Thanks
Thrawn for providing that ABE information, I really appreciate it.
Actually now that you've mentioned it in regards to Union Bank, I was not able to determine the site that needed to be blocked using the Avast scanning statistics as I had with the BofA site as nothing was being scanned when the Union Bank website failed and logged me out due to the XXS setting problem in NoScript. Presumably what was done was internal to the website leaving the NoScript "console" the only resource available to me to get the information I needed. So ultimately I actually ended up gleaning the web site to use in the Anti-XXS Protection Exceptions list
from the console data. Searching the data I found the URL "
https://sso.unionbank.com" that solved the problem involving the XXS protection setting that was causing the website to fail and logoff. So the console data came in handy for sure in this case. Incidentally the BofA issue did not provide any console information but fortunately I was able to finally determine the problem site in this case from the Avast scanning stats. I'm not at all familiar with any of this stuff, but was able to use the data to at least come up with a URL to try out in the XXS Protection Exceptions list that worked to solve the problem. I have to say, that I'm basically "flying by the seat of my pants" here so to speak, since most of this stuff is not really familiar to me and it's been largely a "trial and error" situation for me in many ways. I am pleased that I was able to figure out what sites needed to be excluded in the "exceptions" list for XXS so that I am able to continue to use this source of security provided by NoScript as opposed to losing this level of security globally.
Below is the "Console Data" that I used to come up with the "exception" to use in NoScript XXS, if there's anything else in there that is helpful then feel free to post anything that might be helpful.
Thanks very much for that "ABE" rule stuff, I'm not at all familiar with this either and will have to read up on it, but for now
I've added what you provided in your post to the ABE "Rulesets" box of which there was nothing there at the time. Again,
I thank you very much for that.
I have to say much of this stuff is very esoteric, as I'm not sure how the "typical" user would know anything about how to add this as you've provided here:
Code: Select all
Site .roll.bankofamerica.com
Accept from .bankofamerica.com
Deny
Site .sso.unionbank.com
Accept from .unionbank.com
Deny
I have to ask, how would a "typical" user know the specific
syntax and format to use for the entries in an ABE "ruleset" such as beginning with "Site" and including the "Accept from" line and finally the "Deny" not to mention the rest?
I've superficially checked out the webpage
ABE - Application Boundaries Enforcer utilizing the "?" link provided in the "Options" > "Advanced" > "ABE" tab but I have to tell you this stuff is way over the head of the average user obviously. I'm a retired (long ago) computer programmer and current software support global moderator on another support site but even with my background I have to say I've really got very little clue about a lot of this stuff to be honest and to be fair it would take someone quit a bit of time and research to get up to just minimal speed to acquire even some basic knowledge about a lot of this.
I get the idea what these Abe "rulesets do for me in this case is provide me with additional security to counter the reduced security that is the result of "excluding" these sites in XSS so that by adding this to ABE the essentially "lost" or the virtual "hole" left in the security as a result of these XSS exclusions is compensated for by adding these "rulesets" in ABE. And that while we can hopefully trust these websites that I've excluded, by "excluding" them it leaves an opportunity for other unscrupulous sites to take advantage of perhaps. At least this is my understanding, but that said I personally would have NEVER known how to add these "rulesets" you've been so considerate to provide here.
Here is the
CONSOLE DATA I used to find the site to try in the XXS exclude for Union Bank (in bold, cannot color tag) for what it's worth:
Code: Select all
Warning: attempting to write 5070 bytes to preference extensions.disconnect.blockedRequests. This is bad for general performance and memory usage. Such an amount of data should rather be written to an external file.
A form was submitted in the windows-1252 encoding which cannot encode all Unicode characters, so user input may get corrupted. To avoid this problem, the page should be changed so that the form is submitted in the UTF-8 encoding either by changing the encoding of the page itself to UTF-8 or by specifying accept-charset=utf-8 on the form element. eluminate.js:1:0
This site makes use of a SHA-1 Certificate; it's recommended you use certificates with signature algorithms that use hash functions stronger than SHA-1.[Learn More] urlinfo
A form was submitted in the windows-1252 encoding which cannot encode all Unicode characters, so user input may get corrupted. To avoid this problem, the page should be changed so that the form is submitted in the UTF-8 encoding either by changing the encoding of the page itself to UTF-8 or by specifying accept-charset=utf-8 on the form element. preimage.view:26:0
[NoScript InjectionChecker] JavaScript Injection in ##<map><entry><string>FPREQ_COUNTRY</string><string>United States</string></entry><entry><string>HRT_USER_FIRST_NAME</string></entry><entry><string>HRT_TRANSACTION_DATE_TIME</string><string>2015-09-01 13:29:28.028</string></entry><entry><string>FPREQ_SYSTEM_LANGUAGE</string></entry><entry><string>FPREQ_USER_AGENT</string><string>Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0</string></entry><entry><string>FPREQ_ACCEPT_LANGUAGE</string><string>en-US,en;q=0.5</string></entry><entry><string>HRT_PTT_OPEN_DATE</string><string>2005-04-19</string></entry><entry><string>FPREQ_REFERER</string><string>https://bankingsso.unionbank.com/detail/detail.view?selectedAccountCode=0000</string></entry><entry><string>HRT_REQUEST_ID</string><string>B@H1a676615-5afd-4852-9a0d-f5cbc50d6826</string></entry><entry><string>FPREQ_REMOTE_ADDR</string><string>108.89.80.37</string></entry><entry><string>HRT_USER_LAST_NAME</string></entry><entry><string>HRT_LOGIN_NAME</string></entry><entry><string>HRT_TRANSACTION_KEY</string></entry><entry><string>FPREQ_USER_LANGUAGE</string></entry><entry><string>FPREQ_DEVICE_PRINT</string><string>version=2&pm_fpua=mozilla/5.0 (windows nt 6.1; wow64; rv:40.0) gecko/20100101 firefox/40.0|5.0 (Windows)|Win32&pm_fpsc=24|1600|900|860&pm_fpsw=pdf|pdf|qt4|qt1|qt3|qt2|qt5|dsw&pm_fptz=-7&pm_fpln=lang=en-US|syslang=|userlang=&pm_fpjv=1&pm_fpco=1&pm_fpasw=nppdf32|nppdf32|npqscan|npgeplugin|npgoogleupdate3|npdeployjava1|npjp2|npauthz|npspwrap|npspwrap|npqtplugin4|npqtplugin|npqtplugin3|npqtplugin2|npqtplugin5|npswf32_18_0_0_232|np32dsw|npctrl|npvlc|npwlpg&pm_fpan=Netscape&pm_fpacn=Mozilla&pm_fpol=true&pm_fposp=&pm_fpup=&pm_fpsaw=1600&pm_fpspd=24&pm_fpsbd=&pm_fpsdx=&pm_fpsdy=&pm_fpslx=&pm_fpsly=&pm_fpsfse=&pm_fpsui=</string></entry><entry><string>ORMREQ_APP_ID</string><string>B@H</string></entry><entry><string>FPREQ_USER_COOKIE</string><string>108.89.80.37|1414963560302|0.0729898952474769</string></entry><entry><string>HRT_CUSTOMER_SEGMENT_TYPE</string></entry><entry><string>FPREQ_OTHER</string><string>gzip, deflate|null|vHmlMxVIdw-WwMA-cYiamQ__.banking-app06</string></entry><entry><string>FPREQ_ACCEPT</string><string>text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8</string></entry><entry><string>HRT_SESSION_ID</string></entry><entry><string>HRT_EVENT_DATA_LIST</string><list><map><entry><string>HRT_TRX_COUNTER</string></entry><entry><string>HRT_TRX_KEY</string></entry></map></list></entry></map>
