Now this is confusing. I am using a seperate profile but as soon as I install NoScript and allow the website the problem occurs. Yes I could turn off the XSS feature and live happily ever after but I prefer to know what sites have XSS problems. Are you saying ABE is availabe outside of NoScript.Thrawn wrote:That's why we suggested using a separate profile. But yes, it's the bank's mistake.
UK Nationwide Logon Stalling FF 47.0.1
Re: UK Nationwide Logon Stalling FF 47.0.1
Mozilla/5.0 (Windows NT 6.2; WOW64; rv:47.0) Gecko/20100101 Firefox/47.0
Re: UK Nationwide Logon Stalling FF 47.0.1
I'm saying that you could switch off the XSS filter in the bank-only profile, while using ABE to ensure that you can't open any other site. Feel free to periodically check on the bank in your regular profile to see whether they've picked up their game.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Linux i686; rv:38.9) Gecko/20100101 Goanna/2.0 Firefox/38.9 PaleMoon/26.1.1
Re: UK Nationwide Logon Stalling FF 47.0.1
Thanks that works fine. Much better. Having got used to using the bank profile old habits die hard. What are the chances of a passive feature that indicates the site has an XSS liability? I think it will be more by accident that I try to logon to Nationwide under the other profile but it would amount to a periodic check. I'll have a play around with the ABE language. Perhaps the script you gave could be formally documented as an example of ABE coding?Thrawn wrote:Feel free to periodically check on the bank in your regular profile to see whether they've picked up their game.
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:47.0) Gecko/20100101 Firefox/47.0
Re: UK Nationwide Logon Stalling FF 47.0.1
Low, bordering on nonexistent. The filter only fires on requests that look like actually XSS attempts. There isn't a reliable way to distinguish a real attack from a website design so poor that it looks like one.NS001 wrote:What are the chances of a passive feature that indicates the site has an XSS liability?
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:47.0) Gecko/20100101 Firefox/47.0