Page 1 of 1

CLEARCLICK Report #364936 at Yahoo! Mail login

Posted: Sat Apr 07, 2012 3:32 pm
by oscillator
Hi, I've been using NoScript for a while now and noticed some time ago that when you go to Yahoo! Mail sign-in page, and click the 'Adchoices', NoScript pops up with a clearclick warning window saying "Potential Clickjacking/ UI Redressing Attempt! NoScript intercepted a mouse or keyboard interaction with a partially hidden element. Click on the image below to cycle between the obstructed and the clear version."

(You can try this yourself)

When you cycle between images, the 'partially hidden element' is actually just the sign in part of the page. I've tried this on other websites with the 'adchoices' option and this doesn't happen. I've clicked report when doing this a few times, but thought I'd come post it in the forum just to highlight it, it's not really much of an issue but I'm just putting it out there in case it warrants further investigation.

Re: Yahoo! Mail - partially hidden element.

Posted: Sun Apr 08, 2012 7:05 am
by Tom T.
When you click to submit the report, please note the Report ID number that is generated. Then include that number when you post here.
Otherwise, we have no way of responding to you. Please do this the next time it happens.

I'll try to reproduce, as a Yahoo Mail user, but I never see ads anyway, and don't remember seeing an AdChoices button.

Re: Yahoo! Mail - partially hidden element.

Posted: Sun Apr 08, 2012 7:16 am
by Tom T.
CONFIRMED on Fx 11.0, Report # 364936, at

Code: Select all

https://login.yahoo.com/config/login_verify2?&.src=ym
I had to TA Blocked Object, or click the placeholder, to make "AdChoices" appear:

Code: Select all

https://login.yahoo.net/login_superads/en-US/superads_iframe_content.html?es=ddoT7A751u8Zh8QM24Y-&b=bgbdb3t7o2eg5%26b%3D3%26s%3Dso&ao=o%3D1%26s%3D1%26dnt%3D1
Error Message:

Code: Select all

[NoScript ClearClick] Swallowed event mousedown on A/0 at https://login.yahoo.net/login_superads/en-US/superads_iframe_content.html?es=ddoT7A751u8Zh8QM24Y-&b=bgbdb3t7o2eg5%26b%3D3%26s%3Dso&ao=o%3D1%26s%3D1%26dnt%3D1