eurobank e-banking

Ask for help about NoScript, no registration needed to post
maxer

eurobank e-banking

Post by maxer »

Can you please check this site?
https :// ebanking .eurobank.gr /ebanking/login.faces
Mozilla/5.0 (Windows NT 6.3; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
User avatar
therube
Ambassador
Posts: 7969
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: eurobank e-banking

Post by therube »

Why?
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:36.0) Gecko/20100101 SeaMonkey/2.33.1
barbaz
Senior Member
Posts: 11068
Joined: Sat Aug 03, 2013 5:45 pm

Re: eurobank e-banking

Post by barbaz »

Smells spammy to me...
Broke the link in any case.

@maxer: You have until tomorrow to clarify the issue, and if you do not do so satisfactorily we will delete this thread as spam.
*Always* check the changelogs BEFORE updating that important software!
-
maxer

Re: eurobank e-banking

Post by maxer »

Sorry not clear enough.

So, I disconnect from firefox sync, reset settings in noscript plugin and when I visit *only* the site above, it tries to open/save a part of script code I think.
If I disable the plugin, all is ok.

Could you help?
Thank you

PS: you souldn't trust your nose!
Mozilla/5.0 (Windows NT 5.1; rv:40.0) Gecko/20100101 Firefox/40.0
maxer

Re: eurobank e-banking

Post by maxer »

In addition the message:
Image

which of course shows up after I allow scripts in eurobank.gr
Mozilla/5.0 (Windows NT 5.1; rv:40.0) Gecko/20100101 Firefox/40.0
barbaz
Senior Member
Posts: 11068
Joined: Sat Aug 03, 2013 5:45 pm

Re: eurobank e-banking

Post by barbaz »

Hmm, that's weird. So if you Allow Scripts Globally does it also happen?
Any related messages in the Browser Console (Ctrl-Shift-J) when it happens?
maxer wrote:PS: you souldn't trust your nose!
Meh, stupid allergies have it all stuffed up & I can't tell what's what :roll: ;)
*Always* check the changelogs BEFORE updating that important software!
-
maxer

Re: eurobank e-banking

Post by maxer »

barbaz wrote:Hmm, that's weird. So if you Allow Scripts Globally does it also happen?
Yes, it happens.
Any related messages in the Browser Console (Ctrl-Shift-J) when it happens?
Not sure if it is what you need to see:

