Comment 19 for bug 537293

Revision history for this message
Tony Mugan (tmugan) wrote :

I've run two packet captures with Firefox

The successful login (with another brand new firefox profile) had 611 packets in just the login process to the Bankwest site.

The failed login (reusing one of the other "tainted" profiles) captured only 67 packets before the session stopped.

On viewing those captures, there is one obvious difference.
The failed one shows packet 15 as an "Encrypted Alert" packet followed by packet 16 as a [FIN, ACK].
This is repeated later in the capture with packet 66 as an "Encrypted Alert" packet followed by packet 67 as a [RST, ACK].

The conversation is clearly being completed much earlier in the failed session which can be consistently reproduced.