|
1 | 1 | <!-- |
| 2 | + Note: https?://collaborateext(stg)?.../$ redirects to a |
| 3 | + port on which nothing appears to listen/reply |
| 4 | + ?=> fetch test failures |
| 5 | +
|
2 | 6 | Other Verizon rulesets: |
3 | 7 |
|
4 | 8 | - Share_the_Network.xml |
| 9 | + - verizon.net.xml |
| 10 | + - verizonbusiness.com.xml |
5 | 11 | - Verizon_Enterprise.xml |
6 | 12 | - Verizon_Wireless.xml |
7 | 13 |
|
|
10 | 16 |
|
11 | 17 | - ak1s.abmr.net/is/www22.verizon.com |
12 | 18 | - vznews.convio.net |
13 | | -
|
14 | | - - wildcard.verizon.net.edgekey.net |
15 | | - - static-business.verizon.net |
16 | | -
|
17 | 19 | - ehg-verizon.hitbox.com |
18 | 20 | - vzw.jiwire.com |
19 | | -
|
20 | 21 | - vrzn.i.lithium.com |
21 | 22 |
|
22 | 23 | - vrzn.lithium.com |
|
29 | 30 | - (www.)thinkfinity.org |
30 | 31 | - (www.)community.thinkfinity.org |
31 | 32 | - developer.verizon.com * |
| 33 | + - fiostrending.verizon.com ʰ |
32 | 34 | - foundation.verizon.com (shows RHEL test page; self-signed, CN: ph1025101.bwi40g.vzbi.caas) |
33 | | - - mail.verizon.com * |
34 | 35 | - newscenter2.verizon.com (no https) |
35 | 36 | - publicpolicy.verizon.com (redirects to forums; mismatched, CN: responsibility.verizon.com) |
36 | | - - webmail.verizon.com * |
37 | 37 |
|
38 | 38 | * Times out. |
| 39 | + ʰ Redirects to http |
39 | 40 |
|
40 | 41 |
|
41 | 42 | Problematic domains: |
42 | 43 |
|
| 44 | + - verizon.com ᵐ |
43 | 45 | - about.verizon.com (works; self-signed, CN: vz-about-dev.com) |
44 | 46 | - entertainment.verizon.com (some pages work, at least games/index.php 404s) |
| 47 | + - responsibility.verison.com ʳ |
45 | 48 | - searchresults.verizon.com (works; mismatched, CN: entertainmentlogin.verizon.com) |
46 | | - - verizon.net * |
47 | | - - businessforums.verizon.net ** |
48 | | - - verizonbusiness.com * |
49 | 49 |
|
50 | | - * Cert only matches www |
51 | | - ** CN: secure02.lithium.com, works. Handled mostly in Lithium-clients.xml. |
| 50 | + ᵐ Mismatched |
| 51 | + ʳ Refused; preemptable redirect |
52 | 52 |
|
53 | 53 |
|
54 | | - Partially covered domains: |
| 54 | + Partially covered hosts in *verizon.com: |
55 | 55 |
|
56 | | - - collaborateext.verizon.com ¹ |
57 | | - - collaborateextstg.verizon.com ¹ |
58 | | - - www22.verizon.com * |
59 | | - - www98.verizon.com *** |
60 | | - - business.verizon.net ** |
61 | | - - (www.)verizonbusiness.com *** |
| 56 | + - (www.)? ** |
| 57 | + - collaborateext ¹ |
| 58 | + - collaborateextstg ¹ |
| 59 | + - www22 * |
| 60 | + - www98 |
62 | 61 |
|
| 62 | + ** ?lid=//global//residential redirects |
63 | 63 | ¹ $ redirects to ...:449 |
64 | 64 |
|
65 | 65 | * See: |
66 | | - - https://mail1.eff.org/pipermail/https-everywhere/2011-November/001237.html |
67 | | - - https://mail1.eff.org/pipermail/https-everywhere-rules/2012-February/001003.html |
| 66 | + - https://lists.eff.org/pipermail/https-everywhere/2011-November/001237.html |
| 67 | + - https://lists.eff.org/pipermail/https-everywhere-rules/2012-February/001003.html |
68 | 68 |
|
69 | 69 | NB: Has this been fixed? It doesn't seem to loop... |
70 | 70 |
|
71 | | - * The login page, and only the login page(!), redirects to http. |
