eurobank e-banking
eurobank e-banking
Can you please check this site?
https :// ebanking .eurobank.gr /ebanking/login.faces
https :// ebanking .eurobank.gr /ebanking/login.faces
Mozilla/5.0 (Windows NT 6.3; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
Re: eurobank e-banking
Why?
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:36.0) Gecko/20100101 SeaMonkey/2.33.1
Re: eurobank e-banking
Smells spammy to me...
Broke the link in any case.
@maxer: You have until tomorrow to clarify the issue, and if you do not do so satisfactorily we will delete this thread as spam.
Broke the link in any case.
@maxer: You have until tomorrow to clarify the issue, and if you do not do so satisfactorily we will delete this thread as spam.
*Always* check the changelogs BEFORE updating that important software!
-
Re: eurobank e-banking
Sorry not clear enough.
So, I disconnect from firefox sync, reset settings in noscript plugin and when I visit *only* the site above, it tries to open/save a part of script code I think.
If I disable the plugin, all is ok.
Could you help?
Thank you
PS: you souldn't trust your nose!
So, I disconnect from firefox sync, reset settings in noscript plugin and when I visit *only* the site above, it tries to open/save a part of script code I think.
If I disable the plugin, all is ok.
Could you help?
Thank you
PS: you souldn't trust your nose!
Mozilla/5.0 (Windows NT 5.1; rv:40.0) Gecko/20100101 Firefox/40.0
Re: eurobank e-banking
In addition the message:

which of course shows up after I allow scripts in eurobank.gr
which of course shows up after I allow scripts in eurobank.gr
Mozilla/5.0 (Windows NT 5.1; rv:40.0) Gecko/20100101 Firefox/40.0
Re: eurobank e-banking
Hmm, that's weird. So if you Allow Scripts Globally does it also happen?
Any related messages in the Browser Console (Ctrl-Shift-J) when it happens?

Any related messages in the Browser Console (Ctrl-Shift-J) when it happens?
Meh, stupid allergies have it all stuffed up & I can't tell what's whatmaxer wrote:PS: you souldn't trust your nose!


*Always* check the changelogs BEFORE updating that important software!
-
Re: eurobank e-banking
Yes, it happens.barbaz wrote:Hmm, that's weird. So if you Allow Scripts Globally does it also happen?
Not sure if it is what you need to see:Any related messages in the Browser Console (Ctrl-Shift-J) when it happens?
Code: Select all
[NoScript InjectionChecker] JavaScript Injection in qp=si=1&e=https://ebanking.eurobank.gr&LSESSIONID=jLd1o6Uf5YkncyaHKhIt3DwPqPuSpnzRU0G2EXavFtPX08UvPspx5MKlf26U3I4PREmdHKAvgBceKVibfg==&t=xpost&pd=d=JTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uc2NyaXB0JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmE0aiUyNTJGZyUyNTJGM18zXzMuRmluYWxvcmcuYWpheDRqc2YuamF2YXNjcmlwdC5BamF4U2NyaXB0LmZhY2VzJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIxJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmpzJTI1MkZqcXVlcnkuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmpxdWVyeS5jcnlwdG8uanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjMlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmJyb3dzZXJEZXRlY3QuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjQlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRnN3Zm9i
[NoScript XSS]: sanitized window.name, "qp=si%3D1%26e%3Dhttps%253A%252F%252Febanking.eurobank.gr%26LSESSIONID%3DjLd1o6Uf5YkncyaHKhIt3DwPqPuSpnzRU0G2EXavFtPX08UvPspx5MKlf26U3I4PREmdHKAvgBceKVibfg%253D%253D%26t%3Dxpost&pd=d%3DJTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uc2NyaXB0JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmE0aiUyNTJGZyUyNTJGM18zXzMuRmluYWxvcmcuYWpheDRqc2YuamF2YXNjcmlwdC5BamF4U2NyaXB0LmZhY2VzJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIxJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmpzJTI1MkZqcXVlcnkuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmpxdWVyeS5jcnlwdG8uanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjMlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmJyb3dzZXJEZXRlY3QuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjQlMjUyQyUyNTIyJTI1MkZlYmFua2lu
https://yhs.eurobank.gr/eurobankcache/sadf.html?
