Page 1 of 2

Need to remove a Javascript pop-up notice

Posted: Wed Sep 09, 2015 9:50 am
by arcadian
Hi, I've used No-Script on Firefox for quite a few years now and it's been excellent with no problems at all.

However I started having problems recently with a JavaScript pop-up notice that kept appearing and causing slowing down or crashing of the browser page. I got in touch with Firefox help desk about this who then told me to individually isolate all the extensions to trace which one was at fault. It turned out that for some reason it was "No Script" which when disabled removed the pop-up notice immediately. Unfortunately however I can't find anywhere to upload and attach a screen pic of it ?

Much appreciate any help to resolve this as I'd like to re-install "No-Script" again as soon as possible.....

Thanks in advance :)

Re: Need to remove a Javascript pop-up notice

Posted: Wed Sep 09, 2015 1:27 pm
by therube
Just what is this popup notice, what does it say?

Re: Need to remove a Javascript pop-up notice

Posted: Wed Sep 09, 2015 1:50 pm
by arcadian
Unfortunately as I can't find a way to upload on here I've had to post a screen pic of it on photobucket....

http://i356.photobucket.com/albums/oo5/ ... dhqjfk.jpg

Re: Need to remove a Javascript pop-up notice

Posted: Wed Sep 09, 2015 5:27 pm
by barbaz
My browser says the image cannot be displayed because it contains errors

Re: Need to remove a Javascript pop-up notice

Posted: Wed Sep 09, 2015 6:58 pm
by arcadian
If you mean the image in Photobucket mine's fine....

Re: Need to remove a Javascript pop-up notice

Posted: Wed Sep 09, 2015 8:33 pm
by barbaz
Yes the one on Photobucket. Still same deal here but if I download it then I can view it in my system's image viewer.

see viewtopic.php?f=7&t=21192 ?

Re: Need to remove a Javascript pop-up notice

Posted: Thu Sep 10, 2015 6:04 am
by Thrawn
I'm guessing that there will be something in the Browser Console (Ctrl+Shift+J) when this occurs. Probably either the XSS filter or the Cross-Site Inclusion Filter.

Re: Need to remove a Javascript pop-up notice

Posted: Thu Sep 10, 2015 2:26 pm
by arcadian
Sorry way, way above my head.... ! :)

Re: Need to remove a Javascript pop-up notice

Posted: Thu Sep 10, 2015 8:37 pm
by barbaz
Reproduce the problem, hit Ctrl-Shift-J, and post all messages you see starting with "[NoScript".

Re: Need to remove a Javascript pop-up notice

Posted: Fri Sep 11, 2015 9:28 am
by arcadian
browser.xul
Key event not available on some keyboard layouts: key="c" modifiers="accel,alt" browser.xul
Key event not available on some keyboard layouts: key="i" modifiers="accel,alt,shift" browser.xul
[NoScript InjectionChecker] JavaScript Injection in qp=si=1&e=https%3A%2F%2Fonline.lloydsbank.co.uk&LSESSIONID=jLd1o6QZ44QndCuBLhsp2TwMpfOSpn%2FZXEiyEXavFtPX08UvNMN04sU%3D&t=xpost&pd=d=JTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uZGl2JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMndyYXBwZXIlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjElMjUyQyUyNTIyJTI1MjIlMjUyQyUyNTIyb3V0ZXIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyaGVhZGVyJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIzJTI1MkMlMjUyMiUyNTIyJTI1MkMlMjUyMmNsZWFyZml4JTI1MjIlMjU1RCUyNTJDJTI1NUI0JTI1MkMlMjUyMiUyNTIyJTI1MkMlMjUyMnNlY3VyZU1zZyUyNTIyJTI1NUQlMjUyQyUyNTVCNSUyNTJDJTI1MjIlMjUyMiUyNTJDJTI1MjJsb2dnZWRJbiUyNTIyJTI1NUQlMjUyQyUyNTVCNiUyNTJDJTI1MjIlMjUyMiUyNTJDJTI1MjJwYWdlV3JhcCUyNTIyJTI1NUQlMjUyQyUyNTVCNyUyNTJDJTI1MjJwYWdlJTI1MjIlMjUyQyUyNTIyY29udGVudCUyNTIyJTI1NUQlMjUyQyUyNTVCOCUyNTJDJTI
[NoScript XSS]: sanitized window.name, "qp=si%3D1%26e%3Dhttps%253A%252F%252Fonline.lloydsbank.co.uk%26LSESSIONID%3DjLd1o6QZ44QndCuBLhsp2TwMpfOSpn%252FZXEiyEXavFtPX08UvNMN04sU%253D%26t%3Dxpost&pd=d%3DJTVCJTdCJTIyaWQlMjIlM0ElMjI2JTIyJTJDJTIyZGF0YSUyMiUzQSU3QiUyMmNpZCUyMiUzQSUyMjYlMjIlMkMlMjJiJTIyJTNBMCUyQyUyMmQlMjIlM0ElMjIlMjU3QiUyNTIyZG9tLmJsb2NrcXVvdGUlMjUyMiUyNTNBJTI1NUIlMjU1RCUyNTJDJTI1MjJkb20uZGl2JTI1MjIlMjUzQSUyNTVCJTI1NUIwJTI1MkMlMjUyMndyYXBwZXIlMjUyMiUyNTJDJTI1MjIlMjUyMiUyNTVEJTI1MkMlMjU1QjElMjUyQyUyNTIyJTI1MjIlMjUyQyUyNTIyb3V0ZXIlMjUyMiUyNTVEJTI1MkMlMjU1QjIlMjUyQyUyNTIyaGVhZGVyJTI1MjIlMjUyQyUyNTIyJTI1MjIlMjU1RCUyNTJDJTI1NUIzJTI1MkMlMjUyMiUyNTIyJTI1MkMlMjUyMmNsZWFyZml4JTI1MjIlMjU1RCUyNTJDJTI1NUI0JTI1MkMlMjUyMiUyNTIyJTI1MkMlMjUyMnNlY3VyZU1zZyUyNTIyJTI1NUQlMjUyQyUyNTVCNSUyNTJDJTI1MjIlMjUyMiUyNTJDJTI1MjJsb2dnZWRJbiUyNTIyJTI1NUQlMjUyQyUyNTVCNiUyNTJDJTI1MjIlMjUyMiUyNTJDJTI1MjJwYWdlV3JhcCUyNTIyJTI1NUQlMjUyQyUyNTVCNyUyNTJDJTI1MjJwYWdlJTI1MjIlMjUyQyUyNTIyY29udGVudCUyNTIyJTI1NUQlMjUyQyUyN
https://marketing.lloydsbank.co.uk//llo ... %3DPLO0512
about:blank
Overriding failed (2147500037) redirect callback for 12: https://aa.online-metrix.net/fpc.swf?se ... 3a3a3d3135 -> https://aa.online-metrix.net/fpc.swf?se ... 3a3a3d3135 - 2
This site makes use of a SHA-1 Certificate; it's recommended you use certificates with signature algorithms that use hash functions stronger than SHA-1.[Learn More] update.xm

