haxball / haxball-issues

115 stars 43 forks source link

Cloudflare recaptcha error #871

Open resera opened 5 years ago

resera commented 5 years ago

I host room on server and use puppeteer to automatically launch it, but today it failed cause cloudflare asks puppeteer bot to solve recaptcha. Will this be fixed or what?

If this is something that happened by mistake and will be fixed then let me now. Otherwise I will need to take some actions to remake system without using puppeteer...

AnddyAnddy commented 5 years ago

That's a brillant update, probably the best that could happen at this time What are the reason for this all of tje sudden ?

resera commented 5 years ago

I mean, why then headless hosts are for? to run without human interaction (my guess). Thats why we could use tokens and do not solve recaptcha by hand.

My guess is that cloudflare was installed globally on haxball.com to prevent bots in a game, but not to prevent headless host owners to use bots to launch their rooms. So it is just a mistake that will be fixed soon?

saviola777 commented 5 years ago

I don't think that Basro changed anything, it's just a cloudflare thing related to the recent DDoS attacks on haxball.com

Should be gone in a couple of days at most.

Edit: maybe I'm wrong, I didn't see the "checking your browser" thing on the headless site before I believe?

AnddyAnddy commented 5 years ago

Oh my question was to basro, sorry for the misunderstanding

resera commented 5 years ago

I don't think that Basro changed anything, it's just a cloudflare thing related to the recent DDoS attacks on haxball.com

Should be gone in a couple of days at most.

Im not familiar with cloudflare, but is there any way to exclude routes? For example do not check browser when u try to access haxball.com/headless ?

saviola777 commented 5 years ago

I don't think that Basro changed anything, it's just a cloudflare thing related to the recent DDoS attacks on haxball.com Should be gone in a couple of days at most.

Im not familiar with cloudflare, but is there any way to exclude routes? For example do not check browser when u try to access haxball.com/headless ?

Might be possible, but it would defeat the purpose of having cloudflare, because attackers would then target those routes.

resera commented 5 years ago

I thought that purpose of this attack is not to take down entire site but target specific rooms. So whitelisting /headless route wont do any damage. But lets wait for basro

Wazarr94 commented 5 years ago

Yesterday in the evening (CEST) the haxball website was ddosed, it could explain the protection. It was a short DDOS so no one here noticed I guess

basro commented 5 years ago

A DDoS attack was targeted at HaxBall servers, Cloudflare security measures were increased because of that. They are lowered now but may go up again if another attack happens.

ghost commented 5 years ago

@basro I don't know what are you doing but stop using this cloudflare thing. Everytime you open this thing or set it to higher security the game becomes unplayable because of lag/shaking. So stop using this.

saviola777 commented 5 years ago

Here you can read what cloudflare is all about. It is not responsible for lag/shaking and stopping to use it is a bad idea.