XSS protection on tinypic.com
-
NJNP
XSS protection on tinypic.com
I'm having problems trying to upload pictures to tinypic.com. The normal upload uses a captcha which refuses to load for me at all. I don't know which of my plugins is blocking it (I run a bunch: Privacy Badger, Priv3, et al.), but I used to get around it with a Greasemonkey script which allows me to use a plugin upload mode which bypasses the captcha. Unfortunately NoScript has started blocking my picture uploads as malicious XSS (it seems to be freaked out about plugin.tinyscript.com) and I can't convince NoScript to stop blocking it with anything short of a full uninstall. Any suggestions?
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:53.0) Gecko/20100101 Firefox/53.0
-
Guest
Re: XSS protection on tinypic.com
This is what I get from the console:
[NoScript InjectionChecker] JavaScript Injection in ##OÅQA¶9æc\éöÌpNÒõ@ÛÒ½òºÆCÁe¨\bWõ7_îÔì[Ä9£ðv1
[NoScript XSS] Sanitized suspicious upload to [http://s9.tinypic.com/upload.php###DATA ... ¨\bWõ7_îÔì[Ä9£ðv1] from [http://tinypic.com/]: transformed into a download-only GET request.
[NoScript InjectionChecker] JavaScript Injection in ##OÅQA¶9æc\éöÌpNÒõ@ÛÒ½òºÆCÁe¨\bWõ7_îÔì[Ä9£ðv1
[NoScript XSS] Sanitized suspicious upload to [http://s9.tinypic.com/upload.php###DATA ... ¨\bWõ7_îÔì[Ä9£ðv1] from [http://tinypic.com/]: transformed into a download-only GET request.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:53.0) Gecko/20100101 Firefox/53.0
Re: XSS protection on tinypic.com
I have no idea what NoScript sees in that jumbled mess.
While waiting for someone to give some insight, please try adding this XSS exception in NoScript Options > Advanced > XSS > Anti-XSS Protection Exceptions
Does it help?
Do note that I really have no idea how safe the exception is. In suggesting the exception I'm assuming that the upload data NoScript doesn't like is part of an image from your own computer and is therefore probably OK.
While waiting for someone to give some insight, please try adding this XSS exception in NoScript Options > Advanced > XSS > Anti-XSS Protection Exceptions
Code: Select all
^https?://s\d+\.tinypic\.com/upload\.phpDo note that I really have no idea how safe the exception is. In suggesting the exception I'm assuming that the upload data NoScript doesn't like is part of an image from your own computer and is therefore probably OK.
*Always* check the changelogs BEFORE updating that important software!
-
-
NJNP
Re: XSS protection on tinypic.com
Okay, that did... something.
Instead of giving me a ribbon warning that NoScript had blocked an XSS attempt, I just get a message from Tinypic that the upload failed. But if I turn off the "sanitize" and "turn cross-site" box options off, the upload works, which it didn't before I added your recipe.
Instead of giving me a ribbon warning that NoScript had blocked an XSS attempt, I just get a message from Tinypic that the upload failed. But if I turn off the "sanitize" and "turn cross-site" box options off, the upload works, which it didn't before I added your recipe.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:53.0) Gecko/20100101 Firefox/53.0
Re: XSS protection on tinypic.com
Hmm. With the exception in place and the two boxes checked, do you get any different message from NoScript in the Browser Console (Ctrl-Shift-J)?
*Always* check the changelogs BEFORE updating that important software!
-