72 | | - *** Some (most?) pages redirect to http. |
73 | 71 |
|
| 72 | + Insecure cookies are set for these domains and hosts: |
74 | 73 |
|
75 | | - Fully covered domains: |
| 74 | + - .verizon.com |
| 75 | + - auth.verizon.com |
| 76 | + - enterprisecenter.verizon.com |
| 77 | + - espanol.verizon.com |
| 78 | + - forums.verizon.com |
| 79 | + - signin.verizon.com |
| 80 | + - smallbizrewards.verizon.com |
| 81 | + - webmail.verizon.com |
| 82 | + - .webmail.verizon.com |
| 83 | + - www.verizon.com |
| 84 | + - www36.verizon.com |
| 85 | + - www98.verizon.com |
76 | 86 |
|
77 | | - - verizon.com subdomains: |
78 | 87 |
|
79 | | - - (www.) |
80 | | - - auth |
81 | | - - enterprisecenter |
82 | | - - entertainmentlogin |
83 | | - - espanol |
84 | | - - forums |
85 | | - - responsibility |
86 | | - - signin |
87 | | - - smallbusiness |
88 | | - - webmail |
| 88 | + Mixed content: |
89 | 89 |
|
90 | | - - (www.)verizon.net |
91 | | - - static-business.verizon.net |
| 90 | + - Images on forums, www from $self |
92 | 91 |
|
93 | | ---> |
94 | | -<ruleset name="Verizon (partial)"> |
| 92 | + - Ads / bugs, on: |
95 | 93 |
|
| 94 | + - www from fls.doubleclick.net |
| 95 | + - www from \d+.fls.doubleclick.net |
| 96 | +
|
| 97 | +--> |
| 98 | +<ruleset name="Verizon.com (partial)"> |
| 99 | + |
| 100 | + <!-- Direct rewrites: |
| 101 | + --> |
| 102 | + <target host="auth.verizon.com" /> |
| 103 | + <!--target host="business.verizon.com" /--> |
| 104 | + <target host="collaborateext.verizon.com" /> |
| 105 | + <target host="collaborateextstg.verizon.com" /> |
| 106 | + <target host="enterprisecenter.verizon.com" /> |
| 107 | + <target host="entertainmentlogin.verizon.com" /> |
| 108 | + <target host="espanol.verizon.com" /> |
| 109 | + <target host="forums.verizon.com" /> |
| 110 | + <!--target host="mail.verizon.com" /--> |
| 111 | + <!--target host="mblogin.verizon.com" /--> |
| 112 | + <!--target host="myverizonenterprise.verizon.com" /--> |
| 113 | + <!--target host="respframework.verizon.com" /--> |
| 114 | + <target host="signin.verizon.com" /> |
| 115 | + <!--target host="smallbizrewards.verizon.com" /--> |
| 116 | + <target host="smallbusiness.verizon.com" /> |
| 117 | + <target host="webmail.verizon.com" /> |
| 118 | + <target host="www.verizon.com" /> |
| 119 | + <target host="www22.verizon.com" /> |
| 120 | + <target host="www98.verizon.com" /> |
| 121 | + |
| 122 | + <!-- Complications: |
| 123 | + --> |
96 | 124 | <target host="verizon.com" /> |
97 | | - <target host="*.verizon.com" /> |
98 | | - <exclusion pattern="^http://collaborateext(?:stg)?\.verizon\.com/(?:$|\?|aims/main/ext_index\.jsp)" /> |
| 125 | + <target host="responsibility.verizon.com" /> |
| 126 | + <target host="www36.verizon.com" /> |
| 127 | + |
| 128 | + <!-- Redirect differs: |
| 129 | + --> |
| 130 | + <!--exclusion pattern="^http://www\.verizon\.com/\?lid=//global//residential" /--> |
99 | 131 | <!-- |
100 | | - investor/DocServlet 404s |
| 132 | + More conservatively: |
| 133 | + --> |
| 134 | + <exclusion pattern="^http://(?:www\.)?verizon\.com/+\?(?:.*&)?lid=" /> |
| 135 | + |
| 136 | + <!-- +ve: |
