Support

Admin Tools

#12220 Cross Site Scripting Firefox

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Wednesday, 09 May 2012 09:17 CDT

zagirova
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? No
Have I searched the tickets before posting? No
Have I read the documentation before posting (which pages?)? No
Joomla! version: 1.5.20
PHP version: 5.3
MySQL version: (unknown)
Host: (optional, but it helps us help you)
Admin Tools version: (unknown)

Description of my issue:
I've disable cross site scripting but it still present on Firefox. Please, help.

nicholas
Akeeba Staff
Manager
Hello Liza,

Joomla! 1.5.20 is an old and insecure version of Joomla! which is no longer supported by the Joomla! project and us. Please upgrade to Joomla! 1.5.26 immediately.

After doing that, please try using Chrome instead of Firefox. We are aware that Firefox versions 5 through 9 (inclusive) are extremely buggy and cause a lot of issues not only with our products but with pretty much everything. Bluntly put, they are as stable as a barrel of nitroglycerin rolling down a bumpy hill.

If the problem persists, please explain what you mean with "I've disable cross site scripting but it still present". Do you mean that you've set the XSSShield option in the Configure WAF page to No, clicked on Save, but when you go back to the page it is still enabled?

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

zagirova
What do you mean - use Chrome? Do I need to tell this to hackers: please, use chrome?
Still present mean, that there is security department of my customer's company and they make me to fix some security issues and XSS in all browsers - is one of the issues.

nicholas
Akeeba Staff
Manager
Liza, don't get excited. Read your message again, please:
I've disable cross site scripting but it still present on Firefox.

This is kinda vague for someone who has no idea what your site is and doesn't sit in front of computer.

What I think what you wrote means: I tried to disable the XSSShield feature, but it's still enabled. I am using Firefox. (Obviously, this not the case)

What you (most likely) intended for this to mean: I have enabled the XSSShield feature, but I still get notifications about XSS attacks in emails and the Security Exceptions Log. (However, that's just my wild guess on what you mean and I decline to provide support based on wild guesses)

Unfortunately, I am not clairvoyant and I can not reply to all possible interpretations of a vague support request. Can you please explain exactly what you did, what you see and what you think the problem is so that I can help you? Remember that I am neither sitting in front of your computer not am I inside your head. Unless you explain to me well enough what the problem you want help with is, how can I possibly help you? Help me help you, please, instead of getting excited. Thank you!

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

zagirova
Then sorry about it.

I've customer (Insurance company of some big bank). Annually security department of bank is testing all their websites and web application. As I'm giving maintenance to one of their website, I've got request to deal with some insecure issues they found in my website. Thats why actually I've installed AdminTools. All issues was solved but not XSS in Firefox, like security department told me in email. Its still vulnerable in Firefox.

nicholas
Akeeba Staff
Manager
That's why I asked you to upgrade to Joomla! 1.5.26 first. You have 1.5.20. Versions 1.5.21 up to and including 1.5.26 have fixed several XSS vulnerabilities. While you are at it, please upgrade all extensions on the site: components, modules, plugins and templates (templates have code, don't gorget about them). Finally, please make sure that none of your extensions is listed in a red-coloured VEL entry. The green-coloured ones have no problem, as long as you update them.

That said, cross site scripting attacks are something which has to do with the web server software, not the browser. In other words, it's not possible that your site is vulnerable to XSS when the attacker uses Browser X but not Browser Y. Please read the Wikipedia entry on XSS for some introductory information. I am really curious as to how the security department came to the conclusion that your site is vulnerable only through Firefox. This sounds like a bogus security report or a misunderstaning.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!