[NoScript XSS] Sanitized suspicious upload to [[b]https://sso.unionbank.com/[/b]HRTInvocationServlet###DATA###%3Cmap%3E%3Centry%3E%3Cstring%3EFPREQ_COUNTRY%3C%2Fstring%3E%3Cstring%3EUnited+States%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_USER_FIRST_NAME%3C%2Fstring%3E%3Cstring%3EMichael%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_TRANSACTION_DATE_TIME%3C%2Fstring%3E%3Cstring%3E2015-09-01+13%3A29%3A28.028%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_SYSTEM_LANGUAGE%3C%2Fstring%3E%3Cstring%3EEnglish%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_USER_AGENT%3C%2Fstring%3E%3Cstring%3EMozilla%2F5.0+%28Windows+NT+6.1%3B+WOW64%3B+rv%3A40.0%29+Gecko%2F20100101+Firefox%2F40.0%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_ACCEPT_LANGUAGE%3C%2Fstring%3E%3Cstring%3Een-US%2Cen%3Bq%3D0.5%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_PTT_OPEN_DATE%3C%2Fstring%3E%3Cstring%3E2005-04-19%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_REFERER%3C%2Fstring%3E%3Cstring%3Ehttps%3A%2F%2Fbankingsso.unionbank.com%2Fdetail%2Fdetail.view%3FselectedAccountCode%3D0000%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_REQUEST_ID%3C%2Fstring%3E%3Cstring%3EB%40H1a676615-5afd-4852-9a0d-f5cbc50d6826%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_REMOTE_ADDR%3C%2Fstring%3E%3Cstring%3E108.89.80.37%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_USER_LAST_NAME%3C%2Fstring%3E%3Cstring%3ESegesman%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_LOGIN_NAME%3C%2Fstring%3E%3Cstring%3Emichaeljohn47%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_TRANSACTION_KEY%3C%2Fstring%3E%3Cstring%3E301%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_USER_LANGUAGE%3C%2Fstring%3E%3Cstring%3EEnglish%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_DEVICE_PRINT%3C%2Fstring%3E%3Cstring%3Eversion%3D2%26amp%3Bpm_fpua%3Dmozilla%2F5.0+%28windows+nt+6.1%3B+wow64%3B+rv%3A40.0%29+gecko%2F20100101+firefox%2F40.0%7C5.0+%28Windows%29%7CWin32%26amp%3Bpm_fpsc%3D24%7C1600%7C900%7C860%26amp%3Bpm_fpsw%3Dpdf%7Cpdf%7Cqt4%7Cqt1%7Cqt3%7Cqt2%7Cqt5%7Cdsw%26amp%3Bpm_fptz%3D-7%26amp%3Bpm_fpln%3Dlang%3Den-US%7Csyslang%3D%7Cuserlang%3D%26amp%3Bpm_fpjv%3D1%26amp%3Bpm_fpco%3D1%26amp%3Bpm_fpasw%3Dnppdf32%7Cnppdf32%7Cnpqscan%7Cnpgeplugin%7Cnpgoogleupdate3%7Cnpdeployjava1%7Cnpjp2%7Cnpauthz%7Cnpspwrap%7Cnpspwrap%7Cnpqtplugin4%7Cnpqtplugin%7Cnpqtplugin3%7Cnpqtplugin2%7Cnpqtplugin5%7Cnpswf32_18_0_0_232%7Cnp32dsw%7Cnpctrl%7Cnpvlc%7Cnpwlpg%26amp%3Bpm_fpan%3DNetscape%26amp%3Bpm_fpacn%3DMozilla%26amp%3Bpm_fpol%3Dtrue%26amp%3Bpm_fposp%3D%26amp%3Bpm_fpup%3D%26amp%3Bpm_fpsaw%3D1600%26amp%3Bpm_fpspd%3D24%26amp%3Bpm_fpsbd%3D%26amp%3Bpm_fpsdx%3D%26amp%3Bpm_fpsdy%3D%26amp%3Bpm_fpslx%3D%26amp%3Bpm_fpsly%3D%26amp%3Bpm_fpsfse%3D%26amp%3Bpm_fpsui%3D%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EORMREQ_APP_ID%3C%2Fstring%3E%3Cstring%3EB%40H%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_USER_COOKIE%3C%2Fstring%3E%3Cstring%3E108.89.80.37%7C1414963560302%7C0.0729898952474769%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_CUSTOMER_SEGMENT_TYPE%3C%2Fstring%3E%3Cstring%3ER%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_OTHER%3C%2Fstring%3E%3Cstring%3Egzip%2C+deflate%7Cnull%7CvHmlMxVIdw-WwMA-cYiamQ__.banking-app06%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_ACCEPT%3C%2Fstring%3E%3Cstring%3Etext%2Fhtml%2Capplication%2Fxhtml%2Bxml%2Capplication%2Fxml%3Bq%3D0.9%2C*%2F*%3Bq%3D0.8%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_SESSION_ID%3C%2Fstring%3E%3Cstring%3E128862341%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_EVENT_DATA_LIST%3C%2Fstring%3E%3Clist%3E%3Cmap%3E%3Centry%3E%3Cstring%3EHRT_TRX_COUNTER%3C%2Fstring%3E%3Cstring%3E1%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_TRX_KEY%3C%2Fstring%3E%3Cstring%3E301%3C%2Fstring%3E%3C%2Fentry%3E%3C%2Fmap%3E%3C%2Flist%3E%3C%2Fentry%3E%3C%2Fmap%3E] from [https://bankingsso.unionbank.com/detail/preimage.view]: transformed into a download-only GET request.
