New issue
Advanced search Search tips

Issue 710862 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 702542
Owner: ----
Closed: Apr 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

ERR_BLOCKED_BY_XSS_AUDITOR false positive in VBulletin

Reported by ad...@epicnpc.com, Apr 12 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36

Steps to reproduce the problem:
1. Go to site using Vbulletin 
2. Click Edit, then "Advanced Edit"
3. ERR_BLOCKED_BY_XSS_AUDITOR error appears

What is the expected behavior?
I should be able to edit my post

What went wrong?
Normal links are triggering these error messages.

If I remove these links from my post using the "Quick Edit" feature, I can then click "advanced edit" without the error. If the links remains, I get the error.

These are just normal forum links and should not trigger a security alert.

Example:
https://www.epicnpc.com/threads/1019842-Account-Store-Lv-Ar-8-Legend-CN-LD-from-5-Updated  (a normal post on our site)
the URL code is the trigger, if I remove the link code, and just leave plain text, it does not trigger the error.

https://www.epicnpc.com/itrader.php?u=474815  (our feedback system)
itrader.php is the trigger

Did this work before? Yes Problem started with Chrome Version 57.0.2987.133

Chrome version: 57.0.2987.133  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: 

Epicnpc does not allow any members to post passwords, phone numbers, or credit cards. In the very rare case someone does this, we remove it immediately and ban that member.
 
Components: Blink>SecurityFeature>XSSAuditor
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Summary: ERR_BLOCKED_BY_XSS_AUDITOR false positive in VBulletin (was: ERR_BLOCKED_BY_XSS_AUDITOR false positive)
This is likely dupe of comment#3 in Issue 702542 although it includes more details and is specific to a particular website platform which is useful.

Sites can opt-out of the XSS Auditor by sending an X-XSS-Protection: 0 response header.

Comment 2 by tsepez@chromium.org, Apr 12 2017

Mergedinto: 702542
Status: Duplicate (was: Unconfirmed)

Sign in to add a comment