| 137 | + --> |
| 138 | + <test url="http://verizon.com/?lid=" /> |
| 139 | + <test url="http://verizon.com/?lid=//global" /> |
| 140 | + <test url="http://verizon.com/?lid=//global//residential" /> |
| 141 | + <test url="http://www.verizon.com/?lid=" /> |
| 142 | + <test url="http://www.verizon.com/?lid=//global" /> |
| 143 | + <test url="http://www.verizon.com/?lid=//global//residential" /> |
| 144 | + |
| 145 | + <!-- -ve: |
| 146 | + --> |
| 147 | + <test url="http://www.verizon.com/home/ak-cached/2h/styles/common.css" /> |
| 148 | + |
| 149 | + <!-- investor/DocServlet 404s |
101 | 150 | --> |
102 | 151 | <exclusion pattern="^http://www22\.verizon\.com/(?:Foryourhome/MyAccount/Unprotected|investor/DocServlet|secure/pages/viewbill)/" /> |
| 152 | + |
| 153 | + <!-- +ve: |
| 154 | + --> |
| 155 | + <test url="http://www22.verizon.com/Foryourhome/MyAccount/Unprotected/" /> |
| 156 | + <test url="http://www22.verizon.com/investor/DocServlet/" /> |
| 157 | + <test url="http://www22.verizon.com/secure/pages/viewbill/" /> |
| 158 | + |
| 159 | + <!-- Redirects to http: |
| 160 | + --> |
103 | 161 | <exclusion pattern="^http://www98\.verizon\.com/(?:$|\?)" /> |
104 | | - <target host="verizon.net" /> |
105 | | - <target host="*.verizon.net" /> |
106 | | - <exclusion pattern="^http://business\.verizon\.net/.*SMBPortalWeb/login$" /> |
107 | | - <target host="verizonbusiness.com" /> |
108 | | - <target host="www.verizonbusiness.com" /> |
109 | 162 |
|
| 163 | + <!-- +ve: |
| 164 | + --> |
| 165 | + <test url="http://www98.verizon.com/?" /> |
| 166 | + <test url="http://www98.verizon.com/?utm_source=" /> |
| 167 | + |
| 168 | + <!-- -ve: |
| 169 | + --> |
| 170 | + <test url="http://www98.verizon.com/cs/groups/public/documents/adacct/caret_svg.svg" /> |
| 171 | + <test url="http://www98.verizon.com/home/ak-cached/2h/styles/common.css" /> |
| 172 | + <test url="http://www98.verizon.com/resources/verizonglobalhome/i/buttons/pause.png" /> |
| 173 | + <test url="http://www98.verizon.com/support/residential/billingcenter/homepage.htm" /> |
| 174 | + |
| 175 | + <!-- $ redirects to nonfunctional port, so: |
| 176 | + --> |
| 177 | + <test url="http://collaborateext.verizon.com/aims/encore/recapScreen_new.jsp" /> |
| 178 | + |
| 179 | + <!-- Sets cookies without Secure: |
| 180 | + --> |
| 181 | + <test url="http://www36.verizon.com/fiosvoice/signin.aspx?goto=http://www36.verizon.com:80/fiosvoice/members/default.aspx" /> |
| 182 | + |
| 183 | + |
| 184 | + <!-- Not secured by server: |
| 185 | + --> |
| 186 | + <!--securecookie host="^\.verizon\.com$" name="^(?:Aka[SU]TrackingID|AMAuthCookie|CHAT_IN_PROGRESS|GlobalSessionID|HBXInitialVisit|INTERACTIVE_CHAT|ReferenceSessionCookie|VA_CHAT_IN_PROGRESS|dotcomsid|hersheys|islogin|lob|vzapps)$" /--> |
| 187 | + <!--securecookie host="^auth\.verizon\.com$" name="^JSESSIONID$" /--> |
| 188 | + <!--securecookie host="^enterprisecenter\.verizon\.com$" name="^NSC_" /--> |
| 189 | + <!--securecookie host="^espanol\.verizon\.com$" name="(?:_JSESSIONID$|NSC_)" /--> |
| 190 | + <!--securecookie host="^forums\.verizon\.com$" name="^Lithium(?:UserInfo|UserSecure|Visitor)$" /--> |
