LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-26-2008, 07:11 AM   #1
[KIA]aze
Member
 
Registered: Jun 2006
Distribution: Debian, Ubuntu, Windows XP
Posts: 146

Rep: Reputation: 16
Linuxisos.de cross-scripting on Paypal: Is it necessary?


I wanted to buy something on http://linuxisos.de/ .
However, when I got to the Paypal page, NoScript notified me of a cross-scripting attempt.

Here's what I could copy from the console:
Quote:
[NoScript XSS] Sanitized suspicious upload to [https://secure.paypal.com/cgi-bin/webscr] from [https://www.linuxisos.de/checkout_confirmation.php]: transformed into a download-only GET request.
Is cross-scripting necessary in some cases or not?
Is there any valid reason for a website to do cross-scripting on paypal?

Is there a way to see the script that was sent to Paypal and know what it does?

Last edited by [KIA]aze; 03-26-2008 at 07:12 AM.
 
Old 03-28-2008, 06:53 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by [KIA]aze View Post
Is cross-scripting necessary in some cases or not?
If you read the NoScript FAQ you'll see you can get this message when you have the destination site whitelisted but the site from which the Javascript action originates not. If it's XSS this means an untrusted site is trying to make you believe it is OK to do stuff for it in a site you trust. OTOH if uploading data from one site to another is legitimate it shouldn't be called or tagged as XSS.


Quote:
Originally Posted by [KIA]aze View Post
Is there any valid reason for a website to do cross-scripting on paypal?
If you rephrase that more neutrally you're asking "is there a valid reason for a website to upload data to Paypal?". Since it involves HTTPS on both sides, the site probably mentioning Paypal transactions and it being the site you *expect* to do a transaction with that should be OK (me not having any idea about the way things are done by that site). If you are unsure you can always 0) enable Firefox to alert you when it thinks a site is bogus, 1) inspect the certificate more closely to see if it's valid, 2) check the 'net for problems with that site, 3) contact the owner (apparently he owns linuxisos.de, freesoft-shop.de and tuxonline-shop.de) or 4) use another site. If you are sure it's OK then just add this site to your whitelisting of trusted domains (for the duration of the transaction). BTW, also be careful about which plugins you have enabled: problems can occur when transforming plugins change data before NoScript sees it.


Quote:
Originally Posted by [KIA]aze View Post
Is there a way to see the script that was sent to Paypal and know what it does?
Per the NoScript FAQ at the time of the warning the details will be in Firefox' error console. You may be able to trap it either viewing the page or included sources or one of those plugins that intercepts data like Tamper Data, Firebug or the Web Developer one or a MITM proxy like Paros or Burp proxy.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Cross Site Scripting - Apache illiadum Linux - Security 1 08-28-2007 01:26 PM
LXer: Title: phpLDAPadmin Cross-Site Scripting and Script Insertion LXer Syndicated Linux News 0 04-26-2006 04:54 PM
ebay and paypal GraemeK General 7 02-14-2004 06:35 AM
cross site scripting - best method? lunardreamr Programming 1 09-26-2003 11:18 AM
May no longer be able to take PayPal jeremy LQ Suggestions & Feedback 16 09-13-2003 01:16 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:41 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration