搜尋 Mozilla 技術支援網站

防止技術支援詐騙。我們絕對不會要求您撥打電話或發送簡訊,或是提供個人資訊。請用「回報濫用」功能回報可疑的行為。

了解更多

is there any addon (or somthing else) to SIMULATE ie9s "display only secure content"

  • 5 回覆
  • 2 有這個問題
  • 4 次檢視
  • 最近回覆由 wwabbit

more options

i tried https everywhere and forcing with no script fruitlessly

since firefox does not display a detailed message, here is a screen shot from chrome: http://image.bayimg.com/baadpaaee.jpg

here the OFFICIAL answer from m$: "This message is telling you that there may be both secure and non-secure content on the page. Secure and non-secure content, or mixed content, means that a webpage is trying to display elements using BOTH secure (HTTPS/SSL) and non-secure (HTTP) web server connections. This OFTEN happens with online stores or financial sites that display IMAGES, banners, or scripts that are coming from a server that is not secured. The risk of displaying mixed content is that a non-secure webpage or script might be able to access information from the secure content."

certain thumbnails of close friend notifications and app requests NULLIFY the encryption and firefox doesnt padlock unlike chrome

so how to FILTER unencrypted info FROM the encrypted :)

"An attacker can replace any unprotected, unsecure HTTP content on an otherwise secure, HTTPS page with a “poisoned” version. For example, when you visit https://www.youtube.com with different browsers and a man-in-the-middle attacker present, you’ll see different results. Most other browsers just show the unprotected content automatically, allowing a spoofing or information disclosure attack"

this pees me out :D

i tried https everywhere and forcing with no script fruitlessly since firefox does not display a detailed message, here is a screen shot from chrome: http://image.bayimg.com/baadpaaee.jpg here the OFFICIAL answer from m$: "This message is telling you that there may be both secure and non-secure content on the page. Secure and non-secure content, or mixed content, means that a webpage is trying to display elements using BOTH secure (HTTPS/SSL) and non-secure (HTTP) web server connections. This OFTEN happens with online stores or financial sites that display IMAGES, banners, or scripts that are coming from a server that is not secured. The risk of displaying mixed content is that a non-secure webpage or script might be able to access information from the secure content." certain thumbnails of close friend notifications and app requests NULLIFY the encryption and firefox doesnt padlock unlike chrome so how to FILTER unencrypted info FROM the encrypted :) "An attacker can replace any unprotected, unsecure HTTP content on an otherwise secure, HTTPS page with a “poisoned” version. For example, when you visit https://www.youtube.com with different browsers and a man-in-the-middle attacker present, you’ll see different results. Most other browsers just show the unprotected content automatically, allowing a spoofing or information disclosure attack" this pees me out :D

由 wwabbit 於 修改

所有回覆 (5)

more options

Firefox's Site Identity button gives that warning by displaying a grey warning triangle icon in the URL bar. Click on that icon to see the full explanation.
https://support.mozilla.com/en-US/kb/Site+Identity+Button

more options

A built-in mixed content blocker is planned for future release (see Security/Features/Mixed Content Blocker - MozillaWiki). In the meantime, an add-on is a good idea. I'm going to poke around when I get a chance.

more options

You can check the security.warn_viewing_mixed pref on the about:config page to see if it is set to true if you want to be warned in cases like that.

more options

Hmm, well, many hours later, I have a Greasemonkey userscript that clears many insecure elements, but it doesn't work on scripts. By the time I edit or delete the script tag, Firefox has already requested the script. So I think it will take a real add-on.

more options

the ONLY dude who has REAL answers is JSCHER2000 kudos, son :) and btw what usercript is it, i do have grease monkey :)