SVG and NoScript

Ask for help about NoScript, no registration needed to post
SVGPonderer

SVG and NoScript

Post by SVGPonderer »

Hello! Are there security risks in keeping SVG enabled in Fx 3.5 ? How about privacy risks?
Does NoScript care (or need to care in the future) about SVG at all?
Mozilla/5.0 (Windows; U; Windows NT 6.0; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5
SVGPonderer

Re: SVG and NoScript

Post by SVGPonderer »

Privacy risks like for instance a separate cash vulnerable to some kind of attack similar to what SafeCache was protecting against.

By the way I've seen a few posts here and there where users say they use SafeCache and SafeHistory....but they have Fx 3+. Was I dreaming or is it feasible to use these add ons with Fx 3.5? If so, how?

Thanks! (And sorry for double post)
Mozilla/5.0 (Windows; U; Windows NT 6.0; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: SVG and NoScript

Post by Giorgio Maone »

Generally speaking, SVG adds something to your attack surface in terms of parsing or rendering bugs which might be exploit for code execution, but on pages which have scripting disabled the risk is minimal if not void, because heap spraying preparation would be very impractical or impossible.
There's no additional privacy risk that I can think of.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5 (.NET CLR 3.5.30729)
SVGPonderer

Re: SVG and NoScript

Post by SVGPonderer »

Okay, thank you :)
Going to keep it on then.

How about SafeCache and SafeHistory with Fx 3.5? I was dreaming right? They cannot do their task even if I somehow keep them enabled in Fx 3.5? I was under the impression that even you were using them, hence my questionning.
Mozilla/5.0 (Windows; U; Windows NT 6.0; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: SVG and NoScript

Post by Giorgio Maone »

SafeHistory is broken on recent Firefox. You can switch the layout.css.visited_links_enabled about:config property to false if you're concerned about this issue and you don't mind the usability impact.
I'm not sure about SafeCache, since I don't use it (I flush my cache after every session).
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5 (.NET CLR 3.5.30729)
SVGPonderer

Re: SVG and NoScript

Post by SVGPonderer »

Thanks :)

I don't need history a lot anyway. Only "recently closed tabs" and windows are useful to me, and those can't be sniffed if I'm not mistaken.
Mozilla/5.0 (Windows; U; Windows NT 6.0; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5
Post Reply