about:blank
SyntaxError: unreachable code after return statement jquery.js.faces:246:18
TypeError: q is null lastpass.js:1042:292
[NoScript InjectionChecker] JavaScript Injection in qp=si=1&e=https://ebanking.eurobank.gr&LSESSIONID=jLd1o6Uf5YkncyaHKhIt3DwPqPuSpnzRU0G2EXavFtPX08UvPspx5MKlf26U3I4PREmdHKAvgBceKVibfg==&t=xpost&pd=d=JTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uc2NyaXB0JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmE0aiUyNTJGZyUyNTJGM18zXzMuRmluYWxvcmcuYWpheDRqc2YuamF2YXNjcmlwdC5BamF4U2NyaXB0LmZhY2VzJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIxJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmpzJTI1MkZqcXVlcnkuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmpxdWVyeS5jcnlwdG8uanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjMlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmJyb3dzZXJEZXRlY3QuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjQlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRnN3Zm9i
[NoScript XSS]: sanitized window.name, "qp=si%3D1%26e%3Dhttps%253A%252F%252Febanking.eurobank.gr%26LSESSIONID%3DjLd1o6Uf5YkncyaHKhIt3DwPqPuSpnzRU0G2EXavFtPX08UvPspx5MKlf26U3I4PREmdHKAvgBceKVibfg%253D%253D%26t%3Dxpost&pd=d%3DJTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uc2NyaXB0JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmE0aiUyNTJGZyUyNTJGM18zXzMuRmluYWxvcmcuYWpheDRqc2YuamF2YXNjcmlwdC5BamF4U2NyaXB0LmZhY2VzJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIxJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmpzJTI1MkZqcXVlcnkuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmpxdWVyeS5jcnlwdG8uanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjMlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmJyb3dzZXJEZXRlY3QuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjQlMjUyQyUyNTIyJTI1MkZlYmFua2lu
https://yhs.eurobank.gr/eurobankcache/sadf.html?
javascript:%20false;
Using //@ to indicate sourceURL pragmas is deprecated. Use //# instead rs=AGLTcCO1-caRQi1vAcPxcufbx1g1JHQ13w:87:0
Using //@ to indicate sourceURL pragmas is deprecated. Use //# instead rs=AGLTcCO1-caRQi1vAcPxcufbx1g1JHQ13w:224:0
Using //@ to indicate sourceURL pragmas is deprecated. Use //# instead rs=AGLTcCO1-caRQi1vAcPxcufbx1g1JHQ13w:1387:0
[NoScript InjectionChecker] JavaScript Injection in qp=si=1&e=https://ebanking.eurobank.gr&LSESSIONID=jLd1pqMd54QvdCaHKh8q2D4NpPOSpnzRU0G2EXavFtPX08UvPspx5MKlf26U14kOQk+eGKAjjBQYKF6V&t=xpost&pd=d=JTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uc2NyaXB0JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmE0aiUyNTJGZyUyNTJGM18zXzMuRmluYWxvcmcuYWpheDRqc2YuamF2YXNjcmlwdC5BamF4U2NyaXB0LmZhY2VzJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIxJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmpzJTI1MkZqcXVlcnkuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmpxdWVyeS5jcnlwdG8uanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjMlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmJyb3dzZXJEZXRlY3QuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjQlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRnN3Zm9iamVj
[NoScript XSS]: sanitized window.name, "qp=si%3D1%26e%3Dhttps%253A%252F%252Febanking.eurobank.gr%26LSESSIONID%3DjLd1pqMd54QvdCaHKh8q2D4NpPOSpnzRU0G2EXavFtPX08UvPspx5MKlf26U14kOQk%252BeGKAjjBQYKF6V%26t%3Dxpost&pd=d%3DJTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uc2NyaXB0JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmE0aiUyNTJGZyUyNTJGM18zXzMuRmluYWxvcmcuYWpheDRqc2YuamF2YXNjcmlwdC5BamF4U2NyaXB0LmZhY2VzJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIxJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmpzJTI1MkZqcXVlcnkuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmpxdWVyeS5jcnlwdG8uanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjMlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmJyb3dzZXJEZXRlY3QuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjQlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJG
https://yhs.eurobank.gr/eurobankcache/sadf.html?
