Post Reply 
Problem with Half-SSL...
Mar. 14, 2009, 11:15 PM (This post was last modified: Apr. 02, 2009 08:33 PM by sidki3003.)
Post: #9
RE: Problem with Half-SSL...
When logging in, the page is sending a lot of set-cookie headers with a "secure" field. But one header is special, it has all the supplemental fields duplicated:

Code:
Set-cookie: UAUTH=USERNAME:xxx..|SID:xxx; path=/; domain=.accountonline.com; SECURE; Path=/; Domain=.accountonline.com; Secure


The "Set-Cookie: 7 Strip "Secure" if Half-SSL" header filter was expecting just one "secure" field, thus left one in place. Consequently, the "UAUTH" cookie wasn't accepted by the browser.

Below test version loops through all existing "secure" instances.

Code:
[HTTP headers]
In = TRUE
Out = FALSE
Key = "Set-Cookie: 7 Strip "Secure" if Half-SSL     9.03.14 (cch!) [sd] (d.1) (In)"
URL = "$TST(keyword=*.i_ssl_h:[12].*)"
Match = "(\# ; secure(^$TST(uPort=*))(^(^ ;)& ?))+{1,*}\#&$LOG(wRESP $DTM(c) : Set-Cookie stripped: Secure)&($TST(volat=*.log:2*)$ADDLST(Log-Main,[$DTM(d T)]\tHDR_In Set-Cookie_Strip\t\Secure\t\u)|)"
Replace = "\@"

edit: 5a -> 7
edit2: "TEST" flag removed
Add Thank You Quote this message in a reply
Post Reply 


Messages In This Thread
Problem with Half-SSL... - ProxRocks - Mar. 13, 2009, 11:22 PM
RE: Problem with Half-SSL... - sidki3003 - Mar. 13, 2009, 11:55 PM
RE: Problem with Half-SSL... - ProxRocks - Mar. 14, 2009, 12:40 AM
RE: Problem with Half-SSL... - sidki3003 - Mar. 14, 2009, 01:03 AM
RE: Problem with Half-SSL... - ProxRocks - Mar. 14, 2009, 01:35 AM
RE: Problem with Half-SSL... - sidki3003 - Mar. 14, 2009, 01:58 AM
RE: Problem with Half-SSL... - ProxRocks - Mar. 14, 2009, 02:04 AM
RE: Problem with Half-SSL... - ProxRocks - Mar. 14, 2009, 04:02 PM
RE: Problem with Half-SSL... - sidki3003 - Mar. 14, 2009 11:15 PM
RE: Problem with Half-SSL... - ProxRocks - Mar. 14, 2009, 11:35 PM
RE: Problem with Half-SSL... - sidki3003 - Mar. 14, 2009, 11:40 PM
RE: Problem with Half-SSL... - lnminente - Mar. 15, 2009, 03:31 AM
RE: Problem with Half-SSL... - lnminente - Mar. 22, 2009, 11:12 PM
RE: Problem with Half-SSL... - sidki3003 - Mar. 23, 2009, 09:06 PM
RE: Problem with Half-SSL... - Toppy - Mar. 23, 2009, 02:08 PM
RE: Problem with Half-SSL... - ProxRocks - Mar. 23, 2009, 02:27 PM
RE: Problem with Half-SSL... - Toppy - Mar. 23, 2009, 05:03 PM
RE: Problem with Half-SSL... - ProxRocks - Mar. 23, 2009, 05:24 PM
RE: Problem with Half-SSL... - Toppy - Mar. 23, 2009, 05:40 PM
RE: Problem with Half-SSL... - ProxRocks - Mar. 23, 2009, 06:04 PM
RE: Problem with Half-SSL... - Toppy - Mar. 23, 2009, 06:50 PM
RE: Problem with Half-SSL... - sidki3003 - Apr. 02, 2009, 08:32 PM
RE: Problem with Half-SSL... - ProxRocks - Apr. 07, 2009, 02:27 AM
RE: Problem with Half-SSL... - sidki3003 - Apr. 07, 2009, 03:00 AM
RE: Problem with Half-SSL... - ProxRocks - Apr. 07, 2009, 10:00 AM
RE: Problem with Half-SSL... - sidki3003 - Apr. 07, 2009, 10:32 AM
RE: Problem with Half-SSL... - ProxRocks - Apr. 07, 2009, 05:11 PM
RE: Problem with Half-SSL... - sidki3003 - Apr. 07, 2009, 05:28 PM
RE: Problem with Half-SSL... - ProxRocks - Apr. 07, 2009, 05:40 PM
RE: Problem with Half-SSL... - ProxRocks - Apr. 10, 2009, 01:36 PM
RE: Problem with Half-SSL... - sidki3003 - Apr. 10, 2009, 02:14 PM
RE: Problem with Half-SSL... - ProxRocks - Apr. 10, 2009, 03:51 PM
RE: Problem with Half-SSL... - sidki3003 - Apr. 10, 2009, 04:23 PM
RE: Problem with Half-SSL... - ProxRocks - Apr. 10, 2009, 05:03 PM
RE: Problem with Half-SSL... - sidki3003 - Apr. 10, 2009, 05:46 PM
RE: Problem with Half-SSL... - ProxRocks - Apr. 10, 2009, 06:16 PM
RE: Problem with Half-SSL... - ProxRocks - Apr. 17, 2009, 11:26 AM
RE: Problem with Half-SSL... - sidki3003 - Apr. 17, 2009, 12:19 PM
RE: Problem with Half-SSL... - ProxRocks - Apr. 17, 2009, 12:42 PM
RE: Problem with Half-SSL... - sidki3003 - May. 03, 2009, 08:43 PM
RE: Problem with Half-SSL... - sidki3003 - May. 09, 2009, 02:44 PM
RE: Problem with Half-SSL... - DarthTrader - May. 03, 2009, 09:25 PM
RE: Problem with Half-SSL... - ProxRocks - May. 03, 2009, 11:42 PM
RE: Problem with Half-SSL... - DarthTrader - May. 04, 2009, 12:02 AM
RE: Problem with Half-SSL... - ProxRocks - May. 04, 2009, 12:36 AM

Forum Jump: