Ekultek / WhatWaf

Detect and bypass web application firewalls and protection systems
Other
2.55k stars 434 forks source link

Unknown Firewall (f002b7712) #1549

Closed WhatWaf-Firewalls closed 1 year ago

WhatWaf-Firewalls commented 2 years ago

WhatWaf version: 2.0.3 Running context: whatwaf -W --ra --tor -u ************************** Fingerprint:

<!--
GET http://www.london.gov.uk HTTP/1.1
Status code: 403
Date: Sat, 04 Jun 2022 13:27:10 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-Chl-Bypass: 1
Permissions-Policy: accelerometer=(),autoplay=(),camera=(),clipboard-read=(),clipboard-write=(),fullscreen=(),geolocation=(),gyroscope=(),hid=(),interest-cohort=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=()
Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Thu, 01 Jan 1970 00:00:01 GMT
X-Frame-Options: SAMEORIGIN
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Vary: Accept-Encoding
Server: cloudflare
CF-RAY: 716101223cde7260-HAM
Content-Encoding: gzip
-->
<!DOCTYPE html>

<!--[if lt IE 7]> <html class="no-js ie6 oldie" lang="en-US"> <![endif]-->
<!--[if IE 7]>    <html class="no-js ie7 oldie" lang="en-US"> <![endif]-->
<!--[if IE 8]>    <html class="no-js ie8 oldie" lang="en-US"> <![endif]-->
<!--[if gt IE 8]><!--> <html class="no-js" lang="en-US"> <!--<![endif]-->
<head>
<title>Please Wait... | Cloudflare</title>
<meta charset="utf-8"/>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type"/>
<meta content="IE=Edge" http-equiv="X-UA-Compatible"/>
<meta content="noindex, nofollow" name="robots"/>
<meta content="width=device-width,initial-scale=1" name="viewport"/>
<link href="/cdn-cgi/styles/cf.errors.css" id="cf_styles-css" rel="stylesheet"/>
<!--[if lt IE 9]><link rel="stylesheet" id='cf_styles-ie-css' href="/cdn-cgi/styles/cf.errors.ie.css" /><![endif]-->
<style>body{margin:0;padding:0}</style>
<!--[if gte IE 10]><!-->
<script>
  if (!navigator.cookieEnabled) {
    window.addEventListener('DOMContentLoaded', function () {
      var cookieEl = document.getElementById('cookie-alert');
      cookieEl.style.display = 'block';
    })
  }
</script>
<!--<![endif]-->
<script>
    //<![CDATA[
    (function(){
      window._cf_chl_opt={
        cvId: "2",
        cType: "managed",
        cNounce: "94915",
        cRay: "716101223cde7260",
        cHash: "87f721a702db6c6",
        cUPMDTk: "\/%3Cframeset%3E%3Cframe%20src=%5C%22javascript:alert('XSS');%5C%22%3E%3C\/frameset%3E?__cf_chl_tk=b_yODUYiazsR2.TAAMV3_Z0tRBE.5sQvQ9lRB3noS7U-1654349230-0-gaNycGzNB2U",
        cFPWv: "g",
        cTTimeMs: "1000",
        cLt: "n",
        cRq: {
          ru: "aHR0cHM6Ly93d3cubG9uZG9uLmdvdi51ay8lM0NmcmFtZXNldCUzRSUzQ2ZyYW1lJTIwc3JjPSU1QyUyMmphdmFzY3JpcHQ6YWxlcnQoJ1hTUycpOyU1QyUyMiUzRSUzQy9mcmFtZXNldCUzRQ==",
