xss on gmail
Posted: Thu Mar 17, 2016 7:08 pm
[NoScript] Force text/plain for missing content-type on https://www.google.com/intl/pt-PT/mail/help/about.html
[NoScript InjectionChecker] JavaScript Injection in ///se/0/_/ 1/fastbutton?usegapi=1&origin=https://www.google.com&url=https://www.google.com/intl/pt-PT/mail/help/about.html&gsrc=3p&ic=1&jsh=m;/_/scs/apps-static/_/js/k=oz.gapi.pt_PT.1g-4IO2C2v8.O/m=__features__/am=AQ/rt=j/d=1/rs=AGLTcCN-eBIEiIN3HiJ4A9tPWB7HbSMXtQ#_methods=onPlusOne,_ready,_close,_open,_resizeMe,_renderstart,oncircled,drefresh,erefresh,onload&id=I0_1458241430527&parent=https://www.google.com&pfname=&rpctoken=39022211
(function anonymous() {
_methods=onPlusOne,_ready,_close,_open,_resizeMe,_renderstart,oncircled,drefresh,erefresh,onload /* COMMENT_TERMINATOR */
DUMMY_EXPR
})
[NoScript XSS] Desinfectou um requerimento suspeito. O URL original [https://apis.google.com/se/0/_/+1/fastb ... n=39022211] requerido por [https://www.google.com/intl/pt-PT/mail/help/about.html]. URL desinfectada: [https://apis.google.com/#646347786676619544].)
about:blank : Unable to run script because scripts are blocked internally.
False Positive?
[NoScript InjectionChecker] JavaScript Injection in ///se/0/_/ 1/fastbutton?usegapi=1&origin=https://www.google.com&url=https://www.google.com/intl/pt-PT/mail/help/about.html&gsrc=3p&ic=1&jsh=m;/_/scs/apps-static/_/js/k=oz.gapi.pt_PT.1g-4IO2C2v8.O/m=__features__/am=AQ/rt=j/d=1/rs=AGLTcCN-eBIEiIN3HiJ4A9tPWB7HbSMXtQ#_methods=onPlusOne,_ready,_close,_open,_resizeMe,_renderstart,oncircled,drefresh,erefresh,onload&id=I0_1458241430527&parent=https://www.google.com&pfname=&rpctoken=39022211
(function anonymous() {
_methods=onPlusOne,_ready,_close,_open,_resizeMe,_renderstart,oncircled,drefresh,erefresh,onload /* COMMENT_TERMINATOR */
DUMMY_EXPR
})
[NoScript XSS] Desinfectou um requerimento suspeito. O URL original [https://apis.google.com/se/0/_/+1/fastb ... n=39022211] requerido por [https://www.google.com/intl/pt-PT/mail/help/about.html]. URL desinfectada: [https://apis.google.com/#646347786676619544].)
about:blank : Unable to run script because scripts are blocked internally.
False Positive?