Author Topic: Avast seems to block payments made with a french payment platform  (Read 4257 times)

0 Members and 1 Guest are viewing this topic.

Offline eljevidos

  • Newbie
  • *
  • Posts: 4
Hello,

I have noticed that apparently Avast tampers the form data and removes some data of the request.

Surprisingly, this happens only the first time that we try with the browser. After that does it works ok, but if we reboot (or restarts Avast) it happens again.


You can test the problem here: https://www.spplus.net/jcms/hen_7816/fr/demo-sp-plus-boutique-portail-presentation


This is the request in the first try (it fails):

POST /vads-payment/ HTTP/1.1
Host: paiement.systempay.fr
Connection: keep-alive
Content-Length: 344
Cache-Control: max-age=0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Origin: https://www.spplus.net
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.85 Safari/537.36
Content-Type: application/x-www-form-urlencoded
Referer: https://www.spplus.net/jcms/hen_7747
Accept-Encoding: gzip, deflate
Accept-Language: fr-FR,fr;q=0.8,en-US;q=0.6,en;q=0.4,es;q=0.2
Cookie: 142752851509040001290=_



However in the the second and the following tries:

POST /vads-payment/ HTTP/1.1
Host: paiement.systempay.fr
Connection: keep-alive
Content-Length: 344
Cache-Control: max-age=0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Origin: https://www.spplus.net
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.85 Safari/537.36
Content-Type: application/x-www-form-urlencoded
Referer: https://www.spplus.net/jcms/hen_7747
Accept-Encoding: gzip, deflate
Accept-Language: fr-FR,fr;q=0.8,en-US;q=0.6,en;q=0.4,es;q=0.2
Cookie: JSESSIONID=0X6c0lmdLhRHZ33KLDfwOCqB.vadpayment01tls; 142752851509040001290=_



Apparently the cookie is removed!

I guess that is Avast who tampers the data because if I disable or unistall the product, the problem is gone.


Thank you

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 36610
  • 57 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Avast seems to block payments made with a french payment platform
« Reply #1 on: September 06, 2015, 10:31:01 PM »
Does it work if you disable https scanning ???
Free avast! Security Seminar: http://www.authorstream.com/Presentation/bob3160-1425909-protecting-yourself/    -  Important: http://www.organdonor.gov/ -- My Blog: http://bob3160.blogspot.com/ - Win 10 Pro v1703 64bit, 8 Gig Ram, AvastFree 17.6.2307, WinPatrol, Unchecky How to Successfully Install Avast http://goo.gl/VLXde

Offline eljevidos

  • Newbie
  • *
  • Posts: 4
Re: Avast seems to block payments made with a french payment platform
« Reply #2 on: September 07, 2015, 03:41:42 PM »
Thank you!! It works indeed if I disable that option.   :D

I am curious. Do you know why this happens? Perhaps Avast changes or inserts http headers in the request in order to retrieve more info?


Thanks again

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 36610
  • 57 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Avast seems to block payments made with a french payment platform
« Reply #3 on: September 07, 2015, 04:05:38 PM »
Thank you!! It works indeed if I disable that option.   :D

I am curious. Do you know why this happens? Perhaps Avast changes or inserts http headers in the request in order to retrieve more info?


Thanks again
There's a known bug withing https scanning that's currently being worked on.
Hopefully fixed by the next update.
Free avast! Security Seminar: http://www.authorstream.com/Presentation/bob3160-1425909-protecting-yourself/    -  Important: http://www.organdonor.gov/ -- My Blog: http://bob3160.blogspot.com/ - Win 10 Pro v1703 64bit, 8 Gig Ram, AvastFree 17.6.2307, WinPatrol, Unchecky How to Successfully Install Avast http://goo.gl/VLXde

Offline eljevidos

  • Newbie
  • *
  • Posts: 4
Re: Avast seems to block payments made with a french payment platform
« Reply #4 on: September 07, 2015, 04:47:00 PM »
OK  :),

Thank you very much for your help.

Offline eljevidos

  • Newbie
  • *
  • Posts: 4
Re: Avast seems to block payments made with a french payment platform
« Reply #5 on: September 08, 2015, 09:11:05 AM »
In fact we have detected that this problem happens only with EV certificates . It seems that Avast handle the HTTPS handshake, which is suddenly aborted after transmiting the certificate the first time.
In the following calls, the https connection is already stablished so we dont have the problem anymore, until we restart.

Could you confirm if the bug is related with this subject?

Thank you again

Offline MartinZ

  • Moderator
  • Advanced Poster
  • *
  • Posts: 681
  • Product Manager
Re: Avast seems to block payments made with a french payment platform
« Reply #6 on: September 11, 2015, 11:15:44 AM »
Hi,

yes this is a bug and we work on a fix.

Offline linkpbn

  • Newbie
  • *
  • Posts: 1
    • les engrais NPK
Re: Avast seems to block payments made with a french payment platform
« Reply #7 on: August 25, 2016, 06:22:34 PM »
I had a problem in my company with the French payment for the licenses in 2016.
Do I have to create new a topic?
Thank you in advance,
linkpbn

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31482
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Avast seems to block payments made with a french payment platform
« Reply #8 on: August 25, 2016, 06:29:20 PM »
Yes, create a new topic and provide details.
This thread is about a year old and a lot have changed since the last post.