RSS Feed for This Post

XSS Warning - XSS Prevention Extension for Mozilla Firefox

Astalavista IT Security Member Area

When I was reading d0ubl3_h3lix’s security paper about Web Browser Plugins Vulnerabilities , I found out that there’s a Mozilla Firefox extension to prevent the execution of XSS threats that I’ve never tried before (because I only used FireKeeper before :P ) the extension itself ’s called ‘XSS Warning’ .

The further informations about this Mozilla Firefox Security extension :

Taken from http://www.zeropaid.com/bbs/archive/index.php/t-42967.html:
In the spirit of beta testing, I was sent a link from Gianni Amato on a new extension he’s written for Firefox called XSS Warning. Unsurprisingly, it warns you of potential XSS attacks on the URL string with a large blocking page. I have not spent a tremendous amount of time playing with this, but I had a few thoughts. Granted this is experimental, so I’m not trying to rip into it, because it definitely provides a service. But here are some thoughts.

Firstly, it only works in the case of reflected XSS. While that’s the most common form of XSS, it’s also only one form. Secondly, because it doesn’t generate an alert box, if the XSS is loaded inside of a hidden iframe, the user would never be warned that it failed (also making it easy to check for, incidentally). So while I love this research, and I want a lot more of it, this shouldn’t be considered a panacea, although I think we are well on our way now that we finally have people like Gianni and Giorgio looking at this. Very cool, and I encourage everyone to check it out.

Taken from the official website of XSS Warning :
XSS Warning is a extension for Firefox that fitre malicious values to prevent - with Javascript allowed - the Cross Site Scripting (XSS) attacks by malicious Http Request.

XSS Warning 0.3.4 protect from:

# Url attack

# Iframe attack

# Http request attack

This extension is compatible with Firefox 1.5 - 2.0.0.*
Install the latest release of XSS Warning right here !

Astalavista IT Security Member Area Looking for similar article like this? Try with these search terms, You will automatically go to Lifedork website search page with the term:
  • firefox extension bruteforce
  • hack friendster password guide
  • friendster hacking software
  • wireshark MSSQL
  • friendster hack forums
  • web hacking forum
  • pangolin sql download
  • python script exploit apache
  • friendster hack
  • Friendster com BruteForce
  • cross posting firefox warning
  • dork exploits
  • xploits 0day drupal
  • wep key generator
  • remote shell Apache/2 0 52
  • Trackback URL

    4 Comments

    • […] [Read the rest on (it)gossips network: lain] Related PostsEXPLOIT-ME ’s Finally Released!Technika Security Framework , Hackbar 1.1.1 : Mozilla Firefox Plugins for hacking purposesHacking Facebook Accounts using XSS video(new) Facebook.com XSS HackingTechnika - XSS Discovery Tool #2 […]

      • At 2008.04.22 07:57, r3ck0rd said:

        well at least my NoScript has this feature too :)

        • At 2008.04.22 08:01, r3ck0rd said:

          BTW, NoScript filters XSS by striping the html tags in the URL. So, only works for GET method URLs (ah whatever to say it :)).

          • At 2008.04.23 01:17, lain said:

            XSS Warning is not secure anymore anyway .. :) I’ll show you how it could be bypassed easily

          (Required)
          (Required, will not be published)