andryou / scriptsafe

a browser extension to bring security and privacy to chrome, firefox, and opera
https://www.andryou.com/scriptsafe
509 stars 79 forks source link

ScriptSafe v1.0.9.3 not actually blocking SCRIPT on all sites #390

Open ghost opened 5 years ago

ghost commented 5 years ago

Prior to ScriptSafe v1.0.9.3 I would have to allow for any and every SCRIPT attempt on every site visited.

That is no longer the case.

This is a fresh / clean install on: Win10 x64 1809 B 17763.134 Chrome (Version 71.0.3578.98 (Official Build) (64-bit)) Chromium (Version 73.0.3635.0 (Official Build) (64-bit))

SS config : webbugs|true gamepad|true syncnotify|true fpWebGL|[] useragentspoof|off syncfromnotify|true fpBattery|[] frame|true fpBluetooth|[] uaspoofallow|false webvr|true whiteList|["*.googlevideo.com"] hashallow|true webrtcdevice|true useragentintervalmins|5 updatenotify|true fpWebVR|[] lastSync|0 applet|true paranoia|true referrer|alldomains embed|true syncenable|false cookies|true bluetooth|true fpClipboard|[] noscript|true showcontext|true fpAudio|[] browserplugins|true refresh|true keydelta|40 canvas|block clipboard|false linktarget|off annoyancesmode|strict referrerspoof|off webgl|true antisocial|true battery|true annoyances|true sync|true audio|true timezone|random preservesamedomain|strict dataurl|false enable|true blackList|[] audioblock|true clientrects|false xml|all referrerspoofdenywhitelisted|false classicoptions|false webrtc|default_public_interface_only useragent|[""] useragentspoof_os|off fpCanvas|[] video|true fpBrowserPlugins|[] object|true optionslist|true fpCanvasFont|[] iframe|true utm|true mode|block fpGamepad|[] canvasfont|true locale|en_US fpDevice|[] keyboard|false hashchecking|true fpClientRectangles|[] useragentinterval|off script|true rating|false domainsort|true image|false

This was automatically allowed out of the box even though I have not allowed a single domain to execute scripts:

02:18:09 https://mangabat.com/cdn-cgi/scripts/5c5dd728/cloudfla... SCRIPT https://mangabat.com/manga_list?type=latest&category=a... DenyDistrustTemporary 02:18:09 https://mangabat.com/themes/home/js/custom.js?v=1.2.8 SCRIPT https://mangabat.com/manga_list?type=latest&category=a... DenyDistrustTemporary 02:18:09 https://mangabat.com/themes/home/js/fsearch.js?v=1.2.8 SCRIPT https://mangabat.com/manga_list?type=latest&category=a... DenyDistrustTemporary 02:18:09 https://mangabat.com/themes/starrate/js/starwarsjs.js?... SCRIPT https://mangabat.com/manga_list?type=latest&category=a... DenyDistrustTemporary 02:18:09 https://mangabat.com/themes/home/js/owl.carousel.js?v=... SCRIPT https://mangabat.com/manga_list?type=latest&category=a... DenyDistrustTemporary 02:18:09 https://mangabat.com/themes/home/js/cookie.js?v=1.2.8 SCRIPT https://mangabat.com/manga_list?type=latest&category=a... DenyDistrustTemporary 02:18:09 https://mangabat.com/themes/home/js/menu-js.js?v=1.2.8 SCRIPT https://mangabat.com/manga_list?type=latest&category=a... DenyDistrustTemporary 02:18:09 https://mangabat.com/themes/home/js/jquery.slicknav.mi... SCRIPT https://mangabat.com/manga_list?type=latest&category=a... DenyDistrustTemporary 02:18:09 https://mangabat.com/themes/home/js/ddimgtooltip.js?v=... SCRIPT https://mangabat.com/manga_list?type=latest&category=a... DenyDistrustTemporary 02:18:09 https://mangabat.com/themes/home/js/jquery-1-11.js?v=1... SCRIPT https://mangabat.com/manga_list?type=latest&category=a... DenyDistrustTemporary 02:18:09 https://mangabat.com/manga_list?type=latest&category=a... PAGE https://mangabat.com/manga_list?type=latest&category=a...

Consequently... GitHub (a site i trust) and AdGuard (an app I trust) are blocked out of the box:

02:19:20 https://github.githubassets.com/assets/github-3de8d18c... SCRIPT https://github.com/andryou/scriptsafe/issues AllowTrustTemporary 02:19:20 https://github.githubassets.com/assets/frameworks-24c7... SCRIPT https://github.com/andryou/scriptsafe/issues AllowTrustTemporary 02:19:20 https://local.adguard.com/adguard-ajax-api/injections/... SCRIPT https://github.com/andryou/scriptsafe/issues AllowTrustTemporary 02:19:20 https://local.adguard.com/adguard-ajax-api/injections/... SCRIPT https://github.com/andryou/scriptsafe/issues AllowTrustTemporary 02:19:17 https://github.githubassets.com/assets/github-3de8d18c... SCRIPT https://github.com/login?return_to=%2Fandryou%2Fscript... AllowTrustTemporary 02:19:17 https://github.githubassets.com/assets/frameworks-24c7... SCRIPT https://github.com/login?return_to=%2Fandryou%2Fscript... AllowTrustTemporary 02:19:17 https://local.adguard.com/adguard-ajax-api/injections/... SCRIPT https://github.com/login?return_to=%2Fandryou%2Fscript... AllowTrustTemporary 02:19:17 https://local.adguard.com/adguard-ajax-api/injections/... SCRIPT https://github.com/login?return_to=%2Fandryou%2Fscript... AllowTrustTemporary 02:18:56 https://github.githubassets.com/assets/github-3de8d18c... SCRIPT https://github.com/andryou/scriptsafe/issues AllowTrustTemporary 02:18:56 https://github.githubassets.com/assets/frameworks-24c7... SCRIPT https://github.com/andryou/scriptsafe/issues AllowTrustTemporary 02:18:56 https://local.adguard.com/adguard-ajax-api/injections/... SCRIPT https://github.com/andryou/scriptsafe/issues AllowTrustTemporary 02:18:56 https://local.adguard.com/adguard-ajax-api/injections/... SCRIPT https://github.com/andryou/scriptsafe/issues AllowTrustTemporary 02:18:50 https://github.githubassets.com/assets/github-3de8d18c... SCRIPT https://github.com/andryou/scriptsafe AllowTrustTemporary 02:18:50 https://github.githubassets.com/assets/frameworks-24c7... SCRIPT https://github.com/andryou/scriptsafe AllowTrustTemporary 02:18:50 https://local.adguard.com/adguard-ajax-api/injections/... SCRIPT https://github.com/andryou/scriptsafe AllowTrustTemporary 02:18:50 https://local.adguard.com/adguard-ajax-api/injections/...