[Resolved] ClearClick false positive on simfy.de

Ask for help about NoScript, no registration needed to post
MuScript

[Resolved] ClearClick false positive on simfy.de

Post by MuScript »

http://www.simfy.de is a website where you can listen to music which is played via Adobe Flash. To reproduce this issue, you need to be registered, sorry (but it's free). On this website, there are buttons like "play/pause", "next title", a progress bar with which you can seek to a specific position of the song etc. Since I updated NoScript to version 2.3.4, there is a pop-up window by NoScript, which appears when I click at one of those buttons. It says, that I possibly get clickjacked, which is obviously not the case.

Maybe this false positive could be fixed for the next version. Thanks :)
Mozilla/5.0 (Windows; U; Windows NT 6.0; de; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28
User avatar
Giorgio Maone
Site Admin
Posts: 9557
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: ClearClick false positive on simfy.de

Post by Giorgio Maone »

Could you please use the "Report" button and give me the report ID you get assigned? Thanks.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:11.0) Gecko/20100101 Firefox/11.0
MuScript

Re: ClearClick false positive on simfy.de

Post by MuScript »

Sure :)

Report-ID: 311980
Mozilla/5.0 (Windows; U; Windows NT 6.0; de; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28
User avatar
Giorgio Maone
Site Admin
Posts: 9557
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: ClearClick false positive on simfy.de

Post by Giorgio Maone »

Unfortunately I cannot test because it says I'm in a non-supported country (Italy) and I don't have a German proxy at hand (I suppose it's what I would need).

However I made a blind attempt: could you check latest development build 2.3.5rc4 and tell me if it works around your problem?
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:11.0) Gecko/20100101 Firefox/11.0
User avatar
therube
Ambassador
Posts: 7991
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: ClearClick false positive on simfy.de

Post by therube »

I did get the ClearClick warning with 2.3.5rc3 (I believe it was).
Not see any ClearClick warning with 2.3.5rc5.

Though:

Code: Select all

[NoScript InjectionChecker] JavaScript Injection in ///if?enc=tksbDkuD5j-2SxsOS4PmPwAAAIDrUQBAtksbDkuD5j-2SxsOS4PmP7Yu2PmXWH4e2nmwBLXjtnMxg2NPAAAAAOQiCwB0AwAAdAMAAAIAAAAfJhcABzYCAAAAAABVU0QARVVSAKAAWAJvQwAAfQsAAgQCAQUAAIIAFyCOYwAAAAA.&udj=uf('a', 41156, 1331921713);uf('r', 1517087, 1331921713);&cnd=!WSUzIgjCghEQn8xcGAAgh-wIMAM474YFQARI9AZQ5MUsWABgmgFoAHAAeACAAQCIAQCQAQGYAQGgAQqoAQCwAQC5AZrnvFqlGOE_wQGa57xapRjhP8kBiZgngPo_8T_ZAQWjkjoBTeg_4AEA&ccd=!7ASFJwjCghEQn8xcGIfsCCAE&vpid=156&referrer=http://www.simfyads.de/displayads/website/rotation_misc_ajax_160x600.html&media_subtypes=1&dlo=1
(function anonymous() {uf("a", 41156, 1331921713);uf("r", 1517087, 1331921713);DUMMY_EXPR;})

Code: Select all

[NoScript XSS] Sanitized suspicious request. Original URL [http://ib.adnxs.com/if?enc=tksbDkuD5j-2SxsOS4PmPwAAAIDrUQBAtksbDkuD5j-2SxsOS4PmP7Yu2PmXWH4e2nmwBLXjtnMxg2NPAAAAAOQiCwB0AwAAdAMAAAIAAAAfJhcABzYCAAAAAABVU0QARVVSAKAAWAJvQwAAfQsAAgQCAQUAAIIAFyCOYwAAAAA.&udj=uf%28%27a%27%2C+41156%2C+1331921713%29%3Buf%28%27r%27%2C+1517087%2C+1331921713%29%3B&cnd=!WSUzIgjCghEQn8xcGAAgh-wIMAM474YFQARI9AZQ5MUsWABgmgFoAHAAeACAAQCIAQCQAQGYAQGgAQqoAQCwAQC5AZrnvFqlGOE_wQGa57xapRjhP8kBiZgngPo_8T_ZAQWjkjoBTeg_4AEA&ccd=!7ASFJwjCghEQn8xcGIfsCCAE&vpid=156&referrer=http://www.simfyads.de/displayads/website/rotation_misc_ajax_160x600.html&media_subtypes=1&dlo=1] requested from [http://www.simfyads.de/displayads/website/rotation_misc_ajax_160x600.html]. Sanitized URL: [http://ib.adnxs.com/if?enc=tksbDkuD5j-2SxsOS4PmPwAAAIDrUQ20tksbDkuD5j-2SxsOS4PmP7Yu2PmXWH4e2nmwBLXjtnMxg2NPAAAAAOQiCwB0AwAAdAMAAAIAAAAfJhcABzYCAAAAAABVU0QARVVSAKAAWAJvQwAAfQsAAgQ20QUAAIIAFyCOYwAAAAA.&udj=uf%20%20a%20%2C+41156%2C+1331921713%20%3Buf%20%20r%20%2C+1517087%2C+1331921713%20%3B&cnd=!WSUzIgjCghEQn8xcGAAgh-wIMAM474YFQARI9AZQ5MUsWABgmgFoAHAAeACAAQCIAQCQAQGYAQGgAQqoAQCwAQ20AZrnvFqlGOE_wQGa57xapRjhP8kBiZgngPo_8T_ZAQWjkjoBTeg_4AEA&ccd=!7ASFJwjCghEQn8xcGIfsCCAE&vpid=156&referrer=http://www.simfyads.de/displayads/website/rotation_misc_ajax_160x600.html&media_subtypes=1&dlo=1#11047919853104393856].
Proxy: 81.169.182.101:3128
Login from bugmenot as its a cpa ;-).


