[tor-bugs] #5477 [EFF-HTTPS Everywhere]: Surprising DOM origins before HTTPS-E/NoScript redirects have completed

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Wed Apr 18 21:24:44 UTC 2012


#5477: Surprising DOM origins before HTTPS-E/NoScript redirects have completed
------------------------------------------------------+---------------------
 Reporter:  Drugoy                                    |          Owner:  ma1           
     Type:  defect                                    |         Status:  needs_revision
 Priority:  major                                     |      Milestone:                
Component:  EFF-HTTPS Everywhere                      |        Version:                
 Keywords:  address spoofing, critical vulnerability  |         Parent:                
   Points:                                            |   Actualpoints:                
------------------------------------------------------+---------------------

Comment(by mikeperry):

 Ok, I'm almost done with this merge. I've noticed that IOUtil.js and
 Thread.js got folded into the main NoScript service component file. I've
 broken them back out again and updated our copies.

 I've also updated us to use the ChannelReplacement.js directly from NS
 2.3.7.

 I've pushed this to mikeperry/ns-2.3.7-merge. I still need to test it and
 describe the merging process in my diff script, and then push that.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/5477#comment:19>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list