User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8) Gecko/20051025 Firefox/1.5 Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8) Gecko/20051025 Firefox/1.5 I visited gmail today to login and typed my login info wrong but accidentally told firefox to remember the password. I got the login incorrect error. Then tried again with the correct password and firefox is stuck in a loop about every second firefox generates another auth code and it keeps looping. For some reason the auth number below will change every second. http://mail.google.com/mail/?auth=DQAAAGoAAADqYo9mE1G_u9eEjYsyjqF4E7jz9I_jdBc5PJqh-q9z7DIB3fNb3DxkvgEl6cetRwZstrDpnVkuTWf07TRVWoxDhmRDDGYuGSWpqrV5jXO38WZczWm6rEFROOSoeLXU-eccv_wYQW-ovTeyjtvRXkhY&zx=vmkxw6sn1mji Reproducible: Always Steps to Reproduce: 1. type the wrong uid or password in mail.google.com 2. tell system to save it 3. enter in the correct password the 2nd time I tried to go to tools options privacy view passwords to remove the google password and I'm still getting the same problem. Cannot login everytime I visit I get he same problem, it trys to auto login and gets stuck in a loop. Actual Results: http://mail.google.com/mail/?auth=DQAAAGoAAAA4ugjoFFXzhv-1ZGtVpCwmsbfdqR1D9LOyh8WN2BmX3AfJKtR90PoMR1raCoKYCtjnhG4q__1kgcpoueuK-oGNeb2EIlznrGnX1Yz9VrVtA3Pyazg5h1SdomUo3ERUBjl1rfDSRiYJ0HZ4EksWsb-R&zx=15uvvdh4ptxt2 ...loading http://mail.google.com/mail/?auth=DQAAAGoAAABukjSv_i8ueSUIVlRTg7Nu8LC_RjnNO32BEhLulOc_ROumF3fz-1xLDLPrCPTngHZHU8QV3Nff_TNUSTobGsgb4e8cEr8k-gRj1jSdzL4qEXp8b4_0ub_BNjEntfRQbAzlmiD20PbxF6K5AqPTTgwd&zx=tdmultdjdhk3 ...loading http://mail.google.com/mail/?auth=DQAAAGwAAAAPMUPiPSRnwwAYEO61TOW8VtZMxFYZcFIBRz5FvW8-42hfP1w-Gqhd5JggCvE0ijjuUSnZ56_JYX3C0PgEb7M3jm8sMcyPIM6LVADD5jBygY5N_Hsf14rqr_dJ3JvJMCRNFQ-TsK0M5-5PI1_v8Nru&zx=bcli5npcqn3o ...loading .... N times does not seem to login or stop. Expected Results: just a login to gmail and be able to see the inbox. I let it loop maybe 60 times and cannot get it to stop. maybe a security problem maybe not.
This doesn't sound like a security hole to me.
I can't reproduce it. If I enter an incorrect password I stay on https://www.google.com/accounts/ServiceLoginAuth. I only get to the mail.google.com server when I enter a correct password, and then I see my mail. You need to work it out with user support groups (http://forums.mozillazine.org or http://www.mozilla.org/support/) to figure out what's unique to your situation. You might be asked for a cookie log (http://www.mozilla.org/projects/netlib/cookies/cookie-log.html) or an http log (http://www.mozilla.org/projects/netlib/http/http-debugging.html). Speaking of cookies, in addition to deleting any stored google/gmail passwords delete your google cookies as well and see if that helps.
Is this still reproducible on FF2.0 beta 1?
Please reopen if you can reproduce on FF2.0 beta or trunk. Works fine here.
Status: UNCONFIRMED → RESOLVED
Last Resolved: 12 years ago
Resolution: --- → WORKSFORME
You need to log in before you can comment on or make changes to this bug.