[RESOLVED] email.t-online.de / magentacloud.de (WebMail)

Ask for help about NoScript, no registration needed to post
Manu1991

[RESOLVED] email.t-online.de / magentacloud.de (WebMail)

Post by Manu1991 »

With the new V. 5.0.8.1 I now have an XSS warning with my webmail account:

I use FF 52.2, and when I log into the cloud storage service https://magentacloud.de and then try to switch to webmail https://email.t-online.de (via click on the "E-Mail" button), I always get an XSS warning.

Until V. 5.0.7.1 everything was fine.
Mozilla/5.0 (X11; Linux i686; rv:52.0) Gecko/20100101 Firefox/52.0
barbaz
Senior Member
Posts: 11140
Joined: Sat Aug 03, 2013 5:45 pm

Re: email.t-online.de / magentacloud.de (WebMail)

Post by barbaz »

Please check the Browser Console (Ctrl-Shift-J) when this issue happens and post here any messages related to NoScript.
(related messages usually start with either "[NoScript" or "[ABE]"; if you don't know what's related, turn off CSS warnings and post everything else you see)
*Always* check the changelogs BEFORE updating that important software!
-
Manu1991

Re[2]: email.t-online.de / magentacloud.de (WebMail)

Post by Manu1991 »

I got two similar messages at once in the browser's console (FF 52.2):

[NoScript XSS] Eine verdächtige Anfrage wurde bereinigt. Original-URL [https://accounts.login.idm.telekom.com/ ... null%7D%7D] angefordert von [chrome://browser/content/browser.xul]. Bereinigte URL: [https://accounts.login.idm.telekom.com/ ... 3378161526].
[NoScript XSS] Eine verdächtige Anfrage wurde bereinigt. Original-URL [https://accounts.login.idm.telekom.com/ ... null%7D%7D] angefordert von [chrome://browser/content/browser.xul]. Bereinigte URL: [https://accounts.login.idm.telekom.com/ ... 8004002464].
Mozilla/5.0 (X11; Linux i686; rv:52.0) Gecko/20100101 Firefox/52.0
barbaz
Senior Member
Posts: 11140
Joined: Sat Aug 03, 2013 5:45 pm

Re: email.t-online.de / magentacloud.de (WebMail)

Post by barbaz »

NoScript Options > Advanced > XSS, try adding this exception -

Code: Select all

^https://accounts\.login\.idm\.telekom\.com/oic\?
*Always* check the changelogs BEFORE updating that important software!
-
Manu1991

Re[4]: email.t-online.de / magentacloud.de (WebMail)

Post by Manu1991 »

Okay, thanks for your help! :-)

In general, I don't like adding exceptions. ;-) Especially when it worked before for years (up to and including V. 5.0.7.1).

I can also do an insecure reload/refresh to get to the desired page. That also works for me.
Mozilla/5.0 (X11; Linux i686; rv:52.0) Gecko/20100101 Firefox/52.0
chrisgruen

Re: email.t-online.de / magentacloud.de (WebMail)

Post by chrisgruen »

Hello,

I have the same error, and I also allow "insecure reload", but it needs many clicks, I don't want it.

Unfortunately the exception "^https://accounts\.login\.idm\.telekom\.com/oic\?" doesn't work.

I tried it with an old FF version (portable) with Noscript 2...., there is no problem with my emailaccount.
The error appeared with update to 5.8.01., I hope, this will be fixed.
Mozilla/5.0 (Windows NT 10.0; rv:54.0) Gecko/20100101 Firefox/54.0
barbaz
Senior Member
Posts: 11140
Joined: Sat Aug 03, 2013 5:45 pm

Re: email.t-online.de / magentacloud.de (WebMail)

Post by barbaz »

As above, please post the messages from the Browser Console (Ctrl-Shift-J) when the issue occurs.
*Always* check the changelogs BEFORE updating that important software!
-
Guest

Re: email.t-online.de / magentacloud.de (WebMail)

Post by Guest »

Apparently I have made a mistake the first time.
The exception rule is working.
Thanks for help.
Mozilla/5.0 (Windows NT 10.0; rv:54.0) Gecko/20100101 Firefox/54.0
Post Reply