Seeing XSS Notifications on numerous sites since 2.9.0.5

Ask for help about NoScript, no registration needed to post
tmeader
Posts: 12
Joined: Fri Sep 17, 2010 3:49 pm

Seeing XSS Notifications on numerous sites since 2.9.0.5

Post by tmeader »

Wasn't having any issues before the update today. Running FF Beta 46.0 build 2. uBlockOrigin also installed. Again, no issues prior to update to 2.9.0.5. Here's some examples from the console:

Code: Select all

[NoScript XSS] Sanitized suspicious request. Original URL [https://www.youtube.com/subscribe_embed?usegapi=1&count=default&layout=default&channel=UPROXX&origin=http%3A%2F%2Fuproxx.com&gsrc=3p&ic=1&jsh=m%3B%2F_%2Fscs%2Fapps-static%2F_%2Fjs%2Fk%3Doz.gapi.en.cjMoLRgMYKE.O%2Fm%3D__features__%2Fam%3DEQ%2Frt%3Dj%2Fd%3D1%2Frs%3DAGLTcCPo7RshhNz0Dg58m_r6d7oaltVMmA#_methods=onPlusOne%2C_ready%2C_close%2C_open%2C_resizeMe%2C_renderstart%2Concircled%2Cdrefresh%2Cerefresh%2Conytevent%2Conload&id=I0_1458187334306&parent=http%3A%2F%2Fuproxx.com&pfname=&rpctoken=35265939] requested from [http://uproxx.com/]. Sanitized URL: [https://www.youtube.com/#2741171788249752785].

Code: Select all

[NoScript XSS] Sanitized suspicious request. Original URL [https://apis.google.com/u/0/se/0/_/+1/fastbutton?usegapi=1&size=small&origin=http%3A%2F%2Fcomicrack.cyolito.com&url=http%3A%2F%2Fcomicrack.cyolito.com%2F&gsrc=3p&ic=1&jsh=m%3B%2F_%2Fscs%2Fapps-static%2F_%2Fjs%2Fk%3Doz.gapi.en.cjMoLRgMYKE.O%2Fm%3D__features__%2Fam%3DEQ%2Frt%3Dj%2Fd%3D1%2Frs%3DAGLTcCPo7RshhNz0Dg58m_r6d7oaltVMmA#_methods=onPlusOne%2C_ready%2C_close%2C_open%2C_resizeMe%2C_renderstart%2Concircled%2Cdrefresh%2Cerefresh%2Conload&id=I0_1458187763998&parent=http%3A%2F%2Fcomicrack.cyolito.com&pfname=&rpctoken=88894699] requested from [http://comicrack.cyolito.com/]. Sanitized URL: [https://apis.google.com/#4417624034621248370].
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:46.0) Gecko/20100101 Firefox/46.0
ng4ever
Junior Member
Posts: 34
Joined: Sat Aug 15, 2015 8:35 am

Re: Seeing XSS Notifications on numerous sites since 2.9.0.5

Post by ng4ever »

Same issue here on some sites.
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
shayera

Re: Seeing XSS Notifications on numerous sites since 2.9.0.5

Post by shayera »

Yea, this just cost me 2 great tickets to a concert, when I came to the online payment, the faulty detection resulted in the payment processor barfing up a 'wrong merchant' error..
By the time I figured out I could use an 'unsafe reload'.. those tickets were gone.. I am not amused right now
This on a day where one of my regular news sites figured out a detection for uBlock, so you can imagine my fuse
is somewhat short already
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
ng4ever
Junior Member
Posts: 34
Joined: Sat Aug 15, 2015 8:35 am

Re: Seeing XSS Notifications on numerous sites since 2.9.0.5

Post by ng4ever »

The 2 sites it happen to me on so far is www.neowin.net and http://www.newegg.com/Product/Product.a ... 6819117369
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Seeing XSS Notifications on numerous sites since 2.9.0.5

Post by Giorgio Maone »

Please check latest development build 2.9.0.6rc1, thanks.
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
ng4ever
Junior Member
Posts: 34
Joined: Sat Aug 15, 2015 8:35 am

Re: Seeing XSS Notifications on numerous sites since 2.9.0.5

Post by ng4ever »

Giorgio Maone wrote:Please check latest development build 2.9.0.6rc1, thanks.
I tried but keep getting this error: The addon could not be downloaded because of connection failure.

:(
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
ng4ever
Junior Member
Posts: 34
Joined: Sat Aug 15, 2015 8:35 am

Re: Seeing XSS Notifications on numerous sites since 2.9.0.5

Post by ng4ever »

Ok never mind I had to manually download it for it to work.

Anyway that version fixes the XSS Notifications issue for me.
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
Post Reply