Thawj qhov kev tshaj tawm pej xeem ntawm NoScript add-on rau Chrome

Giorgio Maone, tus tsim qhov project NoScript, tswvcuab Thawj qhov kev tso tawm ntawm qhov txuas ntxiv rau Chrome browser muaj rau kev sim. Qhov tsim sib raug rau version 10.6.1 rau Firefox thiab tau ua tiav ua tsaug rau kev hloov ntawm NoScript 10 ceg rau WebExtension thev naus laus zis. Chrome tso tawm yog nyob rau hauv beta xwm txheej thiab muaj mus download tau los ntawm Chrome Web Store. NoScript 11 tau npaj yuav tso tawm thaum kawg Lub Rau Hli, uas yuav yog thawj zaug tso nrog kev txhawb nqa ruaj khov rau Chrome / Chromium.

Ib qho ntxiv-on tsim los thaiv qhov txaus ntshai thiab tsis xav tau JavaScript code, nrog rau ntau hom kev tawm tsam (XSS, DNS Rebinding, CSRF, Tshawb Xyuas), siv los ua ib feem ntawm Tor Browser thiab ntau yam kev faib tawm ntiag tug. Nws tau raug sau tseg tias qhov tsos ntawm lub version rau Chrome yog ib qho tseem ceeb theem nyob rau hauv txoj kev loj hlob ntawm lub project - code puag yog tam sim no sib koom ua ke thiab tuaj yeem siv los tsim kev sib dhos rau Firefox thiab browsers raws li Chromium cav.

Ib qho ntawm qhov sib txawv ntawm qhov kev sim version ntawm NoScript rau Chrome yog qhov kev tsis ua haujlwm ntawm XSS lim siv los thaiv cov ntawv sau sib txuas thiab hloov pauv ntawm tus neeg thib peb JavaScript code. Txog thaum qhov no tau nce thiab ua haujlwm, cov neeg siv yuav tau tso siab rau Chrome's built-in XSS Auditor, uas tsis zoo li NoScript's Injection Checker. Lub lim XSS tsis tuaj yeem muab xa mus tau vim nws xav tau kev thov asynchronous ua haujlwm. Nyob rau hauv ib lub sij hawm, thaum tsiv mus rau WebExtension, Mozilla developers tau siv nyob rau hauv no API ib co advanced nta tsim nyog rau NoScript, xws li asynchronous handlers, uas Google tseem tsis tau pauv mus rau Chrome.

Tau qhov twg los: opennet.ru

Ntxiv ib saib