Re: Bug logging out of yahoo mail on Firefox 18.0.2
Posted: Fri Mar 01, 2013 7:07 am
NoScripters and WebSec nerds of all lands, unite!
https://forums.informaction.com/
Please note:ymu01 wrote:Just curious: Was the false positive mentioned in reference to the XSS notice on Yahoo Mail or in reference to XSS comments tripping the spam filter on the forum?
"Gecko" is Mozilla's name for the internal rendering engine (software) that powers the Firefox (and SeaMonkey) web browsers, so changes in the browsers would have no effect on how Giorgio chooses to configure the spam filter for his web site. The Yahoo XSS messages were the false positives referred to, caused by this change in the Fx/SM internals from Version 18 onward (past two months or so).Giorgio Maone wrote:These are false positive caused by a recent (Gecko >= 18) change in how the Function.prototype.toSource() method works (it doesn't normalize the source and strip out comments anymore).
I'm looking for work-arounds, thanks.