NYTimes TimesPeople Vs. XSS

Ask for help about NoScript, no registration needed to post
Jim Too
Senior Member
Posts: 58
Joined: Mon Mar 23, 2009 4:30 pm

NYTimes TimesPeople Vs. XSS

Post by Jim Too »

If I enable TimesPeople on my NYTimes.com account and follow someone, I get a large "[NoScript XSS]: sanitized window.name" entry in the error console when I am on the nytimes.com pages except when I am on "http://timespeople.nytimes.com/". I am not sure how to write an anti-xss exception rule. Note: if you don't follow anyone there isn't a problem. This should be reproducible but I can PM you the entire noscript xss entry from the error console if needed.

NoScript 1.9.5.6
Last edited by Jim Too on Mon Jul 06, 2009 4:09 pm, edited 1 time in total.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2a1pre) Gecko/20090706 Minefield/3.6a1pre
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: NYTimes TimesPeople Vs. XSS

Post by Giorgio Maone »

Beside the console entry, have you got any other problem?
window.name sanitization is logged on the console for troubleshooting purposes, but it doesn't get notified because it usually cause no inconvenience to users.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5 (.NET CLR 3.5.30729)
Jim Too
Senior Member
Posts: 58
Joined: Mon Mar 23, 2009 4:30 pm

Re: NYTimes TimesPeople Vs. XSS

Post by Jim Too »

The feature doesn't work at all when XSS is enabled. The list of articles never appears (in fact the entire timespeople bar across the top of the page never fills). I looked at the error console to see if the reason it wasn't working was something being blocked which is when I found the noscript entry. When I disable XSS then feature works.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2a1pre) Gecko/20090706 Minefield/3.6a1pre
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: NYTimes TimesPeople Vs. XSS

Post by Giorgio Maone »

OK, could you please show me the whole message?
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5 (.NET CLR 3.5.30729)
Jim Too
Senior Member
Posts: 58
Joined: Mon Mar 23, 2009 4:30 pm

Re: NYTimes TimesPeople Vs. XSS

Post by Jim Too »

Error Console message sent via PM.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2a1pre) Gecko/20090706 Minefield/3.6a1pre
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: NYTimes TimesPeople Vs. XSS

Post by Giorgio Maone »

OK, they're clearly crazy.
They're stuffing a lot of JSON data in window.name. I bet it's extremely vulnerable to XSS.
However I'll try to put a reasonable work-around in next dev build, stay tuned.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5 (.NET CLR 3.5.30729)
Jim Too
Senior Member
Posts: 58
Joined: Mon Mar 23, 2009 4:30 pm

Re: NYTimes TimesPeople Vs. XSS

Post by Jim Too »

Thank you.
Jim
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2a1pre) Gecko/20090706 Minefield/3.6a1pre
Post Reply