Page 1 of 1

No more XSS filtering warning in Firefox 7?

Posted: Fri Oct 07, 2011 4:58 am
by KIAaze
Hi,

Today, I had a problem using the following website: http://www.helenathe3rd.com/
It is supposed to have a "buy" button between the big image and the text, but it didn't show up, even after allowing scripts globally.
After disabling the XSS filtering in "advanced->XSS", it worked.

Is there a way to get notified about such XSS-filtering/cleaning operations by NoScript?

I remember getting warning bars like the one pictured at http://noscript.net/features#xss in the past. But it does not seem to happen anymore.
I'm using Firefox 7.0.1 and NoScript v2.1.5rc1.
And I did check the "XSS" box in the notifications tab as well (tested with default noscript settings+scripts allowed globally in fact).

(The warnings are visible in "Tools->Web developer->Error console->Messages", but if I don't get notified about it and an option to temporarily allow it (unsafe reload as before), I might miss page content. :( )

Re: No more XSS filtering warning in Firefox 7?

Posted: Fri Oct 07, 2011 2:56 pm
by therube
XSS warning does display in SeaMonkey 2.0.x, Gecko 1.9.1, but does not display in SeaMonkey 2.4.x, Gecko 7.0.1 (that's a big jump ;-)).

So yes, it does look like we are not being notified any more.

Re: No more XSS filtering warning in Firefox 7?

Posted: Fri Oct 07, 2011 3:04 pm
by Alan Baxter
KIAaze wrote: Is there a way to get notified about such XSS-filtering/cleaning operations by NoScript?
I agree. There's no indication that the page content has been changed by the XSS filtering.
Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
NoScript 2.1.5rc1