Page 1 of 1
[Resolved] Google Ads break with NoScript Enabled
Posted: Wed Sep 14, 2016 3:34 am
by KonomiKitten
When I have NoScript Enabled (NoScript Options -> Whitelist -> Scripts Globally Allowed) and uBlock Origin Disabled all Google Ads come out as text instead of the actual ad showing. Disabling NoScript in Add-Ons fixes this problem. Why does this happen? And is it a bug?
NoScript Disabled uBlock Origin Whitelisted 1.png
NoScript Enabled uBlock Origin Whitelisted 1.png

Re: Google Ads break with NoScript Enabled
Posted: Wed Sep 14, 2016 4:10 am
by barbaz
KonomiKitten wrote:Why does this happen?
Basically, NoScript's XSS filter is taking action and saving you from a
extremely unsafe practice that is indistinguishable from actual XSS vulnerability.
This has been discussed many times before - for example:
viewtopic.php?f=7&t=21416
viewtopic.php?f=7&t=21430
viewtopic.php?f=7&t=20670
viewtopic.php?f=7&t=20358
KonomiKitten wrote: And is it a bug?
Yes, it's a bug in those google ads which unfortunately for websites cash flow they wouldn't consider it that way.
Re: Google Ads break with NoScript Enabled
Posted: Wed Sep 14, 2016 4:22 am
by KonomiKitten
Thank you for the quick reply, I'm having a look at the other threads but is there any work around to allow these ads through, say a whitelist for Googles servers for XSS?
Re: Google Ads break with NoScript Enabled
Posted: Wed Sep 14, 2016 4:28 am
by barbaz
KonomiKitten wrote:is there any work around to allow these ads through, say a whitelist for Googles servers for XSS?
Why would you want to allow something so dangerous?
Read carefully the warning I wrote:
viewtopic.php?p=77548#p77548
Re: Google Ads break with NoScript Enabled
Posted: Wed Sep 14, 2016 4:40 am
by Guest
Thank you again, feel free to close this topic!
Re: Google Ads break with NoScript Enabled
Posted: Wed Sep 14, 2016 4:43 am
by barbaz
You're welcome!
Guest wrote:feel free to close this topic
No need for the lock here, I'll just mark this Resolved.
Re: [Resolved] Google Ads break with NoScript Enabled
Posted: Wed Sep 14, 2016 4:59 am
by barbaz
I'll also mention this link FWIW
https://noscript.net/features#xss