Closed Bug 1892625 Opened 21 days ago Closed 5 days ago

leroymerlin.fr / sncf-connect.com CAPTCHA and then blocks

Categories

(Web Compatibility :: Site Reports, defect, P1)

Tracking

(Not tracked)

RESOLVED WORKSFORME

People

(Reporter: gerard-majax, Unassigned)

References

()

Details

(Keywords: webcompat:needs-contact, webcompat:needs-diagnosis)

User Story

platform:windows,mac,linux,android
impact:site-broken
configuration:general
affects:some

Attachments

(2 files)

STR:

  1. Reach https://www.leroymerlin.fr/
  2. CDN reports you are on the same network as a bot (?)
  3. Solve CAPTCHA
  4. "You're blocked"

I'm not using a VPN, just plan Orange FR FTTH.

Repro on:

  • Nightly Linux desktop (Android is fine for me) upto 2023-04-13 according to mozregression
  • Current stable (snap) still shows CAPTCHA but grants access, as well as under Chromium

Running mozregression got me this https://hg.mozilla.org/mozilla-central/pushloghtml?fromchange=a445f1762c895000bcdabd9d95697522359d41ed&tochange=5c9aa60ea6f47114a9367f56c50cd13299aa1d29

No enhanced tracking protection as much as I know, no uBlock enabled, repro in private window with tracking protection disabled, wondering how much it might be similar to bug 1840235, given it repros back in time and I clearly accessed the website a few days/weeks ago from the same IP and computer...

And the 403 occurs on the leroymerlin.fr server, reporting LMCDN

$ host www.leroymerlin.fr
www.leroymerlin.fr is an alias for j.sni.global.fastly.net.
j.sni.global.fastly.net has address 199.232.170.132

This morning it's working? Did they react to my support message request on the blocking page ?

This site is another site hosted by Fastly, and we've seen a bunch of those reports. Let's add a KB bug and try to reach out.

Severity: -- → S2
User Story: (updated)
Flags: needinfo?(dschubert)
Priority: -- → P1
Whiteboard: [webcompat:needs-knowledgebase]

Now happening on sncf-connect, which is going to be really really complicated ...

Summary: https://www.leroymerlin.fr/ CAPTCHA and then blocks → leroymerlin.fr / sncf-connect.com CAPTCHA and then blocks

They all seem to use geo.captcha-delivery.com service

Dennis, do you know if we have contacts at captcha-delivery?

That is Fastly. I'm trying to find a contact.

I alerted a friend at Fastly.

Depends on: 1894448
Whiteboard: [webcompat:needs-knowledgebase]

This issue was fixed upstream, so there's nothing left for us to do here. Closing.

Status: NEW → RESOLVED
Closed: 5 days ago
Flags: needinfo?(dschubert)
Resolution: --- → WORKSFORME
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: