Page 1 of 1

[RESOLVED] FF57 search being detected as XSS attack

Posted: Fri Dec 01, 2017 8:16 pm
by SyberCorp
Using the search functionality built into Firefox 57 (either via the unified address bar or via the separate search box) searches are being picked up as a XSS attack (see screenshot). The only thing that has changed from not having this behavior to having it, is updating NoScript to 10.1.5. This seems to only happen with Google, so far. I cannot recreate it if I use one of my other search engines (such as DuckDuckGo). I initially thought this was only happening with Google but I was able to recreate it with Wikipedia as well.

https://imgur.com/a/D9xzu

Re: FF57 search being detected as XSS attack

Posted: Sat Dec 02, 2017 12:42 am
by Gray
I'm getting this on every page I open just starting tonight. I had to disable noscript because every link I click causes this popup.

Re: FF57 search being detected as XSS attack

Posted: Sat Dec 02, 2017 12:42 am
by barbaz
Is this problem still there in NoScript 10.1.5.1?

Re: FF57 search being detected as XSS attack

Posted: Sat Dec 02, 2017 12:53 am
by Gray
On 10.1.5 and firefox reports no update found when I manually update.

Re: FF57 search being detected as XSS attack

Posted: Sat Dec 02, 2017 1:08 am
by 8-bit
Gray wrote:On 10.1.5 and firefox reports no update found when I manually update.
I just updated to 10.1.5.1 via Firefox so it is now all in place. Update to the new .1 and see if that eliminates your problem

Release notes:

v 10.1.5.1
=============================================================
x Fixed regression from new "fail fast" XSS filter main loop,
causing cross-site requests to Google to trigger false
positives (thanks Steve M for reporting)

Re: FF57 search being detected as XSS attack

Posted: Sat Dec 02, 2017 2:39 am
by SyberCorp
barbaz wrote:Is this problem still there in NoScript 10.1.5.1?
No, 10.1.5.1 seems to have addressed the issue. Cool.

Re: [RESOLVED] FF57 search being detected as XSS attack

Posted: Sat Dec 02, 2017 2:55 am
by barbaz
Great, thanks for reporting back. Image

Re: [RESOLVED] FF57 search being detected as XSS attack

Posted: Sat Dec 02, 2017 4:39 am
by Icebice
Not resolved for me. I've tried updating, I've relaunched firefox, reboot my computer, I still get xss attack every time.