[RESOLVED] basecamphq.com xfer to 123.writeboard.com blocked
[RESOLVED] basecamphq.com xfer to 123.writeboard.com blocked
NoScript 2.6.9.10rc2
Browser is FireFox on Ubuntu
With NoScript enabled, I am unable to connect from
accountname.basecamphq.com to 123.writeboard.com
when I click on a Writeboards document link in Basecamphq.
I tried whitelisting both urls but I get stopped by a XSS warning and a password challenge.
How can I figure out what to whitelist if it is not obvious?
The error console messages are overwhelming - I see nothing obvious to help with a whitelist.
If I disable NoScript, I am able to make the Writeboard connection w/o delay.
Browser is FireFox on Ubuntu
With NoScript enabled, I am unable to connect from
accountname.basecamphq.com to 123.writeboard.com
when I click on a Writeboards document link in Basecamphq.
I tried whitelisting both urls but I get stopped by a XSS warning and a password challenge.
How can I figure out what to whitelist if it is not obvious?
The error console messages are overwhelming - I see nothing obvious to help with a whitelist.
If I disable NoScript, I am able to make the Writeboard connection w/o delay.
Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:19.0) Gecko/20100101 Firefox/19.0
Re: basecamphq.com xfer to 123.writeboard.com blocked
NoScript related messages sometimes go by REALLY fast in the Error Console due to tremendous numbers of CSS warnings so you may need to run a video capture of it with the Messages tab open while the XSS warning is triggering then attempt to type the results here afterwards...jwalling wrote:How can I figure out what to whitelist if it is not obvious?
The error console messages are overwhelming - I see nothing obvious to help with a whitelist.
(InjectionChecker messages can have a horribly long regexp after the word 'matches' which you can skip typing that if you want
Also XSS whitelists are regular expressions that get manually typed in @ NoScript Options > Advanced > XSS - so it's completely separate from normal whitelisting
*Always* check the changelogs BEFORE updating that important software!
Mozilla/5.0 (Windows NT 5.2; rv:33.0) Gecko/20100101 SeaMonkey/2.30
Re: basecamphq.com xfer to 123.writeboard.com blocked
I posted NoScript console messages here
https://titanpad.com/FvH1xv6Qw4
https://titanpad.com/FvH1xv6Qw4
Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:19.0) Gecko/20100101 Firefox/19.0
- Giorgio Maone
- Site Admin
- Posts: 9546
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: basecamphq.com xfer to 123.writeboard.com blocked
You can work around by adding this line to your NoScript Options|Advanced|XSS|Exceptions box:
[EDIT]: fixed the regular expression typo
Code: Select all
^https://\d+\.writeboard\.com/\w+/login$
Mozilla/5.0 (Windows NT 6.3; WOW64; rv:34.0) Gecko/20100101 Firefox/34.0
Re: basecamphq.com xfer to 123.writeboard.com blocked
When I added to the XSS Exception box
or added
All the other entries in the Exception box turned RED
These are the other entries
I assume RED means there is a problem
Nb: When I duplicated the last entry, it did not cause the other entries to turn RED.
Am I missing or misinterpreting something?
Code: Select all
^https://\d+\.writeboard\.com/\b+/login$Code: Select all
^https?://\d+\.writeboard\.com/\b+/login$
These are the other entries
Code: Select all
^https?://([a-z]+)\.google\.(?:[a-z]{1,3}\.)?[a-z]+/(?:search|custom|\1)\?
^https?://([a-z]*)\.?search\.yahoo\.com/search(?:\?|/\1\b)
^https?://[a-z]+\.wikipedia\.org/wiki/[^"<>\?%]+$
^https?://translate\.google\.com/translate_t[^"'<>\?%]+$Nb: When I duplicated the last entry, it did not cause the other entries to turn RED.
Am I missing or misinterpreting something?
Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:19.0) Gecko/20100101 Firefox/19.0
Re: basecamphq.com xfer to 123.writeboard.com blocked
RED means there's an invalid regex in XSS Exceptionsjwalling wrote:I assume RED means there is a problem
In this case, it's likely because
Code: Select all
\b+Try replacing '\b+' with
Code: Select all
[0-9A-Za-z]+*Always* check the changelogs BEFORE updating that important software!
Mozilla/5.0 (Windows NT 5.2; rv:33.0) Gecko/20100101 SeaMonkey/2.30
Re: basecamphq.com xfer to 123.writeboard.com blocked
Success!
basecamphq.com xfer to 123.writeboard.com worked
by adding this RegEx to XSS exceptions:
Thanks for quick responses.
basecamphq.com xfer to 123.writeboard.com worked
by adding this RegEx to XSS exceptions:
Code: Select all
^https?://\d+\.writeboard\.com/[0-9A-Za-z]+/login$Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:19.0) Gecko/20100101 Firefox/19.0
- Giorgio Maone
- Site Admin
- Posts: 9546
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: basecamphq.com xfer to 123.writeboard.com blocked
I meant \w+, sorry for the typobarbaz wrote:is not valid regular expression syntax...Code: Select all
\b+
Mozilla/5.0 (Windows NT 6.3; WOW64; rv:34.0) Gecko/20100101 Firefox/34.0