Could not logon to Time-Waner/Roadrunner Webmail
-
gari
Could not logon to Time-Waner/Roadrunner Webmail
Even since versions 2.6.9.22 up to stable version 2.6.9.27 (along with development versions in-between), I could no longer login to my Time-Warner/Roadrunner Webmail account, but when I disable NoScript, it will go through. When typing my User Name and Password and press Enter, It did not do anything at all, and just provided blank User Name and Password again. I even tried allowing "twc.com" on the "Whitelist" tab, but still having the same problem. I have used Windows 64-bit Firefox versions 38 beta and now 39.0b7 beta; however, I don't have any such problem logging-in with Internet Explorer 11.0. I have Windows 7 Professional 64-bit. Any work-around? Thanks in advance.
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:39.0) Gecko/20100101 Firefox/39.0
Re: Could not logon to Time-Waner/Roadrunner Webmail
if nothing is disallowed.. when it fails, do you see anything related in the Browser Console? (Ctrl-Shift-J)
(if you don't know what's related, turn off CSS warnings and post everything else you see)
(if you don't know what's related, turn off CSS warnings and post everything else you see)
*Always* check the changelogs BEFORE updating that important software!
-
Re: Could not logon to Time-Waner/Roadrunner Webmail
> Time-Warner/Roadrunner Webmail
URL?
(Most likely do not need a valid un/pw to see the issue, if it can be reproduced. IOW instead of getting some "invalid user name" message, the screen would just refresh with the fields blanked out.)
> Ever since versions 2.6.9.22
So if you were to revert to something earlier, NoScript 2.6.9.21, that does work?
As a test, create a new, clean Profile.
Install only (current) NoScript.
Test.
URL?
(Most likely do not need a valid un/pw to see the issue, if it can be reproduced. IOW instead of getting some "invalid user name" message, the screen would just refresh with the fields blanked out.)
> Ever since versions 2.6.9.22
So if you were to revert to something earlier, NoScript 2.6.9.21, that does work?
As a test, create a new, clean Profile.
Install only (current) NoScript.
Test.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:36.0) Gecko/20100101 SeaMonkey/2.33.1
-
Gari
Re: Could not logon to Time-Warner/Roadrunner Webmail
Still not working using NoScript version 2.6.9.28rc1 (development build) with Firefox 64-bit beta version 39.0b7. The URL is: https://webmail.twc.com/do/mail/folder/view. Still no message(s) whatsoever upon completing email address and password and pressing on Enter, as if nothing happened. I've tried allowing "webmail.twc.com" on Whitelist tab, but it only allows me to enter "webmail.twc.co" without m on .com. Using Windows 7 Professional 7 64-bit. Below were the ones showing on Browser Consule:
JavaScript 1.6's for-each-in loops are deprecated; consider using ES6 for-of instead ScriptSurrogate.js:343:198
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: JSESSIONID=aaaNiTDduSSJFhEY0y94u; domain=webmail.twc.com; path=/; Secure
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=AJEAAOGL; domain=webmail.twc.com; path=/; Secure
nsIJSON.encode is deprecated. Please use JSON.stringify instead. ssl-observatory.js:608:0
JavaScript 1.6's for-each-in loops are deprecated; consider using ES6 for-of instead ScriptSurrogate.js:345:209
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=AJEAAOGL; domain=webmail.twc.com; path=/; Secure
This site makes use of a SHA-1 Certificate; it's recommended you use certificates with signature algorithms that use hash functions stronger than SHA-1.[Learn More] submit_cert
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=AJEAAOGL; domain=webmail.twc.com; path=/; Secure
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: JSESSIONID=aaa1jC4gXDTIde3_0y94u; domain=webmail.twc.com; path=/; Secure
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=AJEAAOGL; domain=webmail.twc.com; path=/; Secure
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: JSESSIONID=aaaf6LWMFq9UZ-W-0y94u; domain=webmail.twc.com; path=/; Secure
