tux0r That w3m issue seems unrelated; for some reason the request your client is making is tripping a security measure in our stack. Suggest opening a new ticket with details to reproduce; a quick test in lynx (what I had on hand) works fine. Support for this modality is "best effort", but it should at least be functional for text browsers.
Maybe a quick thing I could suggest is making sure that cookies are enabled. It's a total guess, but there are some security related cookies that we use that if not used properly (at all) may trigger a response like this. I know at least lynx is stuffy about using cookies by default. Login won't work anyways if cookies are not enabled for our domain.