          ra: "TW96aWxsYS80LjAgKGNvbXBhdGlibGU7IE1TSUUgNS4wMTsgV2luZG93cyBOVCA1LjA7IFEzMTI0NjEp",
          rm: "R0VU",
          d: "uZ7s7QlGjMNt8ePM96/S0FA7jLNXWkiPJKHGLQ5VKkhdeQodeMnpRZNDW5eiC09H9pkJ8s0K/U4aP2MPpPNQxWjxl6QGbdw0H/NopUJi/JkhrDWrIEP58hNUmwGfR6ke5S4mFxHgWLONfbt7KT04lv+lwCF0dP0Ol0ZMVlpDUZJXkqoFcv/LWWVNjU6S22GMBgGPcPPrKIDS3GjUbToQ6Kl8l0KYhmzfRl7/vNkL8BRnjRpLXJAvZN/UFl3qoiUz6LrRVKGqyDKlxuGxk7tu1D6JiyLMsqhT1zyU2fek6oxUGpneVW+4g93qD61WbpVEjqbVML7OV4jf6U39UhMBnF6WNTDYUSp0ROsRf0m2J+XosjlhlXNy44BWc2weH7F281tl0m1jwXTYL4ZOmBO4ukmkEoFGCTxJd6YxS7Ua04zCCTNdIEEKAcahdB3r+uEKcbMwUB6QApCuKMiUh3GoNrpZIXOzpbRnGkYL1L46KpoFNI9g/8nzVCytw7sl/EIxdGIpLIoj3SJqkeauGP4+oKlclPwshPHHdN47mpPHQ6gNlpJGT+xeZ5c6qEyPbf+cfGGrwtNq7gZu3y8PoEBZRK1GG3OJ78OwlnhXAOzExvo=",
          t: "MTY1NDM0OTIzMC40NDcwMDA=",
          m: "xeG8Fs9svAPNwyc8L18ADzlgat0eBDSF8pXArokNnwA=",
          i1: "kEY2XDuZOSRbbN3/8FmeEw==",
          i2: "NuEWjgTI7yND55lCsw1VcA==",
          zh: "66FtGgcC+pjnmenKCsqQB4WUOiK792ls3dysRyb4g8I=",
          uh: "NL6sTyNQfmIyXHK083o8pl/zhIJhHc1BgNo2JGhtZ3w=",
          hh: "WD95vA53M9g+3HWl2EukVR+abCKG7lfySSsjv90wlro=",
        }
      };
    }());
    //]]>
    </script>
<style>
  #cf-wrapper #spinner {width:69px; margin:  auto;}
  #cf-wrapper #cf-please-wait{text-align:center}
  .attribution {margin-top: 32px;}
  .bubbles { background-color: #f58220; width:20px; height: 20px; margin:2px; border-radius:100%; display:inline-block; }
  #cf-wrapper #challenge-form { padding-top:25px; padding-bottom:25px; }
  #cf-hcaptcha-container { text-align:center;}
  #cf-hcaptcha-container iframe { display: inline-block;}
  @keyframes fader     { 0% {opacity: 0.2;} 50% {opacity: 1.0;} 100% {opacity: 0.2;} }
  #cf-wrapper #cf-bubbles { width:69px; }
  @-webkit-keyframes fader { 0% {opacity: 0.2;} 50% {opacity: 1.0;} 100% {opacity: 0.2;} }
  #cf-bubbles > .bubbles { animation: fader 1.6s infinite;}
  #cf-bubbles > .bubbles:nth-child(2) { animation-delay: .2s;}
  #cf-bubbles > .bubbles:nth-child(3) { animation-delay: .4s;}
</style>
</head>
<body>
<div id="cf-wrapper">
<div class="cf-alert cf-alert-error cf-cookie-error" data-translate="enable_cookies" id="cookie-alert">Please enable cookies.</div>
<div class="cf-error-details-wrapper" id="cf-error-details">
<div class="cf-wrapper cf-header cf-error-overview">
<h1 data-translate="managed_challenge_headline">Please wait...</h1>
<h2 class="cf-subheadline"><span data-translate="managed_checking_msg">We are checking your browser...</span> www.london.gov.uk</h2>
</div>
<div class="cf-section cf-highlight cf-captcha-container">
<div class="cf-wrapper">
<div class="cf-columns two">
<div class="cf-column">
<div class="cf-highlight-inverse cf-form-stacked">
