Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

XSS cross-site scripting here?


  • Please log in to reply
4 replies to this topic

#1 tos226

tos226

    BleepIN--BleepOUT


  • Members
  • 1,568 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:LocalHost
  • Local time:08:56 AM

Posted 18 March 2016 - 10:29 PM

When I'm here, NoScript in SeaMonkey issues a yellow line about potential cross-site scripting, and this is logged to the Console:

[NoScript XSS] Sanitized suspicious request. Original URL [https://apis.google.com/se/0/_/+1/fastbutton?usegapi=1&size=small&count=false&hl=en-GB&origin=http%3A%2F%2Fwww.bleepingcomputer.com&url=http%3A%2F%2Fwww.bleepingcomputer.com%2Fforums%2Ft%2F591240%2Fwindows-10-wont-go-into-sleep-mode%2F&gsrc=3p&ic=1&jsh=m%3B%2F_%2Fscs%2Fapps-static%2F_%2Fjs%2Fk%3Doz.gapi.en_US.Rkahwc9_QbI.O%2Fm%3D__features__%2Fam%3DAQ%2Frt%3Dj%2Fd%3D1%2Frs%3DAGLTcCOJ4AMNA1EZSgGPzZnainRbXAPPWA#_methods=onPlusOne%2C_ready%2C_close%2C_open%2C_resizeMe%2C_renderstart%2Concircled%2Cdrefresh%2Cerefresh&id=I0_1458360970599&parent=http%3A%2F%2Fwww.bleepingcomputer.com&pfname=&rpctoken=28747844] requested from [http://www.bleepingcomputer.com/forums/t/591240/windows-10-wont-go-into-sleep-mode/]. Sanitized URL: [https://apis.google.com/#3379802305398062447].

Am I supposed to do anything? Worry? Not worry? I've been ignoring it since I'm able to post and answer, but I thought I should ask in case someone here understands how to read this sort of stuff.



BC AdBot (Login to Remove)

 


#2 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,472 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:08:56 AM

Posted 19 March 2016 - 08:47 AM

Looks like something in the google+ api changed. Will just remove that social option for now.

#3 ScathEnfys

ScathEnfys

    Bleeping Butterfly


  • Members
  • 1,375 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Deep in the Surface Web
  • Local time:08:56 AM

Posted 22 March 2016 - 07:04 PM

Yea I've been getting that issue too. If there really is an issue in the g+ API... Let's just say I'm glad I run NoScript.


Proud system builder, modder, and watercooler.

GitHub | SoundCloud | Keybase

#4 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,472 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:08:56 AM

Posted 29 March 2016 - 11:06 PM

Is this still happening for you guys?

#5 tos226

tos226

    BleepIN--BleepOUT

  • Topic Starter

  • Members
  • 1,568 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:LocalHost
  • Local time:08:56 AM

Posted 01 April 2016 - 11:20 AM

Just came here. No alert. No message.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users