Asalka uBlock 1.39.0 Xannibaadda Xayeysiiska Isku-darka oo la sii daayay

Siideynta cusub ee xannibaadaha waxyaabaha aan la rabin uBlock Origin 1.39 ayaa diyaar ah, taasoo bixisa xannibaadda xayeysiinta, walxaha xaasidnimada leh, koodhka raadraaca, macdan qodayaasha JavaScript iyo walxaha kale ee farageliya hawlgalka caadiga ah. Isku-darka uBlock Origin waxaa lagu gartaa waxqabadka sare iyo isticmaalka xusuusta dhaqaale, wuxuuna kuu ogolaanayaa inaadan ka takhalusin oo keliya walxaha xanaaqa, laakiin sidoo kale si aad u yareyso isticmaalka kheyraadka iyo dardargelinta boggaga.

Isbeddellada ugu waaweyn:

  • Badhan ayaa lagu daray guddiga soo booda si loo soo diro ogaysiisyada ku saabsan dhibaatooyinka la kulmay markii la shaqeynayey goobta marka la isticmaalayo uBlock Origin. Badhanku wuxuu kuu ogolaanayaa inaad si dhakhso leh ugu gudbiso macluumaadka ku saabsan dhibaatooyinka liisaska la socda filtarrada.
  • Guddi Taageero ayaa lagu daray qaabeeyaha, taasoo sahlaysa in loo diro macluumaadka farsamada ee ku saabsan qaabaynta uBlock Origin horumariyeyaasha si loo ogaado dhibaatooyinka.
  • Daalacashada ku salaysan mishiinka Chromium, dhibaatada filtarrada isqurxinta oo aan si sax ah ugu shaqaynayn goobo badan marka qaabka "Tijaabada Shabakadda Platform-ka" uu awood u yeesho browserka ku jira chrome: // calanka la xalliyey.
  • Taageero lagu daray CSS-ka-fasalada been-abuurka ah.
  • Arrin ku saabsan ka gudubka xannibaadda xayeysiinta Twitch waa la xalliyey.
  • Arrimaha amniga ayaa la hagaajiyay:
    • Awoodda lagu dhaafo xannibaadaha isticmaalka CSS ee khatarta ah (sida asalka:url()) ee shaandhada qurxinta ee loogu talagalay in lagu beddelo waxa ku jira bogga.
    • Awoodda lagu soo diro codsiyada asalka ah iyada oo loo marayo filtarrada isqurxinta iyadoo la adeegsanayo image-set() beddelka shaqada CSS ee Firefox, in kasta oo mamnuucidda adeegsiga url() hawlaha fasalka ee xeerarka si loo xakameeyo daadinta macluumaadka isticmaalaha haddii ay dhacdo xeerar xaasidnimo ah in lagu meeleeyo liisaska shaandhaynta.
    • Waxa suurtagal ahayd in URL-yada lagu beddelo koodka JavaScript ama loo jiheeyo bogag kale iyada oo la adeegsanayo xad-gudubyada xargaha su'aalaha. Tusaale ahaan, markaad gujinayso isku xirka "https://subscribe.adblockplus.org/?location=javascript:alert(1)&title=EasyList" iyo "https://subscribe.adblockplus.org/?location=dashboard.html %23about .html&title=EasyList" waxa uu soo bandhigayaa bogga adeegga uBlock Origin oo wata xiriiriye, kaas oo, marka la gujiyo, fulin doona koodka JavaScript ama furi doona bog kale.

Source: opennet.ru

Add a comment