Page 1 of 1

Cross-site scripting

Posted: Wed Nov 22, 2017 5:06 pm
by Carlos996
What's this?

https://i.imgur.com/dSyFyO7.png
https://pt.wikipedia.org/wiki/Cross-site_scripting
https://en.wikipedia.org/wiki/Cross-site_scripting
https://www.acunetix.com/websitesecurit ... scripting/


NoScript detected a potential Cross-Site Scripting attack

from https://www.opensubtitles.org to https://www.facebook.com.

Suspicious data:

window.name,(POST) cd[Schema.org]=[{"type":"http://schema.org/Organization","proper ... :"Swallows and Amazons subtitles Portuguese ","image":"//static7.opensubtitles.org/gfx/thumbs/3/8/1/7/1227183.jpg","datePublished":"2017-11-22T14:15:25+01:00","keywords":"The adventure begins","description":"Four children (the Swallows) on holiday in the Lake District sail on their own to an island and start a war with rival children (the Amazons). In the meantime, a mysterious man on a houseboat accuses them of a crime they did not commit."},"subscopes":[{"type":"http://schema.org/AggregateRating","pro ... :"Philippa Lowthorpe"},"subscopes":[]},{"type":"http://schema.org/Person","properties": ... me":"Bobby McCulloch"},"subscopes":[]},{"type":"http://schema.org/Movie","properties":{ ... "subscopes":[]}]}]

Re: Cross-site scripting

Posted: Sat Nov 25, 2017 1:57 pm
by oss
very strange, there is no XSS on site. Maybe some error in addon?

Re: Cross-site scripting

Posted: Sun Nov 26, 2017 12:53 am
by Carlos996
It's what happen recently everytime i try to download or upload any subtitle.

Re: Cross-site scripting

Posted: Mon Nov 27, 2017 4:18 am
by oss
I see some facebook there, so probably thats facebook problem

Re: Cross-site scripting

Posted: Tue Nov 28, 2017 11:12 pm
by SmallBrother
That's the problem with embedding other websites into your own.
Basically you allow third parties to edit your pages...

Re: Cross-site scripting

Posted: Wed Dec 27, 2017 12:27 pm
by oss
having facebook like is ok I think.

Re: Cross-site scripting

Posted: Wed Dec 27, 2017 1:38 pm
by SmallBrother
I definitely disagree :)