<form action="/%3Cframeset%3E%3Cframe%20src=%5C%22javascript:alert('XSS');%5C%22%3E%3C/frameset%3E?__cf_chl_f_tk=b_yODUYiazsR2.TAAMV3_Z0tRBE.5sQvQ9lRB3noS7U-1654349230-0-gaNycGzNB2U" class="challenge-form managed-form" enctype="application/x-www-form-urlencoded" id="challenge-form" method="POST">
<div id="cf-please-wait">
<div id="spinner">
<div id="cf-bubbles">
<div class="bubbles"></div>
<div class="bubbles"></div>
<div class="bubbles"></div>
</div>
</div>
<p data-translate="please_wait" id="cf-spinner-please-wait">Please stand by, while we are checking your browser...</p>
<p data-translate="redirecting" id="cf-spinner-redirecting" style="display:none">Redirecting...</p>
</div>
<input name="md" type="hidden" value="FkqS0C0dUsI2AT0743Q_E4buVdECIsbpxTbdHbRJ.a4-1654349230-0-Ad8LbEA2daS2QflRBeFgZm-lQWIzS3Peem9B5OiYR-9Ix9xitRpup-5d8fcsqk-EMvNzGwT-2tuxw7wvpAyIfAoWkCaOppdm0_fpdaVGTIUcWFqDBDU8epjUlq-2IsQF_uo3mfBTfVWce6POcJ8AzOgDY8VLgHTX9pTrwnLcp2im4JKiLByGL9-4ybg6uYJqg65t0FIEyViJI1txiotli6cO1-yepz8crHndosTGezSzKfTR4AzivwhAMyB9SdmHVZyVF4ryd8NGns4UPjjjCbLoQKTvNw6qD70gvq3SACP4_w9ht5BUrO68UbXhoIMAxcKyvNGlpMohOoVUCcv0nQYNE3C3B-gS5u8MPHxxG6ZeZ0Znxkr_Ef_U8Q9lIsc7TDDVNFfAKLUymO0UKh4vqUEFRigbY5yL5mULTj7FTFA60wQgGEOdnUml6JDNxDhX8VIWOPOixdo_erQSEqd3aXRX208_dot_NwC6zeuz7lRlTx3QGJK2Arj7lMXAQDzUs-pDbSIgQEn04fmgRnPiiHLtvm4qeycGbhRT-NqAaw8UTytql37G5q8F5JT1TxdF1k7ne7TlHpg_SHKM030GovxElDAduutDkSuFBwWj5YyYsr7SI7cw4szIPSVRM0k8sK842Mj2_iK2Pi9OwAiiPmh7OzNGZS1I332g95Uu_Y6XNtHanASSq1f-txtE3iAyqzXPHkP4_OwRR_Oi3gjVADsfU-J9HdbVNCOldpjxaqVtxaLqSzK8C7fdgX2iEhh9oPfsmVcuhd3agWZCYrOoLyxOU6khchL8fb2S1c1d_qtB-7i3R31LG3hooAUhcOHy9BA_4CEUNwRIifZiRUV3gQO3XM6vZ7cZgZE8-tIosejq29F28UOnW0VBmsqF20G_z9FVaEVyd_Ceu_ErhAg-6e1jZl6nucGWr1RS6aFvm6FAU6O4ebQoymH9TGqr3mNO_5iDUDz_24QD9RigvC3JSSswmJwKUTsnBbvXF36p8-JC"/>
<input name="r" type="hidden" value="OzimA.G.QIM6HULyZF.8chGQrNyPf0qADY_zWv5CtQA-1654349230-0-Aap5uTYuYbcbuEjpQ16i/XnguxnH2AWMsW+VLzzQ7rwnKRFZQTXn3og5wbhXzvU9h5xX4+qd4XqAbkPQkEgpGjrBhogIq89u7SqQhjyd7/AINCrGD4onGastpspvT2M7i7R1Kq10BTJ/Cmem45QnZrhykjCiNlVsgeJ1nC/sFp6cCl5jW50dLGlq/dtmI9nROwtnpYyXM+bCnGZOPRRoygeC1EMa3bOCC+TXatk9y8nGbaXZLl55Y1zaxgAyuSx9Ky9BwlvA6dqzds6k2lJTtosDeMqaSK6xyz4pFwXA4yoylICJK2093OsKE4C7tuAUQf1C0gIghEtTvANFTjlsBET5mY5+A9zIyC2RoBXyp9SChiZxXv3Y1LzyVcgXuoH/Y0KmZ7KcJzXc+76IgEjwIXvG3ytnr3gPt7j4p1n6b4GWAk4ywk/RuU5prHQg6TFwVYT7a9xx8HK95DwnzUXkZmZj2cq3GmsB3zj/f8CTqq0K/tnQZRqSUsbbN0Oxm0JEu6YQ/o5isvJbZHBc1ml6IyaNc83U1V/WtPQ6MDuDu8AN++T3lsNzkbfYxJ/obbFhOpJn1E1p010gIfMv9XACIWW86SPQ6RmLbps4urYFxbfzLaZj7BFS2jJdJb14gtDdHhMvAElv/WjLRLMR5B9jOtlxgkcxdv5e4D+FJqd7xYzwKYC0S59R78bFdsWEK/mwHG5hVYdJpJXF7Gvk15Mg8lWMgLip2PwrNw6SO38lcCbZriblUEuO0w4KmiX8HehU5q+1cz0ushx8KA5xGUNPe4zTb0qAThwFr9brBcd3u8OMXEtvfq9VPPk478wfBU4X6q6/wbbgpFiXY5zqlKDTBmXro+CcueJp1VCinMUmblzbbFSCKL+sziBzIKG+14iVJqIxhdlFU8KF31bsF4IThJFue0qMWnbBQqXVY3SCTjAFP3zbtlEnMAD+MatfpY5owsT7xJ9IUEC0Bax+1FtapcQadLk+aGFnRsJz/lSqmk3PFF5akU1CLTi/VeMJqHAsJ0bJ2vqe2OVY3vvo/06Iq2fSslFpPZufZVJGcXj911JTsEvyicecYfKPzWqgi66iTDpETp1ohJD8L3t/k6dtfyEhczgHvKNz7RR84A90tOrJ6yDbAyLxbVk5BGz1AAOcVm/BejBsQHKLywTSi25MGkzTPt1S6sPgLxMk1m0HBTPZFU4F9hmjGYN+bmTcyCK2V1GjHIPuNxFOIzpSNKqkDpCEWQ1C8RLCKNvJB3squQjzA00YiWsr10b1edr6G18UX989ZUoywcco/QmrtJCpWTQK43dn0SGIwFdsOUperik9h3n6O6AVgajIuusryIocD4jxvV6e5waE+TxXeEGHuI5DR2qZSgG6pWRhoSOP4c7kDseb7YhemGReL38rJFvbpG79l8MDEUorCRnVJ+mnJhu7UsvYv5pbUk6RvbK/+lJGDKwC6VoZ96vzzh6mEdTNHFoWRCaTwrBu16OR23U92jAASKDNXWKM8JaxdYheD1W/waptJGO8dyE8Ya2ORoFauzEW0s8K1jEzTVx6v3IN5Ugrt1P9EuLxs+9hdIKvqD2OEIM+5n9mm3YCLju4gY8m0WX2YJuec7jCELQBa/ZKwFPq5/zvaD/OvwYW98E7kaibEr38b2iT5s3bdWNLqj1NpOZmsYhAc8SawQuzD6qkU1rKJw5AAxiSm5AaWlxHIKASRoGAkCD9d/EAwgzE1nuo0j2/kzCBR65Z3XNwHnFVcYGeiW8ZmVlsqoY5Na8HukDNwJd+ITtPVaWTEiK1EIFGezB8aOQq0c1vQi3LBrpRDgUUNTQs3/sb4WcePTRzd9dm"/>
<input name="vc" type="hidden" value="b7972cd056efb6c3478f6472ce6beb0f"/>
<noscript class="cf-captcha-info" id="cf-captcha-bookmark">
<h1 data-translate="turn_on_js" style="color:#bd2426;">Please turn JavaScript on and reload the page.</h1>
</noscript>
<div class="cookie-warning" data-translate="turn_on_cookies" id="no-cookie-warning" style="display:none">
<p data-translate="turn_on_cookies" style="color:#bd2426;">Please enable Cookies and reload the page.</p>
</div>
<script>
  //<![CDATA[
    var a = function() {try{return !!window.addEventListener} catch(e) {return !1} },
      b = function(b, c) {a() ? document.addEventListener("DOMContentLoaded", b, c) : document.attachEvent("onreadystatechange", b)};
      b(function(){
        var cookiesEnabled=(navigator.cookieEnabled)? true : false;
        if(!cookiesEnabled){
          var q = document.getElementById('no-cookie-warning');q.style.display = 'block';
        }
      });
  //]]>
  </script>
<div id="trk_captcha_js" style="background-image:url('/cdn-cgi/images/trace/captcha/nojs/h/transparent.gif?ray=716101223cde7260')"></div>
</form>
<script>
    //<![CDATA[
    (function(){
        var isIE = /(MSIE|Trident\/|Edge\/)/i.test(window.navigator.userAgent);
        var trkjs = isIE ? new Image() : document.createElement('img');
        trkjs.setAttribute("src", "/cdn-cgi/images/trace/managed/js/transparent.gif?ray=716101223cde7260");
        trkjs.id = "trk_managed_js";
        trkjs.setAttribute("alt", "");
        document.body.appendChild(trkjs);
        var cpo=document.createElement('script');
        cpo.type='text/javascript';
        cpo.src="/cdn-cgi/challenge-platform/h/g/orchestrate/managed/v1?ray=716101223cde7260";

