Page 1 of 1

Does Disable XSS Require Browser Restart?

Posted: Fri Aug 16, 2013 6:02 pm
by therube
Does Disable XSS Require Browser Restart?

Because even after unchecking both XSS items, I am still getting XSS warnings in Error Console.

Tried new tab & new window.
Neither made a difference?


PS: Why is there no notification on XSS blocks?

Code: Select all

[NoScript] Blocking cross-site Javascript served from https://www.tradepub.com/c/tppre.mpl?first=the&last=rube&title=&company=&email=abc@def.com&phone=3019012340&street=123+main+st&dept_div=&city=WASHINGTON&state=DC&zip=20001&indcode1=15&indcode2=11&ocpcode1=19&ocpcode2=10&ocpcode3=2&orgemp=D005&_=6713567693536 with wrong type info image/gif and included by https://tradepub.freebizmag.com/20000931/checkout.html

Re: Does Disable XSS Require Browser Restart?

Posted: Fri Aug 16, 2013 10:10 pm
by Thrawn
That isn't the (regular) XSS filter, it's the cross-site inclusion filter. It's telling you that although a resource was imported using (presumably) a script tag, the server thinks it's sending you an image. Actually, it looks like a web bug. You might want to block it with ABE.