Code: Select all

[NoScript InjectionChecker] JavaScript Injection in qp=si=1&e=https://ebanking.eurobank.gr&LSESSIONID=jLd1o6Uf5YkncyaHKhIt3DwPqPuSpnzRU0G2EXavFtPX08UvPspx5MKlf26U3I4PREmdHKAvgBceKVibfg==&t=xpost&pd=d=JTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uc2NyaXB0JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmE0aiUyNTJGZyUyNTJGM18zXzMuRmluYWxvcmcuYWpheDRqc2YuamF2YXNjcmlwdC5BamF4U2NyaXB0LmZhY2VzJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIxJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmpzJTI1MkZqcXVlcnkuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmpxdWVyeS5jcnlwdG8uanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjMlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmJyb3dzZXJEZXRlY3QuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjQlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRnN3Zm9i
[NoScript XSS]: sanitized window.name, "qp=si%3D1%26e%3Dhttps%253A%252F%252Febanking.eurobank.gr%26LSESSIONID%3DjLd1o6Uf5YkncyaHKhIt3DwPqPuSpnzRU0G2EXavFtPX08UvPspx5MKlf26U3I4PREmdHKAvgBceKVibfg%253D%253D%26t%3Dxpost&pd=d%3DJTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uc2NyaXB0JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmE0aiUyNTJGZyUyNTJGM18zXzMuRmluYWxvcmcuYWpheDRqc2YuamF2YXNjcmlwdC5BamF4U2NyaXB0LmZhY2VzJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIxJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmpzJTI1MkZqcXVlcnkuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmpxdWVyeS5jcnlwdG8uanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjMlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmJyb3dzZXJEZXRlY3QuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjQlMjUyQyUyNTIyJTI1MkZlYmFua2lu
https://yhs.eurobank.gr/eurobankcache/sadf.html?
about:blank
SyntaxError: unreachable code after return statement jquery.js.faces:246:18
TypeError: q is null lastpass.js:1042:292
[NoScript InjectionChecker] JavaScript Injection in qp=si=1&e=https://ebanking.eurobank.gr&LSESSIONID=jLd1o6Uf5YkncyaHKhIt3DwPqPuSpnzRU0G2EXavFtPX08UvPspx5MKlf26U3I4PREmdHKAvgBceKVibfg==&t=xpost&pd=d=JTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uc2NyaXB0JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmE0aiUyNTJGZyUyNTJGM18zXzMuRmluYWxvcmcuYWpheDRqc2YuamF2YXNjcmlwdC5BamF4U2NyaXB0LmZhY2VzJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIxJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmpzJTI1MkZqcXVlcnkuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmpxdWVyeS5jcnlwdG8uanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjMlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmJyb3dzZXJEZXRlY3QuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjQlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRnN3Zm9i
[NoScript XSS]: sanitized window.name, "qp=si%3D1%26e%3Dhttps%253A%252F%252Febanking.eurobank.gr%26LSESSIONID%3DjLd1o6Uf5YkncyaHKhIt3DwPqPuSpnzRU0G2EXavFtPX08UvPspx5MKlf26U3I4PREmdHKAvgBceKVibfg%253D%253D%26t%3Dxpost&pd=d%3DJTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uc2NyaXB0JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmE0aiUyNTJGZyUyNTJGM18zXzMuRmluYWxvcmcuYWpheDRqc2YuamF2YXNjcmlwdC5BamF4U2NyaXB0LmZhY2VzJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIxJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmpzJTI1MkZqcXVlcnkuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmpxdWVyeS5jcnlwdG8uanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjMlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmJyb3dzZXJEZXRlY3QuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjQlMjUyQyUyNTIyJTI1MkZlYmFua2lu
https://yhs.eurobank.gr/eurobankcache/sadf.html?
javascript:%20false;
Using //@ to indicate sourceURL pragmas is deprecated. Use //# instead rs=AGLTcCO1-caRQi1vAcPxcufbx1g1JHQ13w:87:0
Using //@ to indicate sourceURL pragmas is deprecated. Use //# instead rs=AGLTcCO1-caRQi1vAcPxcufbx1g1JHQ13w:224:0
Using //@ to indicate sourceURL pragmas is deprecated. Use //# instead rs=AGLTcCO1-caRQi1vAcPxcufbx1g1JHQ13w:1387:0
[NoScript InjectionChecker] JavaScript Injection in qp=si=1&e=https://ebanking.eurobank.gr&LSESSIONID=jLd1pqMd54QvdCaHKh8q2D4NpPOSpnzRU0G2EXavFtPX08UvPspx5MKlf26U14kOQk+eGKAjjBQYKF6V&t=xpost&pd=d=JTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uc2NyaXB0JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmE0aiUyNTJGZyUyNTJGM18zXzMuRmluYWxvcmcuYWpheDRqc2YuamF2YXNjcmlwdC5BamF4U2NyaXB0LmZhY2VzJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIxJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmpzJTI1MkZqcXVlcnkuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmpxdWVyeS5jcnlwdG8uanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjMlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmJyb3dzZXJEZXRlY3QuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjQlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRnN3Zm9iamVj
[NoScript XSS]: sanitized window.name, "qp=si%3D1%26e%3Dhttps%253A%252F%252Febanking.eurobank.gr%26LSESSIONID%3DjLd1pqMd54QvdCaHKh8q2D4NpPOSpnzRU0G2EXavFtPX08UvPspx5MKlf26U14kOQk%252BeGKAjjBQYKF6V%26t%3Dxpost&pd=d%3DJTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uc2NyaXB0JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmE0aiUyNTJGZyUyNTJGM18zXzMuRmluYWxvcmcuYWpheDRqc2YuamF2YXNjcmlwdC5BamF4U2NyaXB0LmZhY2VzJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIxJTI1MkMlMjUyMiUyNTJGZWJhbmtpbmclMjUyRmpzJTI1MkZqcXVlcnkuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmpxdWVyeS5jcnlwdG8uanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjMlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJGanMlMjUyRmJyb3dzZXJEZXRlY3QuanMlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjQlMjUyQyUyNTIyJTI1MkZlYmFua2luZyUyNTJG
https://yhs.eurobank.gr/eurobankcache/sadf.html?
javascript:%20false;
TypeError: q is null lastpass.js:1042:292
TypeError: can't access dead object lastpass.js:1070:44

