My first NoScript clickjacking warning
So if you haven't heard of it, it looks like a variant of the clickjacking vulnerability was outed before Rsnake and Jeremiah Grossman could present it publicly (brings up bad memories of the situation with Dan Kaminsky and the DNS vulnerability).  It came out yesterday on the guya.net blog, and there have been a few blogs out there pick up on it (an update on the post says that Adobe has fixed the problem that was demonstrated). Then Rsnake came out with the full details on the vulnerability on his blog a few hours later and which issues have been resolved or are still hanging. It is all good stuff.
But to the point of this post, if you are a Firefox geek that uses NoScript, you'll be glad to know that you are FULLY protected if you are using version 1.8.2 (there's a 1.8.2.1 out as well, but it just provides backward compatibility with FF 2). I upgraded to 1.8.2 (I think it was yesterday), and I have already received a clickjacking warning. The picture is below. The URL is obfuscated purposefully by me since I didn't want anyone jacking around with the site (it is a secure site that requires a password - hmmm). Â
![]()
![]()

So my question is this: Is this a coding error of some kind on the site, or is it a false positive? Is this something that is going to be happening to a lot of people using FF and NoScript, or did I just get lucky? Of course, one might ask if it was actually an attack. I doubt it because (like I said above) the website is a secured site that is password protected, but you never know. I am not a developer, so I don't want to go any further than that, but I am looking into contacting the developer of the site to see if they can find anything (or if they even care). If I hear anything, I will post an update.
UPDATE: After Giorgio Maone's comment, I decided to wait on talking to the developer of the web app I was using. I updated to NoScript a couple of days later, and the error went away. So it was a fals positive, and Giorgio fixed it very quickly. Thanks a lot for your service to the community Giorgio. NoScript is STILL my favorite FF plugin (actually, it never lost that status).
