Suggest adding XSS default rule

Ask for help about NoScript, no registration needed to post
Guest

Suggest adding XSS default rule

Post by Guest »

Suggest adding chrome://browser/content/browser.xul to allow Firefox search box to work when xss filtering turned on.
Mozilla/5.0 (Windows NT 6.1; rv:38.0) Gecko/20100101 Firefox/38.0
barbaz
Senior Member
Posts: 11142
Joined: Sat Aug 03, 2013 5:45 pm

Re: Suggest adding XSS default rule

Post by barbaz »

-1 to this request, too many problems with it.
It inhibits testing of XSS filter and may make false positives harder to spot. And it's actually

Code: Select all

^@chrome://browser/content/browser\.xul$
And for SeaMonkey it'd be

Code: Select all

^@chrome://navigator/content/navigator\.xul$
so you can't really have a set default, otherwise you're likely to be doing the dangerous thing of whitelisting a URL which by default points to nothing.


Can you post here the contents of the searchplugin's xml file as well as post the query that the XSS filter is messing with?
*Always* check the changelogs BEFORE updating that important software!
-
Post Reply