Plesk problem - confirmation that NoScript works against it

Ask for help about NoScript, no registration needed to post
pleskproblem

Plesk problem - confirmation that NoScript works against it

Post by pleskproblem »

Hello everyone.

As you might have heard, a number of websites have been this month infected after a hole was found in Plesk:
http://blog.unmaskparasites.com/2012/06 ... m-domains/

From what I understood, the malicious script, when executed, turns itself into an IFRAME with the malicious page. Can you please confirm that:

1. If I visit an infected website that is NOT on NoScript's whitelist, I'm 100% safe because the script will not run.

2. If I visit an infected website that is on NoScript's whitelist, the code will run, will be converted to an IFRAME but NoScript will block the IFRAME because it's not on the Whitelist.

Is the above correct?

Thank you.
Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
dhouwn
Bug Buster
Posts: 968
Joined: Thu Mar 19, 2009 12:51 pm

Re: Plesk problem - confirmation that NoScript works against

Post by dhouwn »

Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:14.0) Gecko/20100101 Firefox/14.0
pleskproblem

Re: Plesk problem - confirmation that NoScript works against

Post by pleskproblem »

Very kind dhouwn, thanks!
Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: Plesk problem - confirmation that NoScript works against

Post by Thrawn »

That looks nasty. However:
1. Yes, non-trusted sites are safe.
2. For trusted sites, see http://noscript.net/faq#qa1_11 (especially the section about trusted sites getting compromised).
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (Android; Mobile; rv:15.0) Gecko/15.0 Firefox/15.0a1
Post Reply