regular expression for bit.ly?

Ask for help about NoScript, no registration needed to post
Markus837

regular expression for bit.ly?

Post by Markus837 »

Dear NoScript users,

I have recently started using the bit.ly sidebar and every time I post something through it I have to confirm the anti-xss protection for it. I have had a look at the regular expression described here but can't seem to find the right code for the bit.ly sidebar. Can anyone help please? I would like to use the bit.ly sidebar without having to confirm the anti-xss dialogue. Thanks.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: regular expression for bit.ly?

Post by Giorgio Maone »

Can I see the exact [NoScript XSS] messages you get in Tools>Error Console?
Mozilla/5.0 (Windows NT 5.2; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Markus837

Re: regular expression for bit.ly?

Post by Markus837 »

Hello Giorgio,

there are two, not sure if they are identical. This is the log from this page here when I click the bit-ly sidebar.

[NoScript ClearClick] Swallowed event mousedown on TEXTAREA/1 at http://bit.ly/a/sidebar?u=http%3A%2F%2F ... 0bit.ly%3F

and

[NoScript ClearClick] Swallowed event mouseup on TEXTAREA/1 at http://bit.ly/a/sidebar?u=http%3A%2F%2F ... 0bit.ly%3F
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: regular expression for bit.ly?

Post by Giorgio Maone »

Unfortunately they're not XSS-related.
If you actually can see the yellow XSS warning, you should find [NoScript XSS] lines as well...
Mozilla/5.0 (Windows NT 5.2; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Markus837

Re: regular expression for bit.ly?

Post by Markus837 »

So how can I get rid of the warning message every time I want to post a tweet?
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5
Markus837

Re: regular expression for bit.ly?

Post by Markus837 »

Or how can I tell NoScript to stop swallowing the mouse-down and up events please? I don't want to turn of XXS protection but would like to use the bit-ly sidebar for posting and editing tweet from various sites. Thanks.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: regular expression for bit.ly?

Post by Giorgio Maone »

Markus837 wrote:So how can I get rid of the warning message every time I want to post a tweet?
Did you actually show us this warning message so far?
Mozilla/5.0 (Windows NT 5.2; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Markus837

Re: regular expression for bit.ly?

Post by Markus837 »

[REDACTED IMAGE]

I am sure you understand now what I mean. In the error console log I do get the same messages that I have posted above.

Code: Select all

[NoScript ClearClick] Swallowed event mousedown on TEXTAREA/1 at http://bit.ly/a/sidebar?u=http%3A%2F%2Fforums.informaction.com%2Fposting.php%3Fmode%3Dreply%26f%3D7%26t%3D6422&s=&s=InformAction%20Forums%20%E2%80%A2%20Post%20a%20reply
and

Code: Select all

[NoScript ClearClick] Swallowed event mouseup on TEXTAREA/1 at http://bit.ly/a/sidebar?u=http%3A%2F%2Fforums.informaction.com%2Fposting.php%3Fmode%3Dreply%26f%3D7%26t%3D6422&s=&s=InformAction%20Forums%20%E2%80%A2%20Post%20a%20reply
These two messages are from the post reply page here on the forum when I click on the bit.ly sidebar.

Thanks for any help.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5
Markus837

Re: regular expression for bit.ly?

Post by Markus837 »

Additionally you can click "view image" in the above post to see the whole image with the bit.ly sidebar. Again, thanks for any help on this.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: regular expression for bit.ly?

Post by Giorgio Maone »

OK, that's not a XSS warning but a ClearClick (Clickjacking) one.
Please use the "Report" button and tell me the report ID you get assigned.
Mozilla/5.0 (Windows NT 5.2; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Guest

Re: regular expression for bit.ly?

Post by Guest »

Ah darn, I forgot the edit out my bit.ly ID in the screenshot inside the noscript warning message, can you please remove the screen shot, asap, thanks. Here is a new screenshot without my bit.ly id in it. Silly me!!

Image

Again, thanks for any help on this. Much appreciated as otherwise NoScript does protect me very very well.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5
Markus837

Re: regular expression for bit.ly?

Post by Markus837 »

The Report ID is 1680487

Thanks.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: regular expression for bit.ly?

Post by Giorgio Maone »

Could you check latest development build?
Mozilla/5.0 (Windows NT 5.2; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Markus837

Re: regular expression for bit.ly?

Post by Markus837 »

Thanks, just tested it and unfortunately it is still giving me the Potential Clickjacking / UI Redressing Attempt warning.
Does it matter perhaps that I use the MVPS HOSTS file? Perhaps I have to change some settings in NoScript?

Thanks for your support. I am really grateful. :)
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1) Gecko/20090624 Firefox/3.5
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: regular expression for bit.ly?

Post by Giorgio Maone »

Markus837 wrote:Thanks, just tested it and unfortunately it is still giving me the Potential Clickjacking / UI Redressing Attempt warning.
That's very strange.
Could you please give me another report ID and tell me what your noscript.clearclick.subexceptions [url=http://kb..org/About:config]about:config[/url] preference looks like?
Mozilla/5.0 (Windows NT 5.2; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Post Reply