Page 1 of 1
NoScript not default denying website?
Posted: Sun Jan 30, 2011 5:27 pm
by Guest
I am using NoSrcipt 2.0.9.6 and today I visited a website called destructoid.com I got a message from NoScript about it blocking a potential XSS attempt from exelator.com. While I am glad NoScript blocked it, the problem is I never allowed exelator.com but NoScript had it allowed. I suppose I could have allowed it by accident but I highly doubt that because I have not visited destuctoid.com in over a year until today and it has been significantly re-designed since then.
Re: NoScript not default denying website?
Posted: Sun Jan 30, 2011 5:32 pm
by Giorgio Maone
Is it in your bookmarks?
Could you check carefully whether you've got any auto-allowing option enabled in NoScript Options|General?
BTW, a XSS attempt can come also from a scriptless site. Are you sure it's actually in your whitelist?
Re: NoScript not default denying website?
Posted: Sun Jan 30, 2011 5:36 pm
by Guest
Giorgio Maone wrote:Is it in your bookmarks?
Could you check carefully whether you've got any auto-allowing option enabled in NoScript Options|General?
BTW, a XSS attempt can come also from a scriptless site. Are you sure it's actually in your whitelist?
Checked and I'm not seeing anything, all my NoScripts are default except I unchecked "Show message about blocked scripts" that is the only setting I've changed
Re: NoScript not default denying website?
Posted: Sun Jan 30, 2011 5:40 pm
by Guest
Giorgio Maone wrote:
BTW, a XSS attempt can come also from a scriptless site. Are you sure it's actually in your whitelist?
Well when I clicked the NoScript icon in the status bar it showed"Forbid exelator.com" rather than "Allow exelator.com"
Re: NoScript not default denying website?
Posted: Sun Jan 30, 2011 5:53 pm
by Giorgio Maone
Then you (or someone else accessing your PC) allowed it by accident.
Re: NoScript not default denying website?
Posted: Sun Jan 30, 2011 5:58 pm
by Guest
Giorgio Maone wrote:Then you (or someone else accessing your PC) allowed it by accident.
Seems plausible, I think I will inform the website devs about the potential XSS maybe it's malicious
Re: NoScript not default denying website?
Posted: Mon Jan 31, 2011 5:41 am
by bill177
I am having a similar issue. I have a default setup of noscript, am making sure "allow bookmarks" is NOT checked.. all scripts on the sites mentionned are reporting blocked.
1)
I am trying to block statcounter from recording my ip address when I visit my own blog. Both the blog and statcounter.com's site have zero permissions set. I reload my blog X amount of times, log in to statcounter, and each refresh was visited with my IP visible.
2)
I went to a run-of-the-mill "what is my ip?" website, and my IP shows without touching NoScript as well. It shows all scripts being blocked in NoScript's options, I double, triple, quadruple check. I do not understand why this is getting through. I went up and down my Whitelist permissions, and the none of the mentioned sites are listed.
Re: NoScript not default denying website?
Posted: Mon Jan 31, 2011 10:51 am
by Giorgio Maone
You send your IP with every single request, no matter whether scripts are enabled or not.
That's how TCP/IP works, and there's nothing you can do about it except hiding behind a proxy.
Re: NoScript not default denying website?
Posted: Mon Jan 31, 2011 10:53 am
by dhouwn
bill177, are you under the false impression that Javascript is needed for a server to get your IP?
/edit: Ninja Giorgio, once again.
Re: NoScript not default denying website?
Posted: Mon Jan 31, 2011 3:16 pm
by bill1977
That I was... blindly following the many "block trackers" Google search hits that claimed ScriptBlocker was also capable of blocking counters such as the Statcounter snippet of code embedded on my blogger page. Ahh well, I had no real need to do it, other than to see if I could. Thanks for setting it straight.