XXS issue with medium.com I think.

Ask for help about NoScript, no registration needed to post
trinsic
Posts: 2
Joined: Wed Mar 01, 2017 10:49 am

XXS issue with medium.com I think.

Post by trinsic »

Hi, im trying to log into medium.com using firefox+noscript, but it keeps popping up an error stating that meidum.com cant login me in and that I need to enabled third party cookies. I didn't think this was correct so I looked at the server response headers. I couldnt paste the code, the spam filters didnt like it:
Image

It looks like its a cross site scripting issue. Medium.com probably authenticates cookies from another domain or something. The problem is I dont really know how to create an exception in the rules config and wanted to see if someone can point me in the right direction. Let me know if more information is needed.
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:51.0) Gecko/20100101 Firefox/51.0
barbaz
Senior Member
Posts: 11141
Joined: Sat Aug 03, 2013 5:45 pm

Re: XXS issue with medium.com I think.

Post by barbaz »

That's the Web Console, isn't it? When this issue occurs, do you see anything related in the Browser Console? (Ctrl-Shift-J)
(if you don't know what's related, turn off CSS warnings and post everything else you see)
*Always* check the changelogs BEFORE updating that important software!
-
trinsic
Posts: 2
Joined: Wed Mar 01, 2017 10:49 am

Re: XXS issue with medium.com I think.

Post by trinsic »

barbaz wrote:That's the Web Console, isn't it? When this issue occurs, do you see anything related in the Browser Console? (Ctrl-Shift-J)
(if you don't know what's related, turn off CSS warnings and post everything else you see)
Yes it is. No I dont see anything i the browser console.
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:51.0) Gecko/20100101 Firefox/51.0
barbaz
Senior Member
Posts: 11141
Joined: Sat Aug 03, 2013 5:45 pm

Re: XXS issue with medium.com I think.

Post by barbaz »

Does disabling NoScript (Tools > Add-ons Manager > NoScript > Disable > Yes, remove ALL protections) get it working?
*Always* check the changelogs BEFORE updating that important software!
-
Post Reply