SupportProblem The Firefox "NoScript" extension provides good protection against a variety of web-borne attacks (see for an introduction to XSS and CSRF), and is "recommended best practice" for secure web surfing. However, several CERN web services are not compatible with it, and require manual configuration/whitelisting.
  • Web SingleSignOn/SSO ( is being detected as a cross-site-scripting attack, probably due to the enormous size of the request being posted. This also may cause Firefox error message about a "Script not responding". Solution is to add the following to NoScript Options→Advanced→XSS :
  • CERN sites known to require JavaScript:
    • all AIS applications (EDH,HRT,APT, ..),
    • LanDB (just for the initial login?)
  • Several sites change the JavaScript "security domain" to become, in order to exchange data between pages hosted on several machines (otherwise JavaScript would treat them as separate sites, and prevent such sharing). For NoScript, this means that the whole domain has to be whitelisted, not just the individual machines concerned. (Unfortunately, these sites then also will share that data with all other CERN webservices that similarly change their domain). This is worth contacting the site owner on, they might be able to change the way their site works (and thereby protect their service).