javascript:%20false;
TypeError: q is null lastpass.js:1042:292
TypeError: can't access dead object lastpass.js:1070:44
Mozilla/5.0 (Windows NT 6.3; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
Re: eurobank e-banking
Same here since yesterday
Part of the script
When Allow Globally the same
Only solution to disable
Part of the script
Code: Select all
javascript__(function(){function i(){if(typeof XMLHttpRequest!='undefined'){return new XMLHttpRequest()}try{return new ActiveXObject(_Msxml2.XMLHTTP_)}catch(e){try{return new ActiveXObject(_.join(_&_)}function k(a){var b={},c=(a
…
Only solution to disable
Mozilla/5.0 (Windows NT 5.1; rv:40.0) Gecko/20100101 Firefox/40.0
Re: eurobank e-banking
Please try disabling the XSS filter & see if that helps (note that this is *not* a solution, just a test!):
NoScript Options > Advanced > XSS, un-check both the checkboxes
NoScript Options > Advanced > XSS, un-check both the checkboxes
*Always* check the changelogs BEFORE updating that important software!
-
Re: eurobank e-banking
YEP it works
disabling the XSS filter (both sanitizing & turn cross)
You can check it yourself, no need to login.
Just go to the welcome page, https://ebanking.eurobank.gr/ebanking/login.faces
there is a looong delay, browser freezes, cursor, tabs…
disabling the XSS filter (both sanitizing & turn cross)
You can check it yourself, no need to login.
Just go to the welcome page, https://ebanking.eurobank.gr/ebanking/login.faces
there is a looong delay, browser freezes, cursor, tabs…
Mozilla/5.0 (Windows NT 5.1; rv:40.0) Gecko/20100101 Firefox/40.0
Re: eurobank e-banking
Disabling XSS filter works.
So, do we need to put an XSS exception for this site?
So, do we need to put an XSS exception for this site?
Mozilla/5.0 (Windows NT 6.0; rv:40.0) Gecko/20100101 Firefox/40.0
Re: eurobank e-banking
I'm really not sure what would be the actual solution here.
@Thrawn: any advice as to whether an XSS exception is safe, & if so what XSS exception to be made?
@Thrawn: any advice as to whether an XSS exception is safe, & if so what XSS exception to be made?
*Always* check the changelogs BEFORE updating that important software!
-
Re: eurobank e-banking
Till Thrawn's jump,
is it ok as an exception? It seems to work.
Code: Select all
^https://([a-z]+)\.eurobank\.gr/
Mozilla/5.0 (Windows NT 5.1; rv:40.0) Gecko/20100101 Firefox/40.0
Re: eurobank e-banking
Eww, they're polluting window.name! Look at the second line of the console output.
This is *not* a safe practice. If you can leave the XSS filter on, then please do. Otherwise, maybe create a separate profile to do your banking, and don't visit any other sites in that profile.
This is *not* a safe practice. If you can leave the XSS filter on, then please do. Otherwise, maybe create a separate profile to do your banking, and don't visit any other sites in that profile.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:40.0) Gecko/20100101 Firefox/40.0
Re: eurobank e-banking
*If* an XSS exception is the way to go.
That one doesn't look safe to me - it's allowing *all* site to XSS eurobank.
However the regexp matching the address looks like the best that can be done.
Does this exception work?
If so it's safer because rather than allowing all sites to XSS eurobank, it's allowing eurobank to XSS anything.
(I'd suggest removing the unneeded parentheses in any case.)
EDIT Again, note that an XSS exception may not be a good answer here - see Thrawn's post above which collided with mine.
That one doesn't look safe to me - it's allowing *all* site to XSS eurobank.

However the regexp matching the address looks like the best that can be done.
Does this exception work?
Code: Select all
^@https://[a-z]+\.eurobank\.gr/
(I'd suggest removing the unneeded parentheses in any case.)
EDIT Again, note that an XSS exception may not be a good answer here - see Thrawn's post above which collided with mine.
*Always* check the changelogs BEFORE updating that important software!
-