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=AJEAAOGL; domain=webmail.twc.com; path=/; Secure
JavaScript 1.6's for-each-in loops are deprecated; consider using ES6 for-of instead ScriptSurrogate.js:345:209
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: activeLogin=true; domain=webmail.twc.com; path=/; Secure
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: JSESSIONID=aaaOHFLC5coYL5-dfz94u; domain=webmail.twc.com; path=/; Secure
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=AJEAAOGL; domain=webmail.twc.com; path=/; Secure
JavaScript 1.6's for-each-in loops are deprecated; consider using ES6 for-of instead ScriptSurrogate.js:345:209
JavaScript 1.6's for-each-in loops are deprecated; consider using ES6 for-of instead ScriptSurrogate.js:346:1634
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: JSESSIONID=aaaBkwl21bFM4_oRfz94u; domain=webmail.twc.com; path=/; Secure
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=GGEAAOGL; domain=webmail.twc.com; path=/; Secure
JavaScript 1.6's for-each-in loops are deprecated; consider using ES6 for-of instead ScriptSurrogate.js:345:209
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=GGEAAOGL; domain=webmail.twc.com; path=/; Secure
NS_ERROR_FAILURE: Failure arg 1 [nsIIOService2.newChannelFromURI2] WindowsPreviewPerTab.jsm:77:0
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=GGEAAOGL; domain=webmail.twc.com; path=/; Secure
- Thank you for your help.
JavaScript 1.6's for-each-in loops are deprecated; consider using ES6 for-of instead ScriptSurrogate.js:343:198
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: JSESSIONID=aaaNiTDduSSJFhEY0y94u; domain=webmail.twc.com; path=/; Secure
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=AJEAAOGL; domain=webmail.twc.com; path=/; Secure
nsIJSON.encode is deprecated. Please use JSON.stringify instead. ssl-observatory.js:608:0
JavaScript 1.6's for-each-in loops are deprecated; consider using ES6 for-of instead ScriptSurrogate.js:345:209
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=AJEAAOGL; domain=webmail.twc.com; path=/; Secure
This site makes use of a SHA-1 Certificate; it's recommended you use certificates with signature algorithms that use hash functions stronger than SHA-1.[Learn More] submit_cert
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=AJEAAOGL; domain=webmail.twc.com; path=/; Secure
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: JSESSIONID=aaa1jC4gXDTIde3_0y94u; domain=webmail.twc.com; path=/; Secure
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=AJEAAOGL; domain=webmail.twc.com; path=/; Secure
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: JSESSIONID=aaaf6LWMFq9UZ-W-0y94u; domain=webmail.twc.com; path=/; Secure
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=AJEAAOGL; domain=webmail.twc.com; path=/; Secure
JavaScript 1.6's for-each-in loops are deprecated; consider using ES6 for-of instead ScriptSurrogate.js:345:209
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: activeLogin=true; domain=webmail.twc.com; path=/; Secure
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: JSESSIONID=aaaOHFLC5coYL5-dfz94u; domain=webmail.twc.com; path=/; Secure
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=AJEAAOGL; domain=webmail.twc.com; path=/; Secure
JavaScript 1.6's for-each-in loops are deprecated; consider using ES6 for-of instead ScriptSurrogate.js:345:209
JavaScript 1.6's for-each-in loops are deprecated; consider using ES6 for-of instead ScriptSurrogate.js:346:1634
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: JSESSIONID=aaaBkwl21bFM4_oRfz94u; domain=webmail.twc.com; path=/; Secure
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=GGEAAOGL; domain=webmail.twc.com; path=/; Secure
JavaScript 1.6's for-each-in loops are deprecated; consider using ES6 for-of instead ScriptSurrogate.js:345:209
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=GGEAAOGL; domain=webmail.twc.com; path=/; Secure
NS_ERROR_FAILURE: Failure arg 1 [nsIIOService2.newChannelFromURI2] WindowsPreviewPerTab.jsm:77:0
[NoScript HTTPS] FORCED SECURE on https://webmail.twc.com: sto-id=GGEAAOGL; domain=webmail.twc.com; path=/; Secure
- Thank you for your help.
