NoScript - Firefox Addon allows JavaScript, Java and other executable content to run only from trusted domains of your choice, e.g. your home-banking website, guarding your "trust boundaries" against cross-site scripting attacks (XSS) and Clickjacking attempts, thanks to its unique ClearClick technology.
Such a preemptive approach prevents exploitation of security vulnerabilities (known and even unknown!) with no loss of functionality...
Experts do agree: Firefox is really safer with NoScript.
What's New in This Release:
· Restored Nightly compatibility, broken by bug 719154
· [ClearClick] improved compatibility with Disqus widgets
· [AddressMatcher] Optimized trailing "*" in glob expressions
· Fixed origin URL detection flawed when certain wrapped URIs are loaded
· [XSS] Fixed false positive with query string patterns mimicking array
· access
What's New in 2.3.2:
· [XSS] Fixed regression in 2.3.2rc5 preventing some URLs from loading
· [XSS] Removed issue on Chinese pages using HZ-GB-2312 encoding
· [XSS] Added event injection checks for scriptless pages too, in order to
· prevent edge-case execution on permissions change
· [XSS] Fixed InjectionChecker JavaScript scanning bug
· [XSS] Improved HTML detection accuracy
· Better tagging of surrogate sandboxes for about:memory debugging
· Improved glinks surrogate
What's New in 2.3.1:
· Surrogate to let news pages escape Digg's frame
· [ClearClick] Improved compatibility with cross-frame overlapping shadows
· Removed ClearClick bypass based on a Firefox SVG CSS filter bug
· adf.ly surrogate to automatically skip the interstitial page even if scripts are disabled
· Improved Google search surrogates
· New surrogate against Google's scriptless tracking of search results navigation
What's New in 2.3:
· Fixed about:newtab not considered as a local origin by ABE
· Added blob:, about:memory and about:support to the automatic whitelist
· Added reflected script inclusion check exception for intensedebate.com
· Fixed CSS issues on Gecko 1.8
What's New in 2.2.6:
· [XSS] Fixed sanitization reporting bug
What's New in 2.2.1:
· [Locale] Updated he-il (thanks baryoni)
· [ClearClick] Fixed incompatibility with the FoxTab add-on
What's New in 2.1.9:
· Fixed subrequests matching an Anon action rule not being shown in
· the logs if already anonymized by the browser
What's New in 2.1.4:
· Better load progress feedback for hosts which are not DNS-cached yet
What's New in 2.1.2:
· Fixed bookmarklets from sidebars not working on JS-disabled pages
· Improved Twitter surrogate for Fx 3.x
What's New in 2.1.1.1:
· Improved embedded object activation on Javascript-enabled pages via dynamic method proxies
What's New in 2.1.1:
· Fixed toolbar button hidden in popup windows
What's New in 2.1.0.5:
· Fixed recent memory optimizations breaking compatibility with some extensions
What's New in 2.1.0.3:
· [L10n] Updated ro
· Restored some locales gone missing in previous dev build
What's New in 2.1.0.2:
· [XSS] Improved XML prescreening
What's New in 2.1.0.1:
· Removed googlesyndication.com from the default whitelist
· Added securecode.com ("Verified by VISA") to the default whitelist, in
· order to prevent surprise transaction failures
· [XSS] Exception for POST requests coming from a secure albeit not
· whitelisted Verified by Visa (securecode.com) origin
· [ABE] Fixed bug causing excessive console noise from permissive rules
· Updated locales
What's New in 2.0.9.9:
· Fixed spaces in ipecho response breaking WAN IP detection with one of
· the mirrors
· Experimental built-in profiler for debugging purposes
What's New in 2.0.9.8:
· Fixed empty tooltip for embedded placeholder on some RTL pages
· Truncate URLs in placeholders tooltips at the the query string or hash,
· to increase readability
· Increased WAN IP checks interval to 1 hour reducing log spam on routers
· Removed some obsolete code
What's New in 2.0.9.7:
· Fixed status label menu popping up in a wrong position
· Updated locales
What's New in 2.0.9.6:
· X-Do-Not-Track after a DNS cache miss causing some embedded content
· requests to fail
· Contribution button on the bottom of the Options dialog
What's New in 2.0.9.3:
· Fixed some cross-site requests containing JSON-like fragments broken
What's New in 2.0.9.2:
· Fixed forbid META refresh inside NOSCRIPT elements regression
What's New in 2.0.8.1:
· Fixed new IFRAME-based Youtube embedding method broken on non whitelisted pages with embedding restrictions
What's New in 2.0.7:
· Improved LoadGroup integration of the new internal redirection machinery for better loading progress feedback.
|