Information on ES6 attacks thwarted by NoScript 2.6.9.13

Ask for help about NoScript, no registration needed to post
bgmnt
Junior Member
Posts: 47
Joined: Sun Nov 17, 2013 3:41 pm

Information on ES6 attacks thwarted by NoScript 2.6.9.13

Post by bgmnt »

Hi,

In the changelog there is:
x [XSS] Better protection against some ES6 attacks (thanks Masato Kinugawa for reporting)
I'm curious, which attacks did ES6 enabled that NoScript had to be tweaked to protect against ?

Thanks
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Information on ES6 attacks thwarted by NoScript 2.6.9.13

Post by Giorgio Maone »

One using a funny combo of string interpolation (a new, very tricky ES6 feature) and nested comments.
I'll leave to Masato publishing the gory details.
Mozilla/5.0 (Windows NT 6.3; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
bgmnt
Junior Member
Posts: 47
Joined: Sun Nov 17, 2013 3:41 pm

Re: Information on ES6 attacks thwarted by NoScript 2.6.9.13

Post by bgmnt »

Ok thanks, I'll see if he publishes something in English :)

For anyone interested in new threats posed by ES6, I found this. A vulnerability with NoScript XSS protection was even found and quickly fixed. It's interesting to see that ES6 features can take even NoScript off guard, but of course there needs to be a whitelisted site involved for attackers to have a chance to run anything ES6.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
Post Reply