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:39.0) Gecko/20100101 Firefox/39.0
Re: Could not logon to Time-Waner/Roadrunner Webmail
You might be hitting a problem with cookie security.
Try adding the following exclusion to Options-Advanced-HTTPS-Cookies-"Ignore unsafe cookies set by the following sites:"
...and if that fixes it, then someone should tell the webmaster that their site is unsafe.
Try adding the following exclusion to Options-Advanced-HTTPS-Cookies-"Ignore unsafe cookies set by the following sites:"
Code: Select all
.webmail.twc.com
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:38.0) Gecko/20100101 Firefox/38.0
-
Gari
Re: Could not logon to Time-Warner/Roadrunner Webmail
@Thrawn: I added the code you indicated and it works! However, how can I report this unsafe webmail cookies to Time-Warner Cable/Roadrunner webmail? That this means that accessing my webmail account is not safe?
- Thanks Thrawn, and everybody for your help.
- Thanks Thrawn, and everybody for your help.
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:39.0) Gecko/20100101 Firefox/39.0
Re: Could not logon to Time-Waner/Roadrunner Webmail
As a workaround, can you force HTTPS on the site and have it still work?
NoScript Options > Advanced > HTTPS > Behavior, add the same string suggested by Thrawn to "Force the following sites to use secure (HTTPS) connections"
NoScript Options > Advanced > HTTPS > Behavior, add the same string suggested by Thrawn to "Force the following sites to use secure (HTTPS) connections"
*Always* check the changelogs BEFORE updating that important software!
-
-
Gari
Re: Could not logon to Time-Warner/Roadrunner Webmail
@barbaz: As shown by the Browser Console, "https://" was already being used, but anyway, adding that same code provided by Thrawn to force secure https as you suggested works! How can I inform Time-Warner Cable/Roadrunner webmail that their site having unsafe website cookies?
- Again, many thanks to everybody.
- Again, many thanks to everybody.
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:39.0) Gecko/20100101 Firefox/39.0
Re: Could not logon to Time-Warner/Roadrunner Webmail
I don't know?Gari wrote:How can I inform Time-Warner Cable/Roadrunner webmail that their site having unsafe website cookies?
You can email them and point them to this thread, no? Or call them?
*Always* check the changelogs BEFORE updating that important software!
-
Re: Could not logon to Time-Waner/Roadrunner Webmail
Forcing HTTPS is a good idea, if it works. If automatic cookie management is breaking the site, then something is being accessed over plaintext.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:38.0) Gecko/20100101 Firefox/38.0
Re: Could not logon to Time-Waner/Roadrunner Webmail
I'm not sure this necessarily follows. I tried out NoScript's automatic secure cookies management for a while, visited a webmail site (not the one in this thread) that had no redirections through plain HTTP nor did it load anything over plain HTTP according to blockable items in my ABP-fork, and the site was completely broken until I disabled automatic secure cookies management and cleared cookies...Thrawn wrote:If automatic cookie management is breaking the site, then something is being accessed over plaintext.

*Always* check the changelogs BEFORE updating that important software!
-
Re: Could not logon to Time-Waner/Roadrunner Webmail
Well, if the site was really doing nothing at all over HTTP, then it wouldn't make sense for problems to arise from cookies being secured...
If you still have access to that site, can you reproduce the problem? And what happens if HTTPS is forced?
If you still have access to that site, can you reproduce the problem? And what happens if HTTPS is forced?
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.
True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:38.0) Gecko/20100101 Firefox/38.0
Re: Could not logon to Time-Waner/Roadrunner Webmail
I still have access to the site but it's not exactly a playground
or I would have troubleshot a bit more... maybe I can try again sometime but can't atm. 
*Always* check the changelogs BEFORE updating that important software!
-