        window._cf_chl_opt.cOgUHash = location.hash === '' && location.href.indexOf('#') !== -1 ? '#' : location.hash;
        window._cf_chl_opt.cOgUQuery = location.search === '' && location.href.slice(0, -window._cf_chl_opt.cOgUHash.length).indexOf('?') !== -1 ? '?' : location.search;
        if (window._cf_chl_opt.cUPMDTk && window.history && window.history.replaceState) {
          var ogU = location.pathname + window._cf_chl_opt.cOgUQuery + window._cf_chl_opt.cOgUHash;
          history.replaceState(null, null, "\/%3Cframeset%3E%3Cframe%20src=%5C%22javascript:alert('XSS');%5C%22%3E%3C\/frameset%3E?__cf_chl_rt_tk=b_yODUYiazsR2.TAAMV3_Z0tRBE.5sQvQ9lRB3noS7U-1654349230-0-gaNycGzNB2U" + window._cf_chl_opt.cOgUHash);
          cpo.onload = function() {
            history.replaceState(null, null, ogU);
          };
        }

        document.getElementsByTagName('head')[0].appendChild(cpo);
    }());
    //]]>
    </script>
</div>
</div>
<div class="cf-column">
<div class="cf-screenshot-container">
<span class="cf-no-screenshot"></span>
</div>
</div>
</div>
</div>
</div>
<div class="cf-section cf-wrapper">
<div class="cf-columns two">
<div class="cf-column">
<h2 data-translate="why_captcha_headline">Why do I have to complete a CAPTCHA?</h2>
<p data-translate="why_captcha_detail">Completing the CAPTCHA proves you are a human and gives you temporary access to the web property.</p>
</div>
<div class="cf-column">
<h2 data-translate="resolve_captcha_headline">What can I do to prevent this in the future?</h2>
<p data-translate="resolve_captcha_antivirus">If you are on a personal connection, like at home, you can run an anti-virus scan on your device to make sure it is not infected with malware.</p>
<p data-translate="resolve_captcha_network">If you are at an office or shared network, you can ask the network administrator to run a scan across the network looking for misconfigured or infected devices.</p>
</div>
</div>
</div>
<div class="cf-error-footer cf-wrapper w-240 lg:w-full py-10 sm:py-4 sm:px-8 mx-auto text-center sm:text-left border-solid border-0 border-t border-gray-300">
<p class="text-13">
<span class="cf-footer-item sm:block sm:mb-1">Cloudflare Ray ID: <strong class="font-semibold">716101223cde7260</strong></span>
<span class="cf-footer-separator sm:hidden">•</span>
<span class="cf-footer-item sm:block sm:mb-1"><span>Your IP</span>: 2a0b:f4c1:2::254</span>
<span class="cf-footer-separator sm:hidden">•</span>
<span class="cf-footer-item sm:block sm:mb-1"><span>Performance &amp; security by</span> <a href="https://www.cloudflare.com/5xx-error-landing" id="brand_link" rel="noopener noreferrer" target="_blank">Cloudflare</a></span>
</p>
</div><!-- /.error-footer -->
</div>
</div>
<script>
  window._cf_translation = {};

</script>
</body>
</html>