UK Nationwide Logon Stalling FF 47.0.1

Ask for help about NoScript, no registration needed to post
NS001
Junior Member
Posts: 25
Joined: Fri Feb 08, 2013 2:14 pm

Re: UK Nationwide Logon Stalling FF 47.0.1

Post by NS001 »

Thrawn wrote:That's why we suggested using a separate profile. But yes, it's the bank's mistake.
Now this is confusing. I am using a seperate profile but as soon as I install NoScript and allow the website the problem occurs. Yes I could turn off the XSS feature and live happily ever after but I prefer to know what sites have XSS problems. Are you saying ABE is availabe outside of NoScript.
Mozilla/5.0 (Windows NT 6.2; WOW64; rv:47.0) Gecko/20100101 Firefox/47.0
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: UK Nationwide Logon Stalling FF 47.0.1

Post by Thrawn »

I'm saying that you could switch off the XSS filter in the bank-only profile, while using ABE to ensure that you can't open any other site. Feel free to periodically check on the bank in your regular profile to see whether they've picked up their game.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Linux i686; rv:38.9) Gecko/20100101 Goanna/2.0 Firefox/38.9 PaleMoon/26.1.1
NS001
Junior Member
Posts: 25
Joined: Fri Feb 08, 2013 2:14 pm

Re: UK Nationwide Logon Stalling FF 47.0.1

Post by NS001 »

Thrawn wrote:Feel free to periodically check on the bank in your regular profile to see whether they've picked up their game.
Thanks that works fine. Much better. Having got used to using the bank profile old habits die hard. What are the chances of a passive feature that indicates the site has an XSS liability? I think it will be more by accident that I try to logon to Nationwide under the other profile but it would amount to a periodic check. I'll have a play around with the ABE language. Perhaps the script you gave could be formally documented as an example of ABE coding?
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:47.0) Gecko/20100101 Firefox/47.0
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: UK Nationwide Logon Stalling FF 47.0.1

Post by Thrawn »

NS001 wrote:What are the chances of a passive feature that indicates the site has an XSS liability?
Low, bordering on nonexistent. The filter only fires on requests that look like actually XSS attempts. There isn't a reliable way to distinguish a real attack from a website design so poor that it looks like one.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:47.0) Gecko/20100101 Firefox/47.0
Post Reply