yo why is this giving xss error am i being hacked

Ask for help about NoScript, no registration needed to post
aardwolf

yo why is this giving xss error am i being hacked

Post by aardwolf »

http://shoryuken.com/wiki/index.php/M._Bison_(SSFIV)

why does this cause xss error i need my m. bison info and i dont know if shoryuken is hackedd do i need to tell them that they are hacked ro something plz help
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: yo why is this giving xss error am i being hacked

Post by Giorgio Maone »

The problem is the name of the page being syntactically equivalent to a javascript method call, like object.method(argument).
It's a false positive, nothing malicious there. You can use the "Unsafe reload" command from the "Options" button.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6
marco

Re: yo why is this giving xss error am i being hacked

Post by marco »

Giorgio, are you seeing an issue with Picasa Web Albums?

I'm on 1.9.99 and getting XSS filtering alerts on all picasa pages -

example URL:

http://picasaweb.google.com/lh/explore# ... e=pwalogin

[NoScript XSS] Sanitized suspicious request. Original URL [http://ad-g.doubleclick.net/adi/com.pic ... eralbum_ad] requested from [http://picasaweb.google.com/meanestdogi ... ocked=true]. Sanitized URL: [http://xss:xss@ad-g.doubleclick.net/adi ... 7335154770].
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6 (.NET CLR 3.5.30729)
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: yo why is this giving xss error am i being hacked

Post by Giorgio Maone »

marco wrote:Giorgio, are you seeing an issue with Picasa Web Albums?
the domain=picasaweb.google.com "statement" is likely the culprit.
Just block doubleclick.net (either in NoScript or in Adblock Plus) and you shouldn't get any XSS warning.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6
Post Reply