Purchase button requires XSS (cross-site scripting)
![](/sites/default/modules/gooforumold/images/info.png)
Purchase button requires XSS (cross-site scripting) | keshlam | 11/28/2008 - 00:18 |
... which the NoScript system considers a dangerous action, and I'm not willing to authorize it. That makes buying a full copy somewhat difficult. | ||
Re: Purchase button requires XSS (cross-site scripting) | The Happy Friar | 11/28/2008 - 17:38 |
you don't trust a company that, odds are, has been on the internet long then you have (what is it with all the security-paranoid people who want the game? Not directed towards you, but people have complained they're afraid someone will steal their CC info, the AV says WoG is a virus & they don't trust it, WoG uses some secret DRM that doesn't exist...)? From my experience, paypal is safer then going to the store & buying a copy. | ||
Re: Purchase button requires XSS (cross-site scripting) | keshlam | 11/28/2008 - 17:55 |
Actually, it's those of us who have been on the 'net for 30 years who are more likely to be cautious about security. We've seen the hazards evolve. | ||
Re: Purchase button requires XSS (cross-site scripting) | kyle | 11/28/2008 - 18:08 |
Hey guys, one other person asked about cross site scripting a few weeks ago, but they later looked at the html manually, and gave their thumbs up. | ||
Re: Purchase button requires XSS (cross-site scripting) | keshlam | 11/28/2008 - 18:45 |
Thanks, Kyle. | ||
Re: Purchase button requires XSS (cross-site scripting) | jrodman | 11/30/2008 - 19:38 |
XSS scripting doesn't mean that the site is malicous, it means that the way the site is written, it's open for an unpleasant user of the site to inject malicious content for other users to encounter. It's a channel by which some users can attack other users. So that the code was given by PayPal doesn't mean that it's safe. | ||
Re: Purchase button requires XSS (cross-site scripting) | keshlam | 12/01/2008 - 00:11 |
JRodman: Thanks. That was sorta my understanding -- no accusation of malice, just a question of whether the site was as secure as it might be, and whether it might be worth looking for ways to tighten this up to avoid unnecessarily confusing/scaring potential customers. | ||
Re: Purchase button requires XSS (cross-site scripting) | jrodman | 12/14/2008 - 17:18 |
Yeah, way late, this is a paypal thing. And they should address it, but I don't believe it is a pressing issue, since I don't believe it's exploitable. |