NoScript XSS attack aliexpress.com

Ask for help about NoScript, no registration needed to post
Hobbix
Posts: 7
Joined: Tue Jan 24, 2017 5:20 am

NoScript XSS attack aliexpress.com

Post by Hobbix »

Site: aliexpress.com
When choosing any product, I get an XSS attack.

Screenshot
Image
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:54.0) Gecko/20100101 Firefox/54.0
barbaz
Senior Member
Posts: 11140
Joined: Sat Aug 03, 2013 5:45 pm

Re: NoScript XSS attack aliexpress.com

Post by barbaz »

It's facebook tracking tripping the XSS filter. What's your question?
*Always* check the changelogs BEFORE updating that important software!
-
Hobbix
Posts: 7
Joined: Tue Jan 24, 2017 5:20 am

Re: NoScript XSS attack aliexpress.com

Post by Hobbix »

How can I disable this warning on this site?
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:54.0) Gecko/20100101 Firefox/54.0
barbaz
Senior Member
Posts: 11140
Joined: Sat Aug 03, 2013 5:45 pm

Re: NoScript XSS attack aliexpress.com

Post by barbaz »

Does it go away if you block scripts for all facebook related domains?
*Always* check the changelogs BEFORE updating that important software!
-
Hobbix
Posts: 7
Joined: Tue Jan 24, 2017 5:20 am

Re: NoScript XSS attack aliexpress.com

Post by Hobbix »

barbaz wrote:Does it go away if you block scripts for all facebook related domains?
Yes. When I blocked the facebook.net domain in Noscript, the XSS attack message does not appear.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:54.0) Gecko/20100101 Firefox/54.0
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: NoScript XSS attack aliexpress.com

Post by Thrawn »

That's probably your best choice, then. Just mark facebook.net as Untrusted.

If you find that you really need to allow facebook.net sometimes, then we can help you write an ABE rule for that.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:45.0) Gecko/20100101 Firefox/45.0
Hobbix
Posts: 7
Joined: Tue Jan 24, 2017 5:20 am

Re: NoScript XSS attack aliexpress.com

Post by Hobbix »

Thrawn wrote:then we can help you write an ABE rule for that.
Please help me write a rule for ABE.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:54.0) Gecko/20100101 Firefox/54.0
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: NoScript XSS attack aliexpress.com

Post by Thrawn »

Probably something like this:

Code: Select all

Site .facebook.net
Anon from .aliexpress.com
Deny INC
Then whitelist facebook.net

Which site is giving you trouble when Facebook is blocked?
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:45.0) Gecko/20100101 Firefox/45.0
Post Reply