| 191 | + <!--securecookie host="^signin\.verizon\.com$" name="^VZSSOCOM_SESSIONID$" /--> |
| 192 | + <!--securecookie host="^smallbizrewards\.verizon\.com$" name="^CF(?:ID|TOKEN)$" /--> |
| 193 | + <!--securecookie host="^webmail\.verizon\.com$" name="^(?:AlteonP|JSESSIONID|webmail_ad)$" /--> |
| 194 | + <!--securecookie host="^\.webmail\.verizon\.com$" name="^webmailauthgeo$" /--> |
| 195 | + <!--securecookie host="^www\.verizon\.com$" name="^(?:NSC_|SMBWEBLEARNSESSIONID$)" /--> |
| 196 | + <!--securecookie host="^www36\.verizon\.com$" name="^(?:ASP\.NET_SessionId|Vzopt)$" /--> |
| 197 | + <!--securecookie host="^www98\.verizon\.com$" name="^(?:(?:ESUPPORT_JSESSIONID|omnivendorflag|ppsh_omni_flag|ppshcondcode|ppshcondcodeflag|state_flag|uniqueId)$|NSC_)" /--> |
110 | 198 |
|
111 | | - <securecookie host="^(?:enterprisecenter|espanol|forums|responsibility|signin|smallbusiness|webmail)\.verizon\.com$" name=".+" /> |
112 | 199 | <!--securecookie host="^\.verizon\.com$" name=".+" /--> |
| 200 | + <securecookie host="^(?:enterprisecenter|espanol|forums|responsibility|signin|smallbusiness|webmail)\.verizon\.com$" name=".+" /> |
113 | 201 | <!--securecookie host="^www22\.verizon\.com$" name=".+" /--> |
114 | | - <securecookie host="^(?:www\.)?verizon\.net$" name=".+" /> |
115 | | - <!--securecookie host="^.*\.verizon\.net$" name=".+" /--> |
116 | | - |
117 | 202 |
|
118 | | - <rule from="^http://(?:www(?:22)?\.)?verizon\.com/(?:$|\?.*)" |
119 | | - to="https://www22.verizon.com/home/verizonglobalhome/ghp_landing.aspx" /> |
120 | 203 |
|
121 | | - <rule from="^http://(?:www(22|98)?\.)?verizon\.com/" |
122 | | - to="https://www$1.verizon.com/" /> |
| 204 | + <rule from="^http://verizon\.com/" |
| 205 | + to="https://www.verizon.com/" /> |
123 | 206 |
|
124 | | - <rule from="^http://(auth|collaborateext(?:stg)?|enterprisecenter|entertainmentlogin|espanol|forums|responsibility|smallbusiness|signon|webmail)\.verizon\.com/" |
125 | | - to="https://$1.verizon.com/" /> |
| 207 | + <!-- Redirect drops forward slash, path, and args: |
| 208 | + --> |
| 209 | + <rule from="^http://responsibility\.verizon\.com/.*" |
| 210 | + to="https://www.verizon.com/about/responsibility/" /> |
126 | 211 |
|
127 | | - <rule from="^http://(?:www\.)?verizon\.net/" |
128 | | - to="https://www.verizon.net/" /> |
| 212 | + <test url="http://responsibility.verizon.com/default.aspx" /> |
129 | 213 |
|
130 | | - <rule from="^http://(static-)?business\.verizon\.net/" |
131 | | - to="https://$1business.verizon.net/" /> |
| 214 | + <rule from="^http://www36\.verizon\.com:80/" |
| 215 | + to="https://www36.verizon.com/" /> |
132 | 216 |
|
133 | | - <rule from="^http://businessforums\.verizon\.net/html/" |
134 | | - to="https://forums.verizon.com/html/" /> |
| 217 | + <test url="http://www36.verizon.com:80/fiosvoice/members/default.aspx" /> |
135 | 218 |
|
136 | | - <rule from="^http://(?:www\.)?verizonbusiness\.com/(gfx|support/myaccount|templates)/" |
137 | | - to="https://www.verizonbusiness.com/$1/" /> |
| 219 | + <rule from="^http:" |
| 220 | + to="https:" /> |
138 | 221 |
|
139 | 222 | </ruleset> |
0 commit comments