PDA

View Full Version : Bug Report: HTTPs filtering


NOD32 user
November 19th, 2008, 04:43 PM
Hi,

Mostly ESSv4 is working perfectly here.

So far the only issue I have had is that when browsing some of the CubeCart based web stores the https pages fail to load unless I select 'Do not use HTTPs protocol checking' or choose 'Exclude' when prompted for the certificate.

e.g.
If I visit http://www.balanzzascales.co.uk/shop/index.php and click on 'View Basket' near the top right I am prompted for the certificate which I 'allow always' but the page never loads.

http://secure.theorganizedbridestore.com/index.php - works normally

I have other non-working examples if necessary.

Cubecart v4 is available for download from: http://www.cubecart.com/downloads/

I am running XP sp3 and IE7

ESS 4.0.68.0
Virus signature database: 3625 (20081119)
Update module: 1026 (20081114)
Antivirus and antispyware scanner module: 1160 (20081118)
Advanced heuristics module: 1082 (20081107)
Archive support module: 1085 (20081106)
Cleaner module: 1035 (20081110)
Anti-Stealth support module: 1007 (20081107)
Personal firewall module: 1043 (20081111)
Antispam module: 1009 (20081023)
System status module: 1200 (20080904)
Self-Defense support module : 1005 (20081105)

email sent to betasupport with same subject as this post.

Cheers :)

Mits
November 19th, 2008, 06:05 PM
I'm not optimistic that IE7 bug reports may be of real use to ESET developers, given the idiosyncratic ways IE accesses https sites or manages ssl certificates (especially if Windows Firewall is enabled) - IE7's behaviour is very dependent on the technology of the site (asp, java, ruby, complex css etc.). Have you tried accessing the same sites using Firefox or other browsers?

However, your list of problematic sites would be very useful, can you list some more so we can try them?

MasterTB
November 19th, 2008, 06:24 PM
See here: http://www.wilderssecurity.com/showthread.php?t=225663 I reported it for Opera in all secure sites... and It has been confirmed by agoretsky in XP SP3 aswell.

NOD32 user
November 20th, 2008, 07:01 AM
-{ Quote: "See here: http://www.wilderssecurity.com/showthread.php?t=225663 I reported it for Opera in all secure sites... and It has been confirmed by agoretsky in XP SP3 aswell." }-Fortunately the majority of secure sites are working fine for me.

I can confirm that using Chrome 0.3.154.9 the same issue exists on the same sites

Cheers :)

NOD32 user
November 20th, 2008, 06:40 PM
Found another non CubeCart client project page that has the same issue, leading me to believe the issue is either with particular servers or types of SSL certificates:

http://www.flashmail.net.au/MiltonBlack/subscribe.php

Cheers :)

NOD32 user
November 25th, 2008, 09:07 PM
Hi,

Can anybody else confirm this issue using Internet Explorer on the sites mentioned or is it just me?

-{ Quote: "I'm not optimistic that IE7 bug reports may be of real use to ESET developers, given the idiosyncratic ways IE accesses https sites or manages ssl certificates (especially if Windows Firewall is enabled) - IE7's behaviour is very dependent on the technology of the site (asp, java, ruby, complex css etc.). Have you tried accessing the same sites using Firefox or other browsers?

However, your list of problematic sites would be very useful, can you list some more so we can try them?" }-
Same issue with Chrome.

Sites work normally without any ESS and with ESSv3.

Cheers :)

NOD32 user
December 5th, 2008, 12:53 PM
Followup:

In this current beta version the recommendation for "Protocol filtering" is "Do not scan SSL protocol" - thanks ESET :)

And then I noticed - SSL v.2 check is not implemented
http://www.eset.eu/produkts/eset-smart-security-4-beta-known-issues

Cheers :)