Warning: attempting to write 5070 bytes to preference extensions.disconnect.blockedRequests. This is bad for general performance and memory usage. Such an amount of data should rather be written to an external file.
Warning: attempting to write 5070 bytes to preference extensions.disconnect.blockedRequests. This is bad for general performance and memory usage. Such an amount of data should rather be written to an external file.
SyntaxError: unreachable code after return statement jquery-1.3.2.min.js:19:13091
Warning: attempting to write 5070 bytes to preference extensions.disconnect.blockedRequests. This is bad for general performance and memory usage. Such an amount of data should rather be written to an external file.
Warning: attempting to write 5070 bytes to preference extensions.disconnect.blockedRequests. This is bad for general performance and memory usage. Such an amount of data should rather be written to an external file.
Warning: attempting to write 5070 bytes to preference extensions.disconnect.blockedRequests. This is bad for general performance and memory usage. Such an amount of data should rather be written to an external file.
Warning: attempting to write 5070 bytes to preference extensions.disconnect.blockedRequests. This is bad for general performance and memory usage. Such an amount of data should rather be written to an external file.
Warning: attempting to write 5070 bytes to preference extensions.disconnect.blockedRequests. This is bad for general performance and memory usage. Such an amount of data should rather be written to an external file.
A form was submitted in the windows-1252 encoding which cannot encode all Unicode characters, so user input may get corrupted. To avoid this problem, the page should be changed so that the form is submitted in the UTF-8 encoding either by changing the encoding of the page itself to UTF-8 or by specifying accept-charset=utf-8 on the form element. eluminate.js:1:0
TelemetryStopwatch: key "FX_PAGE_LOAD_MS" was already initialized TelemetryStopwatch.jsm:52:0
SyntaxError: unreachable code after return statement ad.views.20150721.js:1097:8
SyntaxError: unreachable code after return statement ad.views.20150721.js:3290:8
Warning: attempting to write 5070 bytes to preference extensions.disconnect.blockedRequests. This is bad for general performance and memory usage. Such an amount of data should rather be written to an external file.
Synchronous XMLHttpRequest on the main thread is deprecated because of its detrimental effects to the end user's experience. For more help http://xhr.spec.whatwg.org/ jquery.min.20150721.js:4:0
SyntaxError: unreachable code after return statement ad.views.20150721.js:3290:8
Warning: attempting to write 5070 bytes to preference extensions.disconnect.blockedRequests. This is bad for general performance and memory usage. Such an amount of data should rather be written to an external file.
A form was submitted in the windows-1252 encoding which cannot encode all Unicode characters, so user input may get corrupted. To avoid this problem, the page should be changed so that the form is submitted in the UTF-8 encoding either by changing the encoding of the page itself to UTF-8 or by specifying accept-charset=utf-8 on the form element. eluminate.js:1:0
A form was submitted in the windows-1252 encoding which cannot encode all Unicode characters, so user input may get corrupted. To avoid this problem, the page should be changed so that the form is submitted in the UTF-8 encoding either by changing the encoding of the page itself to UTF-8 or by specifying accept-charset=utf-8 on the form element. preimage.view:26:0
