Page 1 of 1

[RESOLVED] Clickjacking on MS Hotmail page

Posted: Sun Jan 24, 2010 11:31 am
by ScrGuest
Hi all,

current version of NoScript Firefox Add-on 1.9.9.93

Clicking on Inbox() or links at the top (people, mail , etc) I am getting Clickjacking Warning.

Either MS added some stuff again similar to current inability to logoff until you clear cookies
or
it is some bug in this version of NoScript.

I was not visiting my hotmail account for several days. There were no problems, say 20/01/10 and earlier
NoScript was updated 21/01 or 22/01

Any ideas, guys?

Thanks in advance

Re: Clickjacking on MS Hotmail page

Posted: Sun Jan 24, 2010 2:30 pm
by Giorgio Maone
It seems something Firefox 3.6-specific, unrelated to the recent NoScript updates.
I already had one report from a Mac OS X user, but you're on Windows so it's cross-platform.
Anyway I couldn't reproduce it yet. Could you use the "Report" button and tell me the assigned ID?
Also, are you using some non-standard zoom level?
Does disabling all extensions except NoScript help?

Re: Clickjacking on MS Hotmail page

Posted: Mon Jan 25, 2010 5:45 am
by Guest
Hi Giorgio,

Thank you for reply

That would be not easy task to check with all Add-ons disabled since I have a lot :)

Currently, after the release of Fox3.6 there are many incompatible Add-ons
That could indeed contribute to the problem

So, I fired up the portable 3.6 version that has just a few Add-ons including incompatible
Image
and NoScript worked as it suppose to in conjunction with hotmail – no click-hijacking

As you asked below are few IDs
I am not sure whether that is expected behaviour when generating Report Ids, but
the IDs are different if Fox closed & restarted, despite clicking on the same link(s):
e.g. 725189 ; 725212, etc.

My regards

Re: Clickjacking on MS Hotmail page

Posted: Mon Jan 25, 2010 12:25 pm
by Giorgio Maone
Guest wrote:That would be not easy task to check with all Add-ons disabled since I have a lot :)
However your second check confirmed it's an extension conflict, so Standard Diagnostic would be beneficial to everyone of us.

Re: Clickjacking on MS Hotmail page

Posted: Thu Jan 28, 2010 9:36 am
by Guest
Hi Giorgio Maone,

Thanks for reply again.

Well, I tested all as suggested regarding Compatible Add-ons

I wanted to report the negative result and move to checking with all currently incompatible...

and all of a sudden NoScript v1.9.9.42 came, which fixed the problem :)

Cheers!