Do you use NoScript ( Firefox Addon )

Discussion in 'polls' started by Joeythedude, Jan 4, 2012.

?

Do you use noscript to handle Javascript

  1. Yes

    91 vote(s)
    52.0%
  2. No

    84 vote(s)
    48.0%
  1. Daveski17

    Daveski17 Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    10,239
    Location:
    Lloegyr
    OK, I understand what you mean now (I think). ;)
     
  2. tlu

    tlu Guest

    I had asked that question before but never got a response: The XSS filter in Chrome was disabled in earlier versions because of performance considerations. Is there a reference that confirms that it has been re-enabled? I haven't found any.
     
  3. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    It's been enabled since Chrome 13. Chrome 11 introduced the experimental version.
     
  4. tlu

    tlu Guest

    Thanks :thumb: Do you have any source for that?
     
  5. tlu

    tlu Guest

    :D Okay, I was just pointing to the fact that there are alternatives for WOT. And at least you have the chance to make a decision - you won't if you allow scripting globally.

    Has this issue been fixed in the meantime?
     
  6. LoneWolf

    LoneWolf Registered Member

    Joined:
    Jan 2, 2006
    Posts:
    3,784
    http://blog.chromium.org/2010/01/security-in-depth-new-security-features.html
     
  7. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    I can't find a source and I'm going by memory. But since I know Chrome's XSS auditor has been bypassed* it's safe to say that it's on.

    *The bypass is significantly difficult to pull off and requires the attacker already having partial control over a large part of a page.
     
  8. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
  9. tlu

    tlu Guest

  10. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,642
    Location:
    USA
    I used to use it. For quite some time actually. Eventually I found it to just be too much work.
     
  11. vasa1

    vasa1 Registered Member

    Joined:
    May 1, 2010
    Posts:
    4,417
    There's this switch:
    Code:
    --disable-xss-auditor
    which I came across here and also

    Code:
    --disable-xss-auditor ⊗ 	Disable WebKit's XSSAuditor. The XSSAuditor mitigates reflective XSS. 
    over here
     
  12. wat0114

    wat0114 Guest

    Maybe, but not really sure. I got an XSS alert from IE when I tried the POC (from the link you provided - they seem to enthusiastically promote FF + NS :rolleyes: ) here.

    BTW, there's an interesting page from Acunetix here:

    -http://www.acunetix.com/websitesecurity/xss.htm

    The first copy/paste resilts in the fake login page, but the http...copy/paste results in IE9 alerting to XSS activity.
     

    Attached Files:

  13. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    I would be very surprised if IE had not solved that issue.
     
  14. wat0114

    wat0114 Guest

    Yeah, same here, though I couldn't find any patch info on it.
     
  15. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Considering how embarrassing it is they probably didn't publicize it much.
     
  16. tlu

    tlu Guest

    Thanks, this also confirms what Hungry said.
     
  17. tlu

    tlu Guest

    The same results with Noscript and default settings. However, if I change

    noscript.injectionCheck

    to 3 in about:config (check every request, not only cross-site requests), I get an XSS warning also for the first test.

    EDIT: I do not get any XSS warning in both cases with Chromium 17.
     
    Last edited by a moderator: Jan 8, 2012
  18. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    Yes, I do.

    NoScript is the main reason why I prefer Firefox over other browsers. I don't spend any time whitelisting/blacklisting sites. Basically, I handle all sites as "scripts currently forbidden", if something needs to be allowed, I just allow it temporarily and don't worry about it. I have 10 sites on my whitelist and those are the same sites that were on my whitelist a couple of years ago.

    I love NoScript and it works great. If some option gets changed by me while browsing, when I close my sandboxed browser, all things related to NS go back to how I have it setup. It can not be any better.

    Bo
     
  19. twl845

    twl845 Registered Member

    Joined:
    Apr 12, 2005
    Posts:
    4,186
    Location:
    USA
    I've been using NoScript for some years. After reading this thread I disabled it as an experiment. I immediately found that cold load time has gone from 16 seconds to 6. The only other annoyance is when I am buying on line and enter my name, address and visa number and click continue. Nothing happens and I fear a frozen screen, only to remember that the NoScript has forbidden the site and I have to temporarily allow it. I guess it's good that happens but It's a PITA. How important is NoScript as opposed to AD Block Plus?
     
  20. TheKid7

    TheKid7 Registered Member

    Joined:
    Jul 22, 2006
    Posts:
    3,576
    Same here. However, I still have the NoScript Addon with scripts Globally Allowed.

    Even with scripts Globally Allowed there is still protection against a potential threat. I think that the potential threat is XSS, but I do not remember for sure.
     
  21. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    NoScript provides from multiple attacks even when a site is whitelisted.

    One of those is XSS. Another is ClickJacking.
     
  22. ichito

    ichito Registered Member

    Joined:
    Jan 14, 2011
    Posts:
    1,997
    Location:
    Poland - Cracow
    Exactly the same...NoScript is the obligatory add-on. From my favourite sites: only trusted sites are allowed (not "disabled"), I haven't sites with disabled NS, on all the rest NS can be only temporary "allowed".
     
  23. ams963

    ams963 Registered Member

    Joined:
    May 3, 2011
    Posts:
    6,039
    Location:
    Parallel Universe
    same here....noscript is my absolute favorite along adblock plus.......
     
  24. EncryptedBytes

    EncryptedBytes Registered Member

    Joined:
    Feb 20, 2011
    Posts:
    449
    Location:
    N/A
    I use it in conjunction with requestpolicy add-on. There is some overlap between the two though they effectively nuke anything that has not been predefined by me script wise etc. They are specifically configured to play nice with the websites I trust to visit only on my host OS. All my main surfing is done on my guest Os’s so I tend not to worry about javascript being bad.
     
  25. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    I use Globally Allowed with a large personal blacklist (mostly for privacy). Its other features are all enabled, including embedding restrictions for whitelisted sites.
    Also got it in normal whitelisting mode on netbook to save more resources.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.