Thank you.
Mozilla/5.0 (Windows NT 6.3; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
gpap
Posts: 2
Joined: Tue Aug 25, 2015 8:43 am

Re: eurobank e-banking

Post by gpap »

Same here since yesterday
Part of the script

Code: Select all

javascript__(function(){function i(){if(typeof XMLHttpRequest!='undefined'){return new XMLHttpRequest()}try{return new ActiveXObject(_Msxml2.XMLHTTP_)}catch(e){try{return new ActiveXObject(_.join(_&_)}function k(a){var b={},c=(a
…
When Allow Globally the same
Only solution to disable
Mozilla/5.0 (Windows NT 5.1; rv:40.0) Gecko/20100101 Firefox/40.0
barbaz
Senior Member
Posts: 11068
Joined: Sat Aug 03, 2013 5:45 pm

Re: eurobank e-banking

Post by barbaz »

Please try disabling the XSS filter & see if that helps (note that this is *not* a solution, just a test!):
NoScript Options > Advanced > XSS, un-check both the checkboxes
*Always* check the changelogs BEFORE updating that important software!
-
gpap
Posts: 2
Joined: Tue Aug 25, 2015 8:43 am

Re: eurobank e-banking

Post by gpap »

YEP it works
disabling the XSS filter (both sanitizing & turn cross)
You can check it yourself, no need to login.
Just go to the welcome page, https://ebanking.eurobank.gr/ebanking/login.faces
there is a looong delay, browser freezes, cursor, tabs…
Mozilla/5.0 (Windows NT 5.1; rv:40.0) Gecko/20100101 Firefox/40.0
maxer

Re: eurobank e-banking

Post by maxer »

Disabling XSS filter works.
So, do we need to put an XSS exception for this site?
Mozilla/5.0 (Windows NT 6.0; rv:40.0) Gecko/20100101 Firefox/40.0
barbaz
Senior Member
Posts: 11068
Joined: Sat Aug 03, 2013 5:45 pm

Re: eurobank e-banking

Post by barbaz »

I'm really not sure what would be the actual solution here.

@Thrawn: any advice as to whether an XSS exception is safe, & if so what XSS exception to be made?
*Always* check the changelogs BEFORE updating that important software!
-
maxer

Re: eurobank e-banking

Post by maxer »

Till Thrawn's jump,

Code: Select all

^https://([a-z]+)\.eurobank\.gr/
is it ok as an exception? It seems to work.
Mozilla/5.0 (Windows NT 5.1; rv:40.0) Gecko/20100101 Firefox/40.0
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: eurobank e-banking

Post by Thrawn »

Eww, they're polluting window.name! Look at the second line of the console output.

This is *not* a safe practice. If you can leave the XSS filter on, then please do. Otherwise, maybe create a separate profile to do your banking, and don't visit any other sites in that profile.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:40.0) Gecko/20100101 Firefox/40.0
barbaz
Senior Member
Posts: 11068
Joined: Sat Aug 03, 2013 5:45 pm

Re: eurobank e-banking

Post by barbaz »

*If* an XSS exception is the way to go.
That one doesn't look safe to me - it's allowing *all* site to XSS eurobank. :o
However the regexp matching the address looks like the best that can be done.

Does this exception work?

Code: Select all

^@https://[a-z]+\.eurobank\.gr/
If so it's safer because rather than allowing all sites to XSS eurobank, it's allowing eurobank to XSS anything.

(I'd suggest removing the unneeded parentheses in any case.)


EDIT Again, note that an XSS exception may not be a good answer here - see Thrawn's post above which collided with mine.
*Always* check the changelogs BEFORE updating that important software!
-
Post Reply