Avast WEBforum

Avast Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: eljevidos on September 04, 2015, 09:14:14 PM

Title: Avast seems to block payments made with a french payment platform
Post by: eljevidos on September 04, 2015, 09:14:14 PM
Hello,

I have noticed that apparently Avast tampers the form data and removes some data of the request.

Surprisingly, this happens only the first time that we try with the browser. After that does it works ok, but if we reboot (or restarts Avast) it happens again.


You can test the problem here: https://www.spplus.net/jcms/hen_7816/fr/demo-sp-plus-boutique-portail-presentation (https://www.spplus.net/jcms/hen_7816/fr/demo-sp-plus-boutique-portail-presentation)


This is the request in the first try (it fails):

POST /vads-payment/ HTTP/1.1
Host: paiement.systempay.fr
Connection: keep-alive
Content-Length: 344
Cache-Control: max-age=0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Origin: https://www.spplus.net
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.85 Safari/537.36
Content-Type: application/x-www-form-urlencoded
Referer: https://www.spplus.net/jcms/hen_7747
Accept-Encoding: gzip, deflate
Accept-Language: fr-FR,fr;q=0.8,en-US;q=0.6,en;q=0.4,es;q=0.2
Cookie: 142752851509040001290=_



However in the the second and the following tries:

POST /vads-payment/ HTTP/1.1
Host: paiement.systempay.fr
Connection: keep-alive
Content-Length: 344
Cache-Control: max-age=0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Origin: https://www.spplus.net
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.85 Safari/537.36
Content-Type: application/x-www-form-urlencoded
Referer: https://www.spplus.net/jcms/hen_7747
Accept-Encoding: gzip, deflate
Accept-Language: fr-FR,fr;q=0.8,en-US;q=0.6,en;q=0.4,es;q=0.2
Cookie: JSESSIONID=0X6c0lmdLhRHZ33KLDfwOCqB.vadpayment01tls; 142752851509040001290=_



Apparently the cookie is removed!

I guess that is Avast who tampers the data because if I disable or unistall the product, the problem is gone.


Thank you
Title: Re: Avast seems to block payments made with a french payment platform
Post by: bob3160 on September 06, 2015, 10:31:01 PM
Does it work if you disable https scanning ???
(http://www.screencast-o-matic.com/screenshots/u/Lh/1437840647533-69944.png)
Title: Re: Avast seems to block payments made with a french payment platform
Post by: eljevidos on September 07, 2015, 03:41:42 PM
Thank you!! It works indeed if I disable that option.   :D

I am curious. Do you know why this happens? Perhaps Avast changes or inserts http headers in the request in order to retrieve more info?


Thanks again
Title: Re: Avast seems to block payments made with a french payment platform
Post by: bob3160 on September 07, 2015, 04:05:38 PM
Thank you!! It works indeed if I disable that option.   :D

I am curious. Do you know why this happens? Perhaps Avast changes or inserts http headers in the request in order to retrieve more info?


Thanks again
There's a known bug withing https scanning that's currently being worked on.
Hopefully fixed by the next update.
Title: Re: Avast seems to block payments made with a french payment platform
Post by: eljevidos on September 07, 2015, 04:47:00 PM
OK  :),

Thank you very much for your help.
Title: Re: Avast seems to block payments made with a french payment platform
Post by: eljevidos on September 08, 2015, 09:11:05 AM
In fact we have detected that this problem happens only with EV certificates . It seems that Avast handle the HTTPS handshake, which is suddenly aborted after transmiting the certificate the first time.
In the following calls, the https connection is already stablished so we dont have the problem anymore, until we restart.

Could you confirm if the bug is related with this subject?

Thank you again
Title: Re: Avast seems to block payments made with a french payment platform
Post by: MartinZ on September 11, 2015, 11:15:44 AM
Hi,

yes this is a bug and we work on a fix.
Title: Re: Avast seems to block payments made with a french payment platform
Post by: linkpbn on August 25, 2016, 06:22:34 PM
I had a problem in my company with the French payment for the licenses in 2016.
Do I have to create new a topic?
Thank you in advance,
linkpbn
Title: Re: Avast seems to block payments made with a french payment platform
Post by: Eddy on August 25, 2016, 06:29:20 PM
Yes, create a new topic and provide details.
This thread is about a year old and a lot have changed since the last post.