Page 1 of 1

NS filtered XSS attempt from securesuite.net

Posted: Tue Sep 29, 2009 3:27 pm
by kukla
Got the above notice from NoScript while ordering from newegg.com (https). NS message said it was writing it to Console, but can't find it there.

Do you know what could have been happening, and anything about securesuite.net and XSS? Thanks.

Re: NS filtered XSS attempt from securesuite.net

Posted: Tue Sep 29, 2009 5:25 pm
by kukla
I have a basic understanding of what XSS means. I guess what I'm really asking is if you have heard anything about securesuite.net and what it might have been doing while I was logged in with https, and in the process of completing a purchase with credit card info. I suppose I should notify Newegg.

Re: NS filtered XSS attempt from securesuite.net

Posted: Tue Sep 29, 2009 5:26 pm
by kukla
I have a basic understanding of what XSS means. I guess what I'm really asking is if you have heard anything about securesuite.net and what it might have been doing while I was logged in with https, and in the process of completing a purchase with credit card info. I suppose I should notify Newegg. I did a google on that site, but can't come up with anything conclusive about their activites.

Did NS mean the Firefox error console or the Mac console, where I often see NS entries? Looked in the FF one and still don't see that entry.

Re: NS filtered XSS attempt from securesuite.net

Posted: Tue Sep 29, 2009 5:45 pm
by Giorgio Maone
You should find a line starting with [NoScript XSS] in Tools|Error Console just after you get the warning.

Re: NS filtered XSS attempt from securesuite.net

Posted: Tue Sep 29, 2009 9:47 pm
by kukla
Any idea exactly what NS may have been preventing by filtering this? Phishing, data theft? Are all the XSS attempts that NS catches exploits of one kind or another? Do any have any legitimate purposes? Heard of this one? Thanks.

Re: NS filtered XSS attempt from securesuite.net

Posted: Tue Sep 29, 2009 10:08 pm
by Giorgio Maone
kukla wrote:Any idea exactly what NS may have been preventing by filtering this?
It might be a false positive or a real issue.
No way to tell it without looking at the actual message.

Re: NS filtered XSS attempt from securesuite.net

Posted: Tue Sep 29, 2009 10:16 pm
by kukla
Giorgio Maone wrote:
kukla wrote:Any idea exactly what NS may have been preventing by filtering this?
It might be a false positive or a real issue.
No way to tell it without looking at the actual message.
No dice then. It's gone. Anyway, thanks to NoScript it didn't get through, whatever it was.