U-Giorgio Maone, umdali wephrojekthi
Isengezo esiklanyelwe ukuvimba ikhodi ye-JavaScript eyingozi nengadingeki, kanye nezinhlobo ezahlukene zokuhlasela (
Omunye umehluko enguqulweni yokuhlola ye-NoScript ye-Chrome ukukhutshazwa kwesihlungi se-XSS esisetshenziselwa ukuvimba ukubhalwa phansi kwezindawo ezihlukene nokufaka esikhundleni sekhodi ye-JavaScript yenkampani yangaphandle. Kuze kube yilapho lesi sici sisebenza futhi, abasebenzisi kuzodingeka bathembele ku-XSS Auditor eyakhelwe ngaphakathi ye-Chrome, engasebenzi njengesihloli sokujova se-NoScript. Isihlungi se-XSS asikwazi ukuthunyelwa okwamanje ngoba sidinga ukucutshungulwa kwesicelo okungavumelani ukuze sisebenze. Ngesinye isikhathi, lapho uthuthela ku-WebExtension, onjiniyela be-Mozilla basebenzise kule API izici ezithile ezithuthukisiwe ezidingekayo ku-NoScript, njengezibambi ezingavumelanisi, i-Google engakayidluliseli ku-Chrome.
Source: opennet.ru