Closed Bug 529091 Opened 15 years ago Closed 15 years ago

Cannot Logon to Banking Web Sites

Categories

(SeaMonkey :: Security, defect)

x86
Windows XP
defect
Not set
major

Tracking

(Not tracked)

RESOLVED INVALID

People

(Reporter: david, Unassigned)

Details

User-Agent:       Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.4) Gecko/20091017 SeaMonkey/2.0
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.4) Gecko/20091017 SeaMonkey/2.0

With SeaMonkey 2.0, I cannot logon to the following banking Web sites:  
   California Oaks State Bank at <https://www.caloaks.com/>
   Premier America Credit Union at <https://www.premier.org/>

Although the responses differ in details, both sites respond as if I had not entered my user ID and password (which are different between the two sites).  This occurs while spoofing Firefox 3.5.3 with the following UA string:  
   Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.4) 
       Gecko/20091017 SeaMonkey/2.0 NOT Firefox/3.5.3
I have also tried various other spoofs, including IE 7 for a PC, IE 5 for a Mac.  Since Premier America Credit Union claims they only support Firefox through version 3.0, I also tried the following UA string: 
   Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.11)
       Gecko/2009060215 Firefox/3.0.11

Note that I was able to logon to both sites with SeaMonkey 1.1.18 using the following UA string:  
   Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.23) 
       Gecko/20090825 SeaMonkey/1.1.18 NOT Firefox/3.5.3


Reproducible: Always




I logon to banking sites while in a special profile used only for that purpose.  That profile is setup to always spoof Firefox because some sites do not allow use of SeaMonkey.  

Since I can logon with SeaMonkey 1.1.18 spoofing Firefox 3.5.3 but not with SeaMonkey 2.0 spoofing Firefox 3.5.3, I strongly suspect a problem with SeaMonkey and not with the way these sites sniff the UA string.  

I have had no problems using that special profile in SeaMonkey 2.0 to logon to another credit union or to Vanguard Group (mutual funds).
My further testing indicates this was caused by the extension Activate Autocomplete 1.0.1.  

NOTE WELL:  I installed Activate Autocomplete 1.0.1 as a workaround for bug #425145.
Status: NEW → RESOLVED
Closed: 15 years ago
Resolution: --- → INVALID
You need to log in before you can comment on or make changes to this bug.