Not blocking some scripts?

General discussion about the NoScript extension for Firefox
Post Reply
Ron85
Posts: 4
Joined: Sun Feb 22, 2015 4:33 pm

Not blocking some scripts?

Post by Ron85 »

I have installed the Lightbeam ad-on on Firefox, which gives you a visual graphic of all sites you visit with the scrips that are allowed. With this ad-on I can see if NoScipt is properly working. I have noticed that some scripts are being allowed even if I don't allow them. As an example, when I visit businessinsider.con I noticed that a gravitar script was allowed even though I didn't give it permission. I have also noticed that sometimes doubleclick is allowed. Any suggestions for preventing this?
Mozilla/5.0 (Windows NT 6.3; WOW64; rv:34.0) Gecko/20100101 Firefox/34.0
barbaz
Senior Member
Posts: 11066
Joined: Sat Aug 03, 2013 5:45 pm

Re: Not blocking some scripts?

Post by barbaz »

What makes you think that's scripts and not other, non-active content (e.g. static images)?
*Always* check the changelogs BEFORE updating that important software!
-
Ron85
Posts: 4
Joined: Sun Feb 22, 2015 4:33 pm

Re: Not blocking some scripts?

Post by Ron85 »

It shows up on untrusted list and I haven't allowed it so why should NoScript allow it?
Mozilla/5.0 (Windows NT 6.3; WOW64; rv:34.0) Gecko/20100101 Firefox/34.0
barbaz
Senior Member
Posts: 11066
Joined: Sat Aug 03, 2013 5:45 pm

Re: Not blocking some scripts?

Post by barbaz »

I can't help you if you don't answer my questions.

NoScript doesn't normally block things that aren't a security threat, such as static images. Even if you mark a site as Untrusted in NoScript you can still visit it and also images from there will still load.

Or it's possible Lightbeam is logging loads before NoScript intercepts them...

Please open the Browser Console (Ctrl-Shift-J), clear it, make sure Net logging is enabled, then go to a site where you think NoScript isn't blocking all scripts, and post here all the entries for the requests that you think shouldn't be happening (if any).
*Always* check the changelogs BEFORE updating that important software!
-
Ron85
Posts: 4
Joined: Sun Feb 22, 2015 4:33 pm

Re: Not blocking some scripts?

Post by Ron85 »

OK, I did what you suggested. The website that I visited is motortrend.com. Lightbridge shows that a doubleclick script is linked to motortrend.com. I can see doubleclick.net in NoScripts Untrusted Listing and I have not allowed it yet it shows up on Lightbridge and the Browser console. The line showing it is:

GET http://ad.doubleclick.net/ad/motortrend ... ogo;sz=1x1 [HTTP/1.1 200 OK 198ms]

It appears to be getting an ad?

Thanks of your help.
Mozilla/5.0 (Windows NT 6.3; WOW64; rv:34.0) Gecko/20100101 Firefox/34.0
barbaz
Senior Member
Posts: 11066
Joined: Sat Aug 03, 2013 5:45 pm

Re: Not blocking some scripts?

Post by barbaz »

The board cut off the URL, please edit your post, wrap the log line in [ code ] tags or check "Do not automatically parse URLs", thanks

Code: Select all

[code]log here
[/code]
*Always* check the changelogs BEFORE updating that important software!
-
barbaz
Senior Member
Posts: 11066
Joined: Sat Aug 03, 2013 5:45 pm

Re: Not blocking some scripts?

Post by barbaz »

OK hold on, something at least similar is visible without any scripts enabled.
Is this it?

Code: Select all

http://ad.doubleclick.net/ad/motortrend.primedia.com/;k=mobil1_mt_bdc_logo;sz=1x1
If so, that's an image. So NoScript won't block it by default.
*Always* check the changelogs BEFORE updating that important software!
-
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: Not blocking some scripts?

Post by Thrawn »

Remember, NoScript is about security. Privacy is a side benefit. Images are not typically a security threat, so NoScript ignores them.

There are lots of adblocking/privacy tools if you want them (Adblock Plus and its various forks, Disconnect, TACO, Ghostery, etc).
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:35.0) Gecko/20100101 Firefox/35.0
Ron85
Posts: 4
Joined: Sun Feb 22, 2015 4:33 pm

Re: Not blocking some scripts?

Post by Ron85 »

OK, tanks to everyone who commented. I guess I was concerned because Doubleclick showed up as a script in the untrusted area and showed up in Lightbeam. So I assumed that it was a script that got through.
Mozilla/5.0 (Windows NT 6.3; WOW64; rv:34.0) Gecko/20100101 Firefox/34.0
PristineVisitor
Posts: 8
Joined: Tue Jan 27, 2015 9:52 pm

Re: Not blocking some scripts?

Post by PristineVisitor »

For people who are paranoid and are also masochistic, (hey, how's it going) I would recommend HttpRequest Policy or Policeman in combination with NoScript.

Http Request policy and it's (hopefully more modern alternative Policeman) basically prevent the loading of any/all 3rd party resources from dis-allowed 3rd party websites. They quite effectively block pixel tracking because these are almost always on 3rd party websites.

However it can basically be 2x the work unless you are willing to "trust" certain things.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
Post Reply