admin
- Posts: 9524
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: NYTimes TimesPeople Vs. XSS
Beside the console entry, have you got any other problem?
window.name sanitization is logged on the console for troubleshooting purposes, but it doesn't get notified because it usually cause no inconvenience to users.
window.name sanitization is logged on the console for troubleshooting purposes, but it doesn't get notified because it usually cause no inconvenience to users.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5 (.NET CLR 3.5.30729)
Re: NYTimes TimesPeople Vs. XSS
The feature doesn't work at all when XSS is enabled. The list of articles never appears (in fact the entire timespeople bar across the top of the page never fills). I looked at the error console to see if the reason it wasn't working was something being blocked which is when I found the noscript entry. When I disable XSS then feature works.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2a1pre) Gecko/20090706 Minefield/3.6a1pre
- Giorgio Maone
- Site Admin
- Posts: 9524
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: NYTimes TimesPeople Vs. XSS
OK, could you please show me the whole message?
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5 (.NET CLR 3.5.30729)
Re: NYTimes TimesPeople Vs. XSS
Error Console message sent via PM.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2a1pre) Gecko/20090706 Minefield/3.6a1pre
- Giorgio Maone
- Site Admin
- Posts: 9524
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: NYTimes TimesPeople Vs. XSS
OK, they're clearly crazy.
They're stuffing a lot of JSON data in window.name. I bet it's extremely vulnerable to XSS.
However I'll try to put a reasonable work-around in next dev build, stay tuned.
They're stuffing a lot of JSON data in window.name. I bet it's extremely vulnerable to XSS.
However I'll try to put a reasonable work-around in next dev build, stay tuned.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5 (.NET CLR 3.5.30729)
Re: NYTimes TimesPeople Vs. XSS
Thank you.
Jim
Jim
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2a1pre) Gecko/20090706 Minefield/3.6a1pre