Page 1 of 1

clearHTTPStatus and NoScript or inside NoScript ? Thank you.

Posted: Sat Jun 11, 2011 7:42 pm
by fred
hello (i'm french by default, i speak french ... but i can vote in Italy (not use because i'm french). 3615 my life :lol:.)

NoScript 2.1.1.2rc1 (i use beta versions) and futures versions ; is ok with this feature (read link) or no ? (i'm not expert) :

Abusing HTTP Status Codes to Expose Private Information | Mike Cardwell, Online :
https://grepular.com/Abusing_HTTP_Status_Codes_to_Expose_Private_Information

clearHTTPStatus :: Add-ons for Firefox (I must/can install or no if a use already NoScript ? Duplicate function ?) :
https://addons.mozilla.org/firefox/addon/clearhttpstatus/

Add please, function of the add-on clearHTTPStatus inside NoScript ...

Thank you. I use Firefox 3.6.17 because all my add-ons are not compatible with FX4.* (even with 3.6.17 ; check compatibility false).

Note: This is not because i no longer seems to come watch my old messages that the subject no longer interests me. I hope the next version of NoScript contain the changes i've requested please (and better than what i proposed of course and others peoples can complete my requests below my message (below my first post = opening of the subject)). Thank you very much.

(Note: Google Toolbar VersionĀ 7.1.20110512W http://www.google.com/intl/us/toolbar/ff/index.html fix the bug inside search box for erase history and maybe fix the bug (select item with mouse) for FX4 ; see my preview message and message of the others peoples. Thank you, and sorry to have suspected NoScript even if there were bugs found in the past (note = surrogate script (with script disabled on the web page concerned) no work, see here !))

Re: clearHTTPStatus and NoScript or inside NoScript ? Thank

Posted: Sat Jun 11, 2011 8:08 pm
by Giorgio Maone
fred wrote:hello (i'm french by default, i speak french ... but i can vote in Italy (not use because i'm french). 3615 my life :lol:.)
Then you MUST go to vote tomorrow.

fred wrote: clearHTTPStatus :: Add-ons for Firefox (I must/can install or no if a use already NoScript ? Duplicate function ?) :
The attack requires JavaScript to be enabled on the attacker's site, so you're protected by default by NoScript, even though it's not exactly duplicate function.