XSS from brightcove?

Ask for help about NoScript, no registration needed to post
User avatar
Lucas Malor
Senior Member
Posts: 71
Joined: Tue Nov 09, 2010 2:01 pm
Contact:

XSS from brightcove?

Post by Lucas Malor »

Code: Select all

Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at http://brightcove01.brightcove.com/24/1328010481001/201603/1915/4805143332001/1328010481001_4805143332001_s-41.ts?pubId=1328010481001&videoId=4805138839001. (Reason: CORS header 'Access-Control-Allow-Origin' missing).
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:41.0) Gecko/20100101 Firefox/41.0
barbaz
Senior Member
Posts: 11141
Joined: Sat Aug 03, 2013 5:45 pm

Re: XSS from brightcove?

Post by barbaz »

If you're using NoScript 2.9.0.5, there have been many threads here about XSS filter issues resulting since that update...

Does downgrading NoScript to 2.9.0.5rc2 make it work? (If so, this is a NoScript bug; I would recommend to downgrade to NoScript 2.9.0.4 until Giorgio fixes whatever bug(s) happened)
*Always* check the changelogs BEFORE updating that important software!
-
barbaz
Senior Member
Posts: 11141
Joined: Sat Aug 03, 2013 5:45 pm

Re: XSS from brightcove?

Post by barbaz »

Does NoScript 2.9.0.6 works again?
*Always* check the changelogs BEFORE updating that important software!
-
User avatar
Lucas Malor
Senior Member
Posts: 71
Joined: Tue Nov 09, 2010 2:01 pm
Contact:

Re: XSS from brightcove?

Post by Lucas Malor »

No more messages, but videos from the site Il Fatto Quotidiano does not work if NoScript is enabled:

http://tv.ilfattoquotidiano.it/2016/03/ ... ta/495784/
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:41.0) Gecko/20100101 Firefox/41.0
User avatar
Lucas Malor
Senior Member
Posts: 71
Joined: Tue Nov 09, 2010 2:01 pm
Contact:

Re: XSS from brightcove?

Post by Lucas Malor »

Excuse me, errata corrige: error log is printed in JS console, but no XSS dialog is displayed.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:41.0) Gecko/20100101 Firefox/41.0
User avatar
Giorgio Maone
Site Admin
Posts: 9546
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: XSS from brightcove?

Post by Giorgio Maone »

Lucas Malor wrote:No more messages, but videos from the site Il Fatto Quotidiano does not work if NoScript is enabled:

http://tv.ilfattoquotidiano.it/2016/03/ ... ta/495784/
I need to enable many things (mostly brightcove-related stuff), but it works for me on 2.6.0.9.
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
User avatar
Lucas Malor
Senior Member
Posts: 71
Joined: Tue Nov 09, 2010 2:01 pm
Contact:

Re: XSS from brightcove?

Post by Lucas Malor »

DO you mean 2.9.0.6?
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:41.0) Gecko/20100101 Firefox/41.0
User avatar
Giorgio Maone
Site Admin
Posts: 9546
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: XSS from brightcove?

Post by Giorgio Maone »

Lucas Malor wrote:DO you mean 2.9.0.6?
Yep
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
Post Reply