History | Log In     View a printable version of the current page.  
Issue Details (XML | Word | Printable)

Key: OQA-31
Type: Improvement Improvement
Status: Open Open
Priority: Critical Critical
Assignee: Patrick Lightbody
Reporter: Owen Carter
Votes: 0
Watchers: 1
Operations

If you were logged in you would be able to see more operations.
OpenQA

Script blocker (noscript) in firefox seems to think about:blank is running scripts on your forum and main websites?

Created: 05/Apr/07 09:36 AM   Updated: 10/Apr/07 04:59 AM
Component/s: Forums, Website
Affects Version/s: None
Fix Version/s: None

Original Estimate: Unknown Remaining Estimate: Unknown Time Spent: Unknown
Environment: Firefox 2.0.0.3 on Windows XP sp2, with the noscript extension installed (see http://noscript.net/)


 Description  « Hide
Hi,

When I visit either the forums or main website at openqa.org my script blocker tool in FireFox, (NoScript, http://noscript.net) is indicating that it is blocking scripts from 'about:blank'

This is weird, I do not see this on any other website (or I'd be blaming my setup), nor does it happen when I am on your Jira site. Looking at your page source reveals no references to about:blank, nor does it show up on any of the page/object properties.

I am concerned because it may be a attack vector; some posts I see indicate it may be a 'Phishermans Friend', see:
http://www.dozleng.com/updates/index.php?s=cfaa7db32e0b513e7c9a20eace212dd1&showtopic=13234
http://seclists.org/fulldisclosure/2007/Feb/0427.html

Of course, that may be a total red-herring, and this is something you are doing intentionally, or it may not be specific to you at all and I only see it on your sites due to some other issue with my system. I just don't understand this well enough to investigate further. But I thought I should at least create this issue so that you are aware of it, just in case it is a serious problem.


 All   Comments   Work Log   Change History      Sort Order:
Owen Carter - 10/Apr/07 04:59 AM
Hi!
Looks like I was mistaken about this being a serious problem;
http://noscript.net/faq#qa1_9
It's just that you (or your CMS) are opening a empty document/frame with scripting injected, it has the title 'about:blank' by default, hence I see it in the script blocker. Because the scripting has to be injected by another script which I already allow, it's safe to allow this too.
Sorry about bothering you, I just failed to find this FAQ when I searched originally. I'm happy if you just close this.
Owen.