Improves protection against XSS (cross-site scripting) and ClearClick

Mar 27, 2012 11:45 GMT  ·  By

A new release for NoScript extension for Mozilla Firefox is available. Revision 2.3.6 took only four release candidates to roll out as a stable. It brings to the table both fixes and improvements.

As far as improvements are concerned, NoScript 2.3.6 shows better protection against ClearClick events, as far as Disqus widgets are concerned. The new version also optimizes trailing "*" in glob expressions (AddressMatcher).

As for the repairs, these do not abound, as there are only three entries available. The current revision of the extension restores compatibility with the Nightly version of Firefox. Also, it fixes the origin URL detection, so it should work when certain wrapped URLs are loaded.

Last on the list of fixes is an entry relating to XSS (cross-site scripting) protection: elimination of false positive with query string patterns mimicking array access.

Download NoScript