Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 26th, 2009, 05:27 AM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Exclamation Noscript bypass ?

I had Scripting and Java disabled with Noscript in FF v3.0.12, and still videos started automatically playing on this www. Lots of Javascript in the source, but how can that happen ?

Just 1 example

http://www.5min.com/Video/Beware-of-...Tech-126844687
  #2  
Old July 26th, 2009, 05:33 AM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: Noscript bypass ?

i can't replicate. does noscript show all scripts block icon?
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #3  
Old July 26th, 2009, 05:46 AM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Question Re: Noscript bypass ?

Yes ?
Attached Images
 
  #4  
Old July 26th, 2009, 06:04 AM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: Noscript bypass ?

this is what i see on that page
Attached Thumbnails
Click image for larger version

Name:	Clipboard03.jpg
Views:	8
Size:	61.8 KB
ID:	210747  

__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #6  
Old July 26th, 2009, 06:56 AM
tsec tsec is offline
Regular Poster
 
Join Date: Nov 2008
Posts: 181
Default Re: Noscript bypass ?

Quote:
Originally Posted by ssj100
Same here.

Ditto
  #7  
Old July 26th, 2009, 08:11 AM
tlu's Avatar
tlu tlu is offline
Very Frequent Poster
 
Join Date: Sep 2004
Posts: 2,065
Default Re: Noscript bypass ?

Quote:
Originally Posted by Cudni
this is what i see on that page

Same here. StevieO, something must be misconfigured or broken on your system. Have you tried a new profile?
  #8  
Old July 26th, 2009, 08:54 AM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,416
Default Re: Noscript bypass ?

Maybe some scripts are partially allowed?
Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #9  
Old July 26th, 2009, 10:02 AM
Gizzy's Avatar
Gizzy Gizzy is offline
Regular Poster
 
Join Date: Oct 2007
Location: NJ, USA
Posts: 149
Default Re: Noscript bypass ?

Do you have flash disabled too?

I noticed in Opera this video works with javascript disabled but flash enabled.

EDIT: I just tried in firefox and it doesn't play the way I have noscript setup,
But if I uncheck "Forbid Adobe Flash" under the plug-ins tab in the noscript settings then it isn't blocked.
__________________
LUA+SRP - Windows Firewall - Sandboxie
  #10  
Old July 26th, 2009, 01:00 PM
Masterton Masterton is offline
Regular Poster
 
Join Date: Jul 2009
Posts: 101
Default Re: Noscript bypass ?

Quote:
Originally Posted by Cudni
this is what i see on that page
Same as Cudni.

The problem might be:
  • You haven't checked "forbid Adobe Flash" in NoScript Options > Plugins
  • The video is somehow hosted elsewhere and you have this domain whitelisted
  #11  
Old July 26th, 2009, 04:49 PM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Exclamation Re: Noscript bypass ?

When i checked the white list i started to think it may be due to those yimg ytming entries, so i removed them, no difference.

Then i saw the new posts and disabled Flash, which i thought i had after the last time i used it, and that did the trick, so Thanx for that.

The thing is, i thought Flash relied on Scripting in order to work. I know for a fact on every other www i've been to with Flash i get a notice that the page etc wont display properly etc.

So i'm not quite sure what's happening with FF and Flash. Could this be potential vulnerability vector if it works without Scripting ?

Also tested the link with IE, see screenie. What's ActiveX got to do with it if it's a Scripting issue, as you don't need ActiveX in FF to view, or Scripting it seems ?

In which case why do all those www's show that those things are required to view in various Browsers ?

Thanx to all who responded.
Attached Images
  
  #12  
Old July 26th, 2009, 04:57 PM
Trespasser's Avatar
Trespasser Trespasser is offline
Frequent Poster
 
Join Date: Mar 2005
Location: Clintwood, Virginia
Posts: 960
Default Re: Noscript bypass ?

Quote:
Originally Posted by Cudni
this is what i see on that page

Same here as well.

Later...
__________________
Ubuntu Precise (Cinnamon DE) 12.04 32bit on one laptop, Ubuntu Precise Gnome Fallback 12.04 32bit on another laptop, Ubuntu Precise (Cinnamon DE) 12.04 64bit on our main Desktop, and Xubuntu 13.04 64bit on our spare Desktop.


"I wish I knew as much as I think I do"...
  #13  
Old July 26th, 2009, 07:28 PM
TonyW TonyW is offline
Very Frequent Poster
 
Join Date: Oct 2005
Location: UK
Posts: 2,301
Default Re: Noscript bypass ?

By default, NoScript appears to block the Flash objects until allowed. I've never tinkered with the Plugins tab in Options; it's ticked here.
  #14  
Old July 27th, 2009, 07:46 AM
Ocky's Avatar
Ocky Ocky is offline
Very Frequent Poster
 
Join Date: May 2006
Location: George, S.Africa
Posts: 2,537
Default Re: Noscript bypass ?

If you are running Adblock Plus as well, and have these filters..
*ads*
*advert*
*banner*
....there will be no blocked script icons shown and no video, you will see a message to download flashplayer.
Without those filters No Script blocked script icons are shown (as they should).
You will see a red exclamation mark in Adblock Plus filter rules next to those
abovementioned filters warning that they are too short, unreliable, and may
slow down browsing.
  #15  
Old July 28th, 2009, 02:22 AM
wardner wardner is offline
Infrequent Poster
 
Join Date: Jul 2009
Posts: 3
Default Re: Noscript bypass ?

Flash is blocked by default in NoScript, resetting NS to default settings will do the trick, possibly reinstating other security options disabled inadvertently (3rd button from the left at the bottom)
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:03 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums