Ekultek / WhatWaf

Detect and bypass web application firewalls and protection systems
Other
2.63k stars 446 forks source link

Unknown Firewall (c951f5752) #635

Closed WhatWaf-Firewalls closed 4 years ago

WhatWaf-Firewalls commented 4 years ago

WhatWaf version: 1.9.3 Running context: ./whatwaf -u ******************** --tor --ra Fingerprint:

<!--
GET http://usa.visa.com HTTP/1.1
Status code: 403
Date: Wed, 04 Dec 2019 06:28:06 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-Chl-Bypass: 1
Set-Cookie: __cfduid=df38a1dcaabed89a74054cd19eeee20b01575440886; expires=Fri, 03-Jan-20 06:28:06 GMT; path=/; domain=.usa.visa.com; HttpOnly; Secure
Cache-Control: no-cache
X-Frame-Options: SAMEORIGIN
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Vary: Accept-Encoding
Server: cloudflare
CF-RAY: 53fbb7e678c4ecbf-DFW
Content-Encoding: gzip
-->
<!DOCTYPE html>

<!--[if lt IE 7]> <html class="no-js ie6 oldie" lang="en-US"> <![endif]-->
<!--[if IE 7]>    <html class="no-js ie7 oldie" lang="en-US"> <![endif]-->
<!--[if IE 8]>    <html class="no-js ie8 oldie" lang="en-US"> <![endif]-->
<!--[if gt IE 8]><!--> <html class="no-js" lang="en-US"> <!--<![endif]-->
<head>
<title>Attention Required! | Cloudflare</title>
<meta id="captcha-bypass" name="captcha-bypass"/>
<meta charset="utf-8"/>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type"/>
<meta content="IE=Edge,chrome=1" http-equiv="X-UA-Compatible"/>
<meta content="noindex, nofollow" name="robots"/>
<meta content="width=device-width,initial-scale=1,maximum-scale=1" name="viewport"/>
<link href="/cdn-cgi/styles/cf.errors.css" id="cf_styles-css" media="screen,projection" rel="stylesheet" type="text/css"/>
<!--[if lt IE 9]><link rel="stylesheet" id='cf_styles-ie-css' href="/cdn-cgi/styles/cf.errors.ie.css" type="text/css" media="screen,projection" /><![endif]-->
<style type="text/css">body{margin:0;padding:0}</style>
<!--[if gte IE 10]><!--><script src="/cdn-cgi/scripts/zepto.min.js" type="text/javascript"></script><!--<![endif]-->
<!--[if gte IE 10]><!--><script src="/cdn-cgi/scripts/cf.common.js" type="text/javascript"></script><!--<![endif]-->
</head>
<body>
<div id="cf-wrapper">
<div class="cf-alert cf-alert-error cf-cookie-error" data-translate="enable_cookies" id="cookie-alert">Please enable cookies.</div>
<div class="cf-error-details-wrapper" id="cf-error-details">
<div class="cf-wrapper cf-header cf-error-overview">
<h1 data-translate="challenge_headline">One more step</h1>
<h2 class="cf-subheadline"><span data-translate="complete_sec_check">Please complete the security check to access</span> usa.visa.com</h2>
</div><!-- /.header -->
<div class="cf-section cf-highlight cf-captcha-container">
<div class="cf-wrapper">
<div class="cf-columns two">
<div class="cf-column">
<div class="cf-highlight-inverse cf-form-stacked">
<form action="/%3Cframeset%3E%3Cframe%20src=%5C%22javascript:alert(&amp;?__cf_chl_captcha_tk__=60db33081c3a71b6d204e32324a321552073af1d-1575440886-0-AQshp0bM03pR6P1w-fDNgWfhqeiQXg5ZJkKAn9zOCLVTVi5acBPbhdHTppXpPC8vIs-UQQgJJM25NJIYHjqZZCZW0LcyTEB7n7CFUWlzXOO7vrA2bzkQ8sRV9iRKJySzkb5g-7uCzFAA3AQjHqegj-D-3PZOSPtRXoBxZ-a-Slj9ncIHhYd5dT0M8iD-Kqxe3aVaDOTcdqZlv7MGN1CCLvFwdsUnfqNTMdjh06jwHWafD9IgjRMeep8-e9ZKtlc21KMUeq_rCj0M-gZ_BpS_4X9A0DRtU3AVRvI-Qa7A8Eu-o3L9sK634WHsDC6klmGIoIigo9uLPFke6YYy-4TuKGx2YdSYVczwXkQ9rpGlxqFSCAQEc5syD_xEusyJ8kzEqymYAD17Um3EEpHwJ4Lgixwdd4wHQG1tVx6jINcc-iJWdJlW-nfN2b7Jxp86BeQv5Q#039;XSS');%5C%22%3E%3C/frameset%3E" class="challenge-form" enctype="application/x-www-form-urlencoded" id="challenge-form" method="POST">
<input name="r" type="hidden" value="10b908930f1f04ef1f04e3865ce72801b55abca1-1575440886-0-AW4PPhgrVFsnvCgQndxSMfNEI/jqHKPFAgfDmaWw4q7hS+IIPFtBlbMMjfwtndrBPvywvwMHAnlF+7O3T6T5BG5bprzp07sqVNG8Q0eJaOCOoAPkEx0yVJpLVssX5wgjNVkpYeEPlpD+Sx8Rwvrh5djqEz5pi2Rb3xgi53HvgkcSeHXa2ZxhPB9SFxEXYRj5tLIsHzJ0Kv6tMrczERE2nJ3lr2LMDBr6tYdhDgmDNcVD+gbXUE837iVlibX+ybaLlGPkCNF+muCkDm7NLIih/p9mtqr5M4MGczhh/7Z05UKNSGMNZJpHkvCzHrQzwdLj4ZRjeDDm/MaJvAMlV1a5fOg1DGk781k10BcgF9++0HIWNUanjuQPitSlcBnVfHcPQ/d/KyyMthnWz7xLT6Cdgru7RtYXgoPUqvEfdfnciSfIXyE4KAgPn26JGRTCB8YlyiRVFin83f3yA+dDS8fpKq5NAGrOSaUu2DhTsAQRHBqSA+GmAE2xg4A7ljGiNjeVKgxwAOxm2WNzv90jbX3W1GxkrYcdv23AKG7a6pG5Kwig5KrMK95/QbXbg1pqIfLOTuMDdbzXFMYlxM5cHLHXyBOtbM4ebrDEoELZQX7o8wqOnz+FkCevC6Vt6dNOAlbZnEsRUMPxGyknKy4MX+STAxdj7lp3DYLEGQJ7bonB44w3lpgSMV/IKUnz5/vmN6cWO8mwE7Ikdyo7OtISEj1e7mq1xxdjxO4mOuo5m6oqreQbDXUw60vSBBlfIBDR+aSIhvqzHvdVa8Z/d3yoV9BOP0GHveCoFytfonfJEB7MUGrQA27vSbutupSKvkWtahun/3HErtNdSXu9W6P8nIsGlfhHitOBGozwcZmpEOFqAqMQ/sACgiOraVtbvwBovehsPmIFs1FbkFre3lHHLadGRF/9KzcJRCN1z9C4wPKKZt3hQeh3GQ/iv2hTQv1kc+GIZtUqEOyeGSHS5xnHRFqxJ4v2Vw10g6MlvsRpF7gMkqujFjY6UbCdHZKlzKY1nCEUVd98qZSbW1zHFvwgfqvlKNw+AkF2KRgRbRmyTUH2xwEkpAMk7zbYNkLhmQxAa2F9X37pc/yuIcnwrMqTzFwEltIH3uNPsMr+d7AeWuuTD+rK3zJe08L92m5de7aRrxzE13YrXjxzRFT+EGugKrvPpYm+7yFX/bCXh+QM7i6lvBX732dCe4iUHsQ3LgdqFZCIfknKU3hzKefxqRfL7Lv9FAUDSd8PbD4xTJqmwaiOTbIOZvGKmpcsfdBd/b9QQNTFZwWFhR2qiakfmU3vq01dEIl1TysAnmMyJU/RuLdK9KQ/7rEkOEQYXtt/FSSbdHOlfQ=="/>
<script async="" data-ray="53fbb7e678c4ecbf" data-sitekey="6LfBixYUAAAAABhdHynFUIMA_sa4s-XsJvnjtgB0" data-type="normal" src="/cdn-cgi/scripts/cf.challenge.js" type="text/javascript"></script>
<div class="g-recaptcha"></div>
<noscript class="cf-captcha-info" id="cf-captcha-bookmark">
<div><div style="width: 302px">
<div>
<iframe frameborder="0" scrolling="no" src="https://www.google.com/recaptcha/api/fallback?k=6LfBixYUAAAAABhdHynFUIMA_sa4s-XsJvnjtgB0" style="width: 302px; height:422px; border-style: none;"></iframe>
</div>
<div style="width: 300px; border-style: none; bottom: 12px; left: 25px; margin: 0px; padding: 0px; right: 25px; background: #f9f9f9; border: 1px solid #c1c1c1; border-radius: 3px;">
<textarea class="g-recaptcha-response" id="g-recaptcha-response" name="g-recaptcha-response" style="width: 250px; height: 40px; border: 1px solid #c1c1c1; margin: 10px 25px; padding: 0px; resize: none;"></textarea>
<input type="submit" value="Submit"/>
</div>
</div></div>
</noscript>
</form>
</div>
</div>
<div class="cf-column">
<div class="cf-screenshot-container">
<span class="cf-no-screenshot"></span>
</div>
</div>
</div><!-- /.columns -->
</div>
</div><!-- /.captcha-container -->
<div class="cf-section cf-wrapper">
<div class="cf-columns two">
<div class="cf-column">
<h2 data-translate="why_captcha_headline">Why do I have to complete a CAPTCHA?</h2>
<p data-translate="why_captcha_detail">Completing the CAPTCHA proves you are a human and gives you temporary access to the web property.</p>
</div>
<div class="cf-column">
<h2 data-translate="resolve_captcha_headline">What can I do to prevent this in the future?</h2>
<p data-translate="resolve_captcha_antivirus">If you are on a personal connection, like at home, you can run an anti-virus scan on your device to make sure it is not infected with malware.</p>
<p data-translate="resolve_captcha_network">If you are at an office or shared network, you can ask the network administrator to run a scan across the network looking for misconfigured or infected devices.</p>
</div>
</div>
</div><!-- /.section -->
<div class="cf-error-footer cf-wrapper">
<p>
<span class="cf-footer-item">Cloudflare Ray ID: <strong>53fbb7e678c4ecbf</strong></span>
<span class="cf-footer-separator">•</span>
<span class="cf-footer-item"><span>Your IP</span>: 199.249.230.115</span>
<span class="cf-footer-separator">•</span>
<span class="cf-footer-item"><span>Performance &amp; security by</span> <a href="https://www.cloudflare.com/5xx-error-landing?utm_source=error_footer" id="brand_link" target="_blank">Cloudflare</a></span>
</p>
</div><!-- /.error-footer -->
</div><!-- /#cf-error-details -->
</div><!-- /#cf-wrapper -->
<script type="text/javascript">
  window._cf_translation = {};

</script>
</body>
</html>
Ekultek commented 4 years ago

dupe #633