XSS protection problem
Posted: Sun Oct 19, 2014 2:01 pm
Hello,
I had the following problem yesterday, which I believe was caused by a combination of problems on the website and NoScript (so not one or the other alone).
I was trying to order furniture from IKEA, using my VISA debit card. When I entered my details, the "verified by VISA" thing came up; I think that's an iframe, I'm not sure.
What normally happens (with other websites) is that this does something for a few seconds then I'm redirected to another page in the website where it says my details have been confirmed and the order is placed.
What happened this time was that, after the verification, NoScript said it blocked an attempted XSS and the website showed an error. I tried to add ikea to the exceptions, using the following regular expression: ^https://.*ikea\.com/.*$
Again the same thing happened, so I tried it a few times, only to find out -in the end- that while my order never went through (so I'm not receiving anything), the money was taken from my account.
To make it clear, I'm not accusing NoScript for this loss (which I'm in contact with my bank to resolve), only trying to understand what I could do to prevent it in the future and whether anyone has had a problem like this. Is my regular expression wrong? Is it a different url I should have used in it?
I had the following problem yesterday, which I believe was caused by a combination of problems on the website and NoScript (so not one or the other alone).
I was trying to order furniture from IKEA, using my VISA debit card. When I entered my details, the "verified by VISA" thing came up; I think that's an iframe, I'm not sure.
What normally happens (with other websites) is that this does something for a few seconds then I'm redirected to another page in the website where it says my details have been confirmed and the order is placed.
What happened this time was that, after the verification, NoScript said it blocked an attempted XSS and the website showed an error. I tried to add ikea to the exceptions, using the following regular expression: ^https://.*ikea\.com/.*$
Again the same thing happened, so I tried it a few times, only to find out -in the end- that while my order never went through (so I'm not receiving anything), the money was taken from my account.
To make it clear, I'm not accusing NoScript for this loss (which I'm in contact with my bank to resolve), only trying to understand what I could do to prevent it in the future and whether anyone has had a problem like this. Is my regular expression wrong? Is it a different url I should have used in it?