Closed Bug 1097290 Opened 11 years ago Closed 10 years ago

Clicked on a link - and received a faulty error message - the link is valid

Categories

(Firefox :: Untriaged, defect)

32 Branch
x86
Windows 7
defect
Not set
normal

Tracking

()

RESOLVED INCOMPLETE

People

(Reporter: bday1234, Unassigned)

Details

User Agent: Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0 Build ID: 20140923175406 Steps to reproduce: NB: FF version is: 32.0.3 Clicked on this web page <https://shop.ashampoo.com/10/paypal/65677927 > and got a (faulty) error msg - see detail below. The link is, in fact, valid - & works correctly in Opera. So it must be a FF-specific problem! NB: I had to contact Ashampoo to get this resolved. It was not apparent it was a fault within FF - based on the error msg! NB: They suggested it might be a fault in FF ......and they were right! :-) They identified that the link was truncated after a "-" - in case that helps. I just tried the link again - just before submitting this bug .. and it's still failing with the same error. (Brisbane, Wed 12th Nov ~8am AEST ~22:00 11th UTC) Since I have dealt with this via Opera now, I have been able to pay & complete my order for the relevant Ashampoo s'ware. However, clearly there is a problem .. It should be looked into! I was, after all, trying to make a Paypal payment. Who knows what security issues may have arisen as a result of this. I just have to hope that nothing untoward has occurred. Barry Day <bday1234@gmx.com> Actual results: Received this (invalid) msg..... ~~~~~~~~~~~~~~~~~ <https://shop.ashampoo.com/10/paypal/65677927 > File not found The page that you requested cannot be found on this server. This might have the following reasons: The link you are using is not valid anymore or wrong. You have not entered the URL correctly. The page does not exist anymore. If you have gotten to this page over a certain URL, please inform the owner over the page that offered this link so that he can update his page. ~~~~~~~~~~~~~~~~~ Expected results: The link should have succeeded - NB: it did in another Browser !
Group: core-security
This link doesn't work in any of the browsers on my system, including Chrome and Safari, nor on my other (Windows) system, where IE11 also gives me the same error message. Does the link still work in Opera? What is it meant to display? I'm not sure why you marked this bug as security-sensitive, and would like to unmark it, but I'd first like to be sure that that link doesn't do anything in any browser. " They identified that the link was truncated after a "-" - in case that helps. " but there is no "-" in the link you gave us, so we can't really figure out what happened to get you the truncated link...
Flags: needinfo?(bday1234)
The link https://shop.ashampoo.com/10/paypal/65677927 appears to be part of a shopping transaction, and isn't going to work on its own without your log in or reference to your cookies that contain the transaction state.
Yes it was indeed a shopping transaction that couldn't be completed due to the fault in the link. I am of course, reluctant to give out my access info ... is there any way I can help otherwise? I still have the email conversation between myself & Ashampoo help desk - who detected the actual fault. Specifically what they said was.... ~~~~~~~~~~~~~~~~ > thank you very much for your e-mail It seems you just a part of the > link, as the part after the minus sign is > missing on your link. The right link is: > https://shop.ashampoo.com ...<FULL LINK REMOVED, it contains my KEY! Sorry. ~~~~~~~~~~~~~~~~ What else can I provide to assist pls..? Barry Day
Flags: needinfo?(bday1234)
(In reply to Barry Day from comment #3) > Yes it was indeed a shopping transaction that couldn't be completed due to > the fault in the link. OK. But then it's OK to mark this bug as non-confidential for now, is that right? Marking it as non-confidential will significantly increase the number of people who can easily help resolve this issue. Right now only a very limited set of people have access to the issue, which means it's less likely to get fixed. > I am of course, reluctant to give out my access info ... Very sensible. :-) > is there any way I can help otherwise? Can you tell us more about where you got the link that broke, and/or how you opened it? Was it in an email, or on another webpage? And, can you maybe detail the "shopping steps" one would have to take to access a similar URL? I just tried looking at ashampoo.com, but didn't succeed in breaking anything (without actually purchasing anything...) Alternatively, how are you in touch with the Ashampoo folks, and can you/we ask them if they have technical people on their team who can help debug this?
Flags: needinfo?(bday1234)
I would imagine the folks at Ashampoo would assist - there's nothing to lose by your asking them. I did mention to them I would log the error with FF, in my response to theirs when they identified the issue. The following contains their support email & my issue/reference ID... taken from my email headers. ~~~~~~~~~~~~~~~ To: Ashampoo Support <sis@ashampoo.com> Subject: Re: Unable to pay through Cleverbridge & paypal ... what's gone wrong pls? [#ASH-HD:1451839#] ~~~~~~~~~~~~~~~ As regards the original sequence of events.... - I received an email offer to make an early order for an upgrade to an existing product. - The email contained a link to the online payment agency they use - Cleverbridge. I clicked the link from within my email, which fired off FF with that link... - The resulting webpage contained a link to actually issue the order & pay (via Paypal). I clicked that link. - From that point, it all went awry.... ie: it's all pretty simple really .... except that the link just didn't work correctly (in FF) - but does in a different Browser .. to wit .. Opera. I'm sure if you mention my ref ID to Ashampoo support they will assist in clarifying what they discovered. After all, it's in their interest as well, since FF is so widely used. NB: Their immediate suggestion/solution was to try a different browser to complete the payment since the link was in fact, valid .... so I chose Opera. If you are unable or prefer to not contact Ashampoo, I suppose it's ok to make the issue public, so long as none of my personal or private info is revealed. But since Ashampoo already know the answer .. it does seem obvious to contact them directly, first. And if they don't/won't/can't help, ....then make it public. I am of course, concerned that somehow during investigating this, my personal, paypal &/or bank info will somehow be revealed - since it related to a payment I was making. I do not think it was at all unwise in the circumstances, to make the issue - private! I do not accept at all, your (mild) reproach for doing so. Barry Day
Flags: needinfo?(bday1234)
(In reply to Barry Day from comment #5) > But since Ashampoo already know the answer .. it does seem obvious to > contact them directly, first. > And if they don't/won't/can't help, ....then make it public. Thank you for the clear description of what happened. OK. I will see if I can get in touch with them after catching up on some sleep. > I am of course, concerned that somehow during investigating this, my > personal, paypal &/or bank info will somehow be revealed - since it related > to a payment I was making. I do not think it was at all unwise in the > circumstances, to make the issue - private! I do not accept at all, your > (mild) reproach for doing so. I did not intend to reproach you! I'm merely saying, I don't think any of the data currently on this bug compromises your personal, paypal or bank info, considering that the link is unusable without your cookies and context (and apparently the link is cut off to boot!).
Group: core-security
Hi reporter, Can you please try to reproduce this on the latest release(43.0.3) and latest Nightly(46.0a1) and provide the results? When doing this, please try to reproduce with a new clean Firefox profile, maybe even in safe mode, as some of this issues may be caused by third party installed add-ons or custom settings(https://support.mozilla.org/en-US/kb/troubleshoot-and-diagnose-firefox-problems). Thanks, Paul.
Flags: needinfo?(bday1234)
Since the reporter didn't provide the requested information, I will mark this issue as RESOLVED INCOMPLETE. If you still encounter this problem, please feel free to reopen this bug, or file a new one.
Status: UNCONFIRMED → RESOLVED
Closed: 10 years ago
Flags: needinfo?(bday1234)
Resolution: --- → INCOMPLETE
You need to log in before you can comment on or make changes to this bug.