Quantcast
Channel: InformAction Forums
Viewing all articles
Browse latest Browse all 17374

Re: NoScript and Yandex Maps Panorama

$
0
0
therube wrote:
[NoScript] Blocking cross-site Javascript served from http://yandex.st/swf/panoplayer/3_1/version?_=1361376287829 with wrong type info application/octet-stream and included by http://maps.yandex.ua/?ll=30.501199%2C50.464807&spn=0.914612%2C0.104749&z=11&l=map%2Cstv&ol=stv&oll=30.50119929%2C50.46480673


Erk. This again.

Best to get it fixed on their end.
Though suppose an exception could be entered.
(I'll leave that for others.)

Yeah...search the forum for 'liberoquotidiano' and you'll find the workaround.
(Sure would be nice when these XSS things hit that we'd be notified.)

It's not actually XSS, it's something else. Unless I'm mistaken, they're importing a script that isn't meant to be imported as a script; it's supposed to be read as binary data.

The strange thing is that it's coming from their own site. Maybe they just messed up their MIME types.

Viewing all articles
Browse latest Browse all 17374

Trending Articles