Re: Need to remove a Javascript pop-up notice

Posted: Sun Sep 13, 2015 9:42 am
by arcadian
How's things going any luck yet....?

Re: Need to remove a Javascript pop-up notice

Posted: Sun Sep 13, 2015 2:25 pm
by barbaz
barbaz wrote:see viewtopic.php?f=7&t=21192 ?

Re: Need to remove a Javascript pop-up notice

Posted: Sun Sep 13, 2015 3:23 pm
by arcadian
Apologies but I haven't the slightest idea what any of it means or what to do :) Wouldn't it be simplest to just turn off No Script altogether.... ?

Re: Need to remove a Javascript pop-up notice

Posted: Sun Sep 13, 2015 4:27 pm
by barbaz
arcadian wrote:Apologies but I haven't the slightest idea what any of it means or what to do :)
Contact the site and tell them what they are doing is very unsafe and should be changed ASAP?
The reason why it's unsafe is they are putting data where *any* site you visit in the same tab/iframe/whatever can access it, so if you were to later visit an attack site, or have already visited an attack site which planted specially crafted payload there... :o

Or perhaps you can block the script causing this message, using ABE or a surrogate script?

(XSS exception is *not* safe here IMO.)
arcadian wrote:Wouldn't it be simplest to just turn off No Script altogether.... ?
Do you really think there is any way that it'd be simpler to deal with the after-effects of being XSS'ed, clickjacked, etc., some of which may be used as a malware delivery vector or means to steal money from you, rather than troubleshoot this problem?
Image

It's not a matter of "if" you'll run into an attack situation on the Internet; it's a matter of when it happens...

Re: Need to remove a Javascript pop-up notice

Posted: Sun Sep 13, 2015 6:19 pm
by arcadian
Great finally got a little clearer idea of things now, so grateful thanks indeed and apols for the dumb final question.... ! :oops:

Although I've had NS for ages firstly I've never really understood what it was all about as I'm far too busy, so when a friend recommended me to use it to begin with that was good enough for me. Secondly I'm not a techie at all and never will be, and finally when I did try to find out anything it was sheer information overload with no idea of where or how to start. So is there any simple basic info for us types anywhere I can read as to what NS does and aims to do ? Also what does ABE and XXXs mean ?

Anyway first thing I did when it happened was to contact the bank who said it was nothing to do with them, which with hindsight was ridiculous given what you've just told me. Instead they should have automatically told me to immediately report it as a security breach but they didn't ! So now to report it to the bank as I simply daren't tamper with anything....

Again many thanks will keep you posted....!!!!!! :)