Bück dich hoch sounded interesting.
Then some Unheilig played. Not a bad playlist.
But the Kraftclub was pretty bla. And Madonna, for get about it.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20120316 Firefox/13.0a2 SeaMonkey/2.10a2
User avatar
Giorgio Maone
Site Admin
Posts: 9557
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: ClearClick false positive on simfy.de

Post by Giorgio Maone »

therube wrote: Though:

Code: Select all

[NoScript XSS] Sanitized suspicious request. Original URL [http://ib.adnxs.com/if?enc=tksbDkuD5j-2SxsOS4PmPwAAAIDrUQBAtksbDkuD5j-2SxsOS4PmP7Yu2PmXWH4e2nmwBLXjtnMxg2NPAAAAAOQiCwB0AwAAdAMAAAIAAAAfJhcABzYCAAAAAABVU0QARVVSAKAAWAJvQwAAfQsAAgQCAQUAAIIAFyCOYwAAAAA.&udj=uf%28%27a%27%2C+41156%2C+1331921713%29%3Buf%28%27r%27%2C+1517087%2C+1331921713%29%3B&cnd=!WSUzIgjCghEQn8xcGAAgh-wIMAM474YFQARI9AZQ5MUsWABgmgFoAHAAeACAAQCIAQCQAQGYAQGgAQqoAQCwAQC5AZrnvFqlGOE_wQGa57xapRjhP8kBiZgngPo_8T_ZAQWjkjoBTeg_4AEA&ccd=!7ASFJwjCghEQn8xcGIfsCCAE&vpid=156&referrer=http://www.simfyads.de/displayads/website/rotation_misc_ajax_160x600.html&media_subtypes=1&dlo=1] requested from [http://www.simfyads.de/displayads/website/rotation_misc_ajax_160x600.html]. Sanitized URL: [http://ib.adnxs.com/if?enc=tksbDkuD5j-2SxsOS4PmPwAAAIDrUQ20tksbDkuD5j-2SxsOS4PmP7Yu2PmXWH4e2nmwBLXjtnMxg2NPAAAAAOQiCwB0AwAAdAMAAAIAAAAfJhcABzYCAAAAAABVU0QARVVSAKAAWAJvQwAAfQsAAgQ20QUAAIIAFyCOYwAAAAA.&udj=uf%20%20a%20%2C+41156%2C+1331921713%20%3Buf%20%20r%20%2C+1517087%2C+1331921713%20%3B&cnd=!WSUzIgjCghEQn8xcGAAgh-wIMAM474YFQARI9AZQ5MUsWABgmgFoAHAAeACAAQCIAQCQAQGYAQGgAQqoAQCwAQ20AZrnvFqlGOE_wQGa57xapRjhP8kBiZgngPo_8T_ZAQWjkjoBTeg_4AEA&ccd=!7ASFJwjCghEQn8xcGIfsCCAE&vpid=156&referrer=http://www.simfyads.de/displayads/website/rotation_misc_ajax_160x600.html&media_subtypes=1&dlo=1#11047919853104393856].
Just "Mark adnxs.com as untrusted".
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:11.0) Gecko/20100101 Firefox/11.0
MuScript

Re: ClearClick false positive on simfy.de

Post by MuScript »

I downloaded and installed the latest developer release of NoScript (2.3.5rc6). With this version there's no longer a ClearClick warning. Note, however, that I changed into a virtual machine for that experiment (if this could distort the result).
Mozilla/5.0 (Windows; U; Windows NT 6.0; de; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28
Post Reply