Kekutanga kuburitswa pachena kweNoScript yekuwedzera yeChrome

Giorgio Maone, mugadziri weNoScript purojekiti, akapa kuburitswa kwekutanga kweiyo-add-on yeChrome browser, iripo pakuedzwa. Kuvaka kunoenderana neshanduro 10.6.1 yeFirefox uye zvakaitwa kuti zvigoneke nekuda kwekuendeswa kwebazi reNoScript 10 kune tekinoroji yeWebExtension. Kuburitswa kweChrome kuri mubeta uye inowanikwa kurodha kubva kuChrome Web Store. NoScript 11 yakarongwa kuburitswa mukupera kwaChikumi, inove yekutanga kuburitswa nerutsigiro rwakatsiga rweChrome/Chromium.

Iyo yekuwedzera-yakagadzirirwa kuvharira ine njodzi uye isingadiwe JavaScript kodhi, pamwe nemhando dzakasiyana dzekurwiswa (XSS, DNS Rebinding, CSRF, Clickjacking), inoshandiswa sechikamu cheTor Browser uye yakawanda yakanangana nekuvanzika kugovera. Zvinocherechedzwa kuti kutaridzika kweshanduro yeChrome inhanho yakakosha mukuvandudzwa kweprojekiti - iyo kodhi base ikozvino yakabatana uye inogona kushandiswa kugadzira magungano eFirefox uye mabhurawuza zvichienderana neChromium injini.

Mumwe wemisiyano muyedzo vhezheni yeNoScript yeChrome kudzima kweXSS sefa inoshandiswa kuvharira kuyambuka-saiti kunyora uye kutsiva yechitatu-bato JavaScript kodhi. Kusvikira chimiro ichi chatanga uye kushanda, vashandisi vachafanira kuvimba neChrome's yakavakirwa-mukati XSS Auditor, iyo isingashande seNoScript's Injection Checker. Iyo XSS sefa haigone kutakurwa parizvino nekuti inoda asynchronous application processing kuti ishande. Pane imwe nguva, pakuenda kuWebExtension, vagadziri veMozilla vakaisa muAPI iyi zvimwe zvepamberi zvinodiwa kuNoScript, senge asynchronous handlers, iyo Google isati yaendesa kuChrome.

Source: opennet.ru

Voeg