TelemetryStopwatch: key "FX_PAGE_LOAD_MS" was already initialized TelemetryStopwatch.jsm:52:0
[NoScript InjectionChecker] JavaScript Injection in ##<map><entry><string>FPREQ_COUNTRY</string><string>United States</string></entry><entry><string>HRT_USER_FIRST_NAME</string></entry><entry><string>HRT_TRANSACTION_DATE_TIME</string><string>2015-09-01 13:33:37.037</string></entry><entry><string>FPREQ_SYSTEM_LANGUAGE</string></entry><entry><string>FPREQ_USER_AGENT</string><string>Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0</string></entry><entry><string>FPREQ_ACCEPT_LANGUAGE</string><string>en-US,en;q=0.5</string></entry><entry><string>HRT_PTT_OPEN_DATE</string><string>2005-04-19</string></entry><entry><string>FPREQ_REFERER</string><string>https://bankingsso.unionbank.com/detail/detail.view?selectedAccountCode=0000</string></entry><entry><string>HRT_REQUEST_ID</string><string>B@H09caba81-4033-4c84-87eb-3718ff801a70</string></entry><entry><string>FPREQ_REMOTE_ADDR</string><string>108.89.80.37</string></entry><entry><string>HRT_USER_LAST_NAME</string></entry><entry><string>HRT_LOGIN_NAME</string></entry><entry><string>HRT_TRANSACTION_KEY</string></entry><entry><string>FPREQ_USER_LANGUAGE</string></entry><entry><string>FPREQ_DEVICE_PRINT</string><string>version=2&pm_fpua=mozilla/5.0 (windows nt 6.1; wow64; rv:40.0) gecko/20100101 firefox/40.0|5.0 (Windows)|Win32&pm_fpsc=24|1600|900|860&pm_fpsw=pdf|pdf|qt4|qt1|qt3|qt2|qt5|dsw&pm_fptz=-7&pm_fpln=lang=en-US|syslang=|userlang=&pm_fpjv=1&pm_fpco=1&pm_fpasw=nppdf32|nppdf32|npqscan|npgeplugin|npgoogleupdate3|npdeployjava1|npjp2|npauthz|npspwrap|npspwrap|npqtplugin4|npqtplugin|npqtplugin3|npqtplugin2|npqtplugin5|npswf32_18_0_0_232|np32dsw|npctrl|npvlc|npwlpg&pm_fpan=Netscape&pm_fpacn=Mozilla&pm_fpol=true&pm_fposp=&pm_fpup=&pm_fpsaw=1600&pm_fpspd=24&pm_fpsbd=&pm_fpsdx=&pm_fpsdy=&pm_fpslx=&pm_fpsly=&pm_fpsfse=&pm_fpsui=</string></entry><entry><string>ORMREQ_APP_ID</string><string>B@H</string></entry><entry><string>FPREQ_USER_COOKIE</string><string>108.89.80.37|1414963560302|0.0729898952474769</string></entry><entry><string>HRT_CUSTOMER_SEGMENT_TYPE</string></entry><entry><string>FPREQ_OTHER</string><string>gzip, deflate|null|-sE53LDttmt8UK+Tm-eZww__.banking-app06</string></entry><entry><string>FPREQ_ACCEPT</string><string>text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8</string></entry><entry><string>HRT_SESSION_ID</string></entry><entry><string>HRT_EVENT_DATA_LIST</string><list><map><entry><string>HRT_TRX_COUNTER</string></entry><entry><string>HRT_TRX_KEY</string></entry></map></list></entry></map>
[NoScript XSS] Sanitized suspicious upload to [[b]https://sso.unionbank.com/[/b]HRTInvocationServlet###DATA###%3Cmap%3E%3Centry%3E%3Cstring%3EFPREQ_COUNTRY%3C%2Fstring%3E%3Cstring%3EUnited+States%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_USER_FIRST_NAME%3C%2Fstring%3E%3Cstring%3EMichael%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_TRANSACTION_DATE_TIME%3C%2Fstring%3E%3Cstring%3E2015-09-01+13%3A33%3A37.037%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_SYSTEM_LANGUAGE%3C%2Fstring%3E%3Cstring%3EEnglish%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_USER_AGENT%3C%2Fstring%3E%3Cstring%3EMozilla%2F5.0+%28Windows+NT+6.1%3B+WOW64%3B+rv%3A40.0%29+Gecko%2F20100101+Firefox%2F40.0%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_ACCEPT_LANGUAGE%3C%2Fstring%3E%3Cstring%3Een-US%2Cen%3Bq%3D0.5%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_PTT_OPEN_DATE%3C%2Fstring%3E%3Cstring%3E2005-04-19%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_REFERER%3C%2Fstring%3E%3Cstring%3Ehttps%3A%2F%2Fbankingsso.unionbank.com%2Fdetail%2Fdetail.view%3FselectedAccountCode%3D0000%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_REQUEST_ID%3C%2Fstring%3E%3Cstring%3EB%40H09caba81-4033-4c84-87eb-3718ff801a70%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_REMOTE_ADDR%3C%2Fstring%3E%3Cstring%3E108.89.80.37%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_USER_LAST_NAME%3C%2Fstring%3E%3Cstring%3ESegesman%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_LOGIN_NAME%3C%2Fstring%3E%3Cstring%3Emichaeljohn47%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_TRANSACTION_KEY%3C%2Fstring%3E%3Cstring%3E301%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_USER_LANGUAGE%3C%2Fstring%3E%3Cstring%3EEnglish%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_DEVICE_PRINT%3C%2Fstring%3E%3Cstring%3Eversion%3D2%26amp%3Bpm_fpua%3Dmozilla%2F5.0+%28windows+nt+6.1%3B+wow64%3B+rv%3A40.0%29+gecko%2F20100101+firefox%2F40.0%7C5.0+%28Windows%29%7CWin32%26amp%3Bpm_fpsc%3D24%7C1600%7C900%7C860%26amp%3Bpm_fpsw%3Dpdf%7Cpdf%7Cqt4%7Cqt1%7Cqt3%7Cqt2%7Cqt5%7Cdsw%26amp%3Bpm_fptz%3D-7%26amp%3Bpm_fpln%3Dlang%3Den-US%7Csyslang%3D%7Cuserlang%3D%26amp%3Bpm_fpjv%3D1%26amp%3Bpm_fpco%3D1%26amp%3Bpm_fpasw%3Dnppdf32%7Cnppdf32%7Cnpqscan%7Cnpgeplugin%7Cnpgoogleupdate3%7Cnpdeployjava1%7Cnpjp2%7Cnpauthz%7Cnpspwrap%7Cnpspwrap%7Cnpqtplugin4%7Cnpqtplugin%7Cnpqtplugin3%7Cnpqtplugin2%7Cnpqtplugin5%7Cnpswf32_18_0_0_232%7Cnp32dsw%7Cnpctrl%7Cnpvlc%7Cnpwlpg%26amp%3Bpm_fpan%3DNetscape%26amp%3Bpm_fpacn%3DMozilla%26amp%3Bpm_fpol%3Dtrue%26amp%3Bpm_fposp%3D%26amp%3Bpm_fpup%3D%26amp%3Bpm_fpsaw%3D1600%26amp%3Bpm_fpspd%3D24%26amp%3Bpm_fpsbd%3D%26amp%3Bpm_fpsdx%3D%26amp%3Bpm_fpsdy%3D%26amp%3Bpm_fpslx%3D%26amp%3Bpm_fpsly%3D%26amp%3Bpm_fpsfse%3D%26amp%3Bpm_fpsui%3D%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EORMREQ_APP_ID%3C%2Fstring%3E%3Cstring%3EB%40H%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_USER_COOKIE%3C%2Fstring%3E%3Cstring%3E108.89.80.37%7C1414963560302%7C0.0729898952474769%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_CUSTOMER_SEGMENT_TYPE%3C%2Fstring%3E%3Cstring%3ER%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_OTHER%3C%2Fstring%3E%3Cstring%3Egzip%2C+deflate%7Cnull%7C-sE53LDttmt8UK%2BTm-eZww__.banking-app06%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EFPREQ_ACCEPT%3C%2Fstring%3E%3Cstring%3Etext%2Fhtml%2Capplication%2Fxhtml%2Bxml%2Capplication%2Fxml%3Bq%3D0.9%2C*%2F*%3Bq%3D0.8%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_SESSION_ID%3C%2Fstring%3E%3Cstring%3E1838822682%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_EVENT_DATA_LIST%3C%2Fstring%3E%3Clist%3E%3Cmap%3E%3Centry%3E%3Cstring%3EHRT_TRX_COUNTER%3C%2Fstring%3E%3Cstring%3E1%3C%2Fstring%3E%3C%2Fentry%3E%3Centry%3E%3Cstring%3EHRT_TRX_KEY%3C%2Fstring%3E%3Cstring%3E301%3C%2Fstring%3E%3C%2Fentry%3E%3C%2Fmap%3E%3C%2Flist%3E%3C%2Fentry%3E%3C%2Fmap%3E] from [https://bankingsso.unionbank.com/detail/preimage.view]: transformed into a download-only GET request.
Warning: attempting to write 5070 bytes to preference extensions.disconnect.blockedRequests. This is bad for general performance and memory usage. Such an amount of data should rather be written to an external file.
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------