Noscript won't block embeddings

Ask for help about NoScript, no registration needed to post
plingpling

Noscript won't block embeddings

Post by plingpling »

Hello,

When I set the "Allow scripts globally (dangerous)" option, FLASH and Java works on every site even though they are blocked in the embeddings tab. If I unset this option, nothing works including Javascript, as intended. What I want to do is to allow Javascript only, and block Java etc. Can I do this?

Thanks...
Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:18.0) Gecko/20100101 Firefox/18.0
User avatar
therube
Ambassador
Posts: 7991
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: Noscript won't block embeddings

Post by therube »

Is Apply these restrictions to whitelisted sites too also enabled?
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:20.0) Gecko/20100101 SeaMonkey/2.17a2
plingpling

Re: Noscript won't block embeddings

Post by plingpling »

No it's not. Should it be?
Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:18.0) Gecko/20100101 Firefox/18.0
User avatar
therube
Ambassador
Posts: 7991
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: Noscript won't block embeddings

Post by therube »

If you have Allowed Scripts Globally then you have effectively whitelisted sites too, so yes, you'll need to enable that option.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:20.0) Gecko/20100101 SeaMonkey/2.17a2
plingpling

Re: Noscript won't block embeddings

Post by plingpling »

therube wrote:If you have Allowed Scripts Globally then you have effectively whitelisted sites too, so yes, you'll need to enable that option.
Thanks therube, but then I can't use objects on trusted sites as well. I want to allow Javascript on all sites, and allow embedded objects only on whitelisted sites.
Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:18.0) Gecko/20100101 Firefox/18.0
Tom T.
Field Marshal
Posts: 3620
Joined: Fri Mar 20, 2009 6:58 am

Re: Noscript won't block embeddings

Post by Tom T. »

plingpling wrote:I want to allow Javascript on all sites, and allow embedded objects only on whitelisted sites.
If you allow Javascript on all sites, then you have in fact whitelisted all sites.

If you want to create whitelists for specific plugins at specific sites, please go to NoScript "Features" Page and search for "mime". This will require some knowledge of regular expressions, but we can help if the FAQ and other resources don't do the job for you.
Mozilla/5.0 (Windows NT 5.1; rv:18.0) Gecko/20100101 Firefox/18.0.2
plingpling

Re: Noscript won't block embeddings

Post by plingpling »

Hi Tom,

I see, I can use that feature.

Also it would be nice if we could do this through the GUI, which shouldn't be so hard I think, you just need to make "Allow scripts globally" allow only javascript, and allow objects by whitelisting pages. Otherwise this option is misleading, for that it makes you think you're just allowing javascript, but actually you're allowing all potentially harmful objects too.

Thanks...
Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:18.0) Gecko/20100101 Firefox/18.0
Tom T.
Field Marshal
Posts: 3620
Joined: Fri Mar 20, 2009 6:58 am

Re: Noscript won't block embeddings

Post by Tom T. »

plingpling wrote:Also it would be nice if we could do this through the GUI...
You can. http://noscript.net/faq#qa1_12
which shouldn't be so hard I think, you just need to make "Allow scripts globally" allow only javascript, and allow objects by whitelisting pages. Otherwise this option is misleading, for that it makes you think you're just allowing javascript, but actually you're allowing all potentially harmful objects too.
Which is why there is the option to "Apply these restrictions to whitelisted sites too", in bold, on the Embeddings tab, as described also on the NoScript "Features" Page page. This time, search for "apply these restrictions".

It's theoretically possible that reading the FAQ and Features page (i. e., the owner's manual and guide) could provide a lot of other useful information, too, as would searching them before posting. ;)
Thanks...
You're quite welcome. :)
Mozilla/5.0 (Windows NT 5.1; rv:18.0) Gecko/20100101 Firefox/18.0.2
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: Noscript won't block embeddings

Post by Thrawn »

plingpling wrote:<snip> this option is misleading, for that it makes you think you're just allowing javascript, but actually you're allowing all potentially harmful objects too.
But since JavaScript itself is potentially harmful, if you want safety, then you should not be globally allowing anything. Allowing JavaScript but blocking objects is basically a nuisance-blocker, like FlashBlock (except more reliable than FlashBlock).

JavaScript may not have as many 0-day vulnerabilities as eg Flash/Java, but it's a vital part of most pure web-based attacks.
Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:18.0) Gecko/20100101 Firefox/18.0
Post Reply