[RESOLVED] "Skipping cross-site checks for OCSP request"?

Ask for help about NoScript, no registration needed to post
kukla
Senior Member
Posts: 321
Joined: Mon May 04, 2009 12:08 am

[RESOLVED] "Skipping cross-site checks for OCSP request"?

Post by kukla »

I'm wondering why I've just started seeing these entries, which I've never seen before in Console (Mac).
[NoScript] Skipping cross-site checks for OCSP request http://ocsp.verisign.com/
Just updated to 1.9.6.9. Is that related? Is this "expected behavior?"
Mozilla/5.0 (Macintosh; U; PPC Mac OS X 10.4; en-US; rv:1.9.1.1) Gecko/20090715 Firefox/3.5.1
User avatar
GµårÐïåñ
Lieutenant Colonel
Posts: 3369
Joined: Fri Mar 20, 2009 5:19 am
Location: PST - USA
Contact:

Re: "Skipping cross-site checks for OCSP request"?

Post by GµårÐïåñ »

I believe this is a performance optimization since its a legitimate built-in function of Fx, generating errors on it would be redundant and unnecessary. But maybe Giorgio can explain it better.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.1) Gecko/20090715 Firefox/3.5.1
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: "Skipping cross-site checks for OCSP request"?

Post by Giorgio Maone »

GµårÐïåñ is correct.
Log spam removed in latest development builds when not in console-verbose mode.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.1) Gecko/20090715 Firefox/3.5.1 (.NET CLR 3.5.30729)
kukla
Senior Member
Posts: 321
Joined: Mon May 04, 2009 12:08 am

Re: "Skipping cross-site checks for OCSP request"?

Post by kukla »

Thanks Giorgio. Basically, you are saying that Fx (3.5.1) is checking for cross site forgeries on its own, so NS is skipping this because it's already being done now?
Mozilla/5.0 (Macintosh; U; PPC Mac OS X 10.4; en-US; rv:1.9.1.1) Gecko/20090715 Firefox/3.5.1
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: "Skipping cross-site checks for OCSP request"?

Post by Giorgio Maone »

kukla wrote:Basically, you are saying that Fx (3.5.1) is checking for cross site forgeries on its own, so NS is skipping this because it's already being done now?
Not at all, Fx 3.5.1 doesn't check any CSRF, otherwise why would I have lost my sleep on ABE? ;)
What's happening here is that some browser-internal requests do not need to be checked, e.g. those sent in background to validate SSL certificates (OCSP).
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.1) Gecko/20090715 Firefox/3.5.1 (.NET CLR 3.5.30729)
kukla
Senior Member
Posts: 321
Joined: Mon May 04, 2009 12:08 am

Re: "Skipping cross-site checks for OCSP request"?

Post by kukla »

Thanks. Just shows how little I know about this stuff. Basically glad to know NS is doing its job :)
Mozilla/5.0 (Macintosh; U; PPC Mac OS X 10.4; en-US; rv:1.9.1.1) Gecko/20090715 Firefox/3.5.1
Post Reply