I have NS 2.6.9.10 and ABP 2.6.6.
Everytime I search for __attribute__((noreturn)) with DuckDuckGo, I get this message:
NoScript filtered a potential XSS attempt from chrome. Technical details have been logged to the console.
And there is this in the console:
Use of getPreventDefault() is deprecated. Use defaultPrevented instead. d1718.js:26
The full link to the script is https://duckduckgo.com/d1718.js
The URL of the results page for this specific search query looks different: https://duckduckgo.com/?q=__attribute__ ... 1799896759
False positive or real threat?
XSS attempt at duckduckgo.com?
-
Ken
XSS attempt at duckduckgo.com?
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:34.0) Gecko/20100101 Firefox/34.0
Re: XSS attempt at duckduckgo.com?
(apologies for any typos, the only way I could look at these was by doing a video capture of the Error Console)
Probably a false positive since *you* thought of and typed the offending string...
(for reference, this isn't the first time user-initiated DuckDuckGo searches have tripped the XSS filter, see viewtopic.php?f=7&t=20141 )
Code: Select all
[NoScript InjectionChecker] JavaScript Injection in ///?q=__attribute__((noreturn))
(function anonymous() {
q=__attribute__((noreturn)) /* COMMENT_TERMINATOR */
DUMMY_EXPR
})
[NoScript XSS] Sanitized suspicious request. Original URL [https://duckduckgo.com/?q=__attribute__%28%28noreturn%29%29] requested from [chrome://navigator/content/navigator.xul]. Sanitized URL: [https://duckduckgo.com/?q=__attribute__%20%20noreturn%20%20#35913664713152404730].(for reference, this isn't the first time user-initiated DuckDuckGo searches have tripped the XSS filter, see viewtopic.php?f=7&t=20141 )
*Always* check the changelogs BEFORE updating that important software!
Mozilla/5.0 (ABE, https://noscript.net/abe/wan)
Re: XSS attempt at duckduckgo.com?
Bear in mind that NoScript filters the request, without being able to tell what the resulting page will actually do with it. It's very likely that DuckDuckGo does proper sanitisation of their search queries.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Dillo/3.0.3