webcompat / web-bugs

A place to report bugs on websites.
https://webcompat.com
Mozilla Public License 2.0
743 stars 66 forks source link

secure.runescape.com - see bug description #67217

Closed webcompat-bot closed 3 years ago

webcompat-bot commented 3 years ago

URL: https://secure.runescape.com/m=account-creation/create_account?theme=oldschool

Browser / Version: Firefox 85.0 Operating System: Windows 10 Tested Another Browser: Yes Chrome

Problem type: Something else Description: Site returns error "Error 15 - This request was blocked by the security rules" on Firefox despite not reporting this error on Chrome Steps to Reproduce: This is the page linked to from the Old School Runescape home page for creating a new account. When loading on Firefox, the page displays the following text (listed IP addresses redacted):

Access Denied Error 15 secure.runescape.com 2021-02-16 22:15:13 UTC

What happened? This request was blocked by the security rules Your IP: [redacted] Proxy IP: [redacted] Incident ID: 1001000300018715443-16446898720802689

When loading on Chrome, the site correctly displays the signup form.

View the screenshot Screenshot
Browser Configuration
  • None

From webcompat.com with ❤️

softvision-raul-bucata commented 3 years ago

We appreciate your report. I was not able to reproduce the issue. The page loads as expected.

Screenshot_12

Tested with: Browser / Version: Firefox Nightly 210216 (🦎87.0a1-20210215093120🦎) Operating System: OnePlus 6 (Android 10) - 2280 ×1080 pixels, 19:9 ratio (~402 ppi density)

Suggestion: Try clearing cache/data/cookies, disable Ad-blocker (if available), or use a clean profile, and check again?

kuhnertdm commented 3 years ago

Hi, I'm the one who created this issue (didn't want to bother with linking my Github until now). The listed OS is Windows 10, not Android - are you able to reproduce with the same OS?

softvision-raul-bucata commented 3 years ago

@kuhnertdm We appreciate your report. I was not able to reproduce the issue on Android as well. I have tried with 2 android devices, and the issue could not be reproduced.

Screenshot_13

Tested with: Browser / Version: Firefox Nightly 210217 (🦎87.0a1-20210217094559🦎) Operating System: Huawei P10 (Android 9) - 1920x1080 pixels, 18.5:9 ratio (~432 ppi density) Operating System: OnePlus 6 (Android 10) - 2280 ×1080 pixels, 19:9 ratio (~402 ppi density)

Could you please provide some error logs? Also, could you access the developer tools menu and see if there are any error messages in the console?

karlcow commented 3 years ago

@softvision-raul-bucata did you test on windows? 😁

karlcow commented 3 years ago

on MacOS On accessing https://secure.runescape.com/m=account-creation/create_account?theme=oldschool

I get

Capture d’écran 2021-02-24 à 10 11 45

Then let's do the "I'm not a robot" 🤖

Then

Capture d’écran 2021-02-24 à 10 12 51

And I can indeed create an account https://secure.runescape.com/m=account-creation/create_account?theme=oldschool

Capture d’écran 2021-02-24 à 10 14 57

@kuhnertdm

  1. Do you use a VPN or go through a proxy?
  2. Is the error message after you created the account or just the access to the creation page
  3. Could you try with "Restart with Add-ons disabled"?
kuhnertdm commented 3 years ago

@karlcow Ignoring the fact that this is also not Windows:

  1. No and no
  2. The latter - Sometimes the Captcha page appears and I click through to find the error message, and other times it does not show the Captcha page, and just displays the error message
  3. Upon trying again today, I'm able to get to the signup page without doing anything different, so this looks to be an inconsistent issue even under the exact same environment (Firefox/Win10). Not sure exactly where to go from here.
liamengland1 commented 3 years ago

Well, it's a server side block, not exactly something Firefox devs can fix themselves. Do you use any extensions that might affect your cookies?

kuhnertdm commented 3 years ago

@llacb47 As of today I've seen the page both succeed at times and show the error at other times, with the following addon list:

So nothing that immediately jumps out to me as potentially affecting arbitrary cookies on sites other than ones that they specifically target (e.g. TweetDeck, Twitch, Reddit)

karlcow commented 3 years ago

uBlock Origin is likely a culprit. It is expected that sites will break. I'm using uBlock myself with strict settings but I accept the consequences ;)

Could you try without addons at all please. as per my initial comment.

liamengland1 commented 3 years ago

I think I know why your access to the site has been blocked. You added* a uBo list/filter that is blocking a script used by the Imperva Web Application Firewall. Therefore, the necessary cookies don't get set and the site denies you access.

*I say you added because I could not reproduce any blocking of imperva fingerprinting scripts on default settings.

Blocking any of the things below will probably impair your access to the site: image

Links to scripts for reference:

https://secure.runescape.com/_Incapsula_Resource?SWJIYLWA=719d34d31c8e3a6e6fffd425f7e032f3
https://secure.runescape.com/Criciousand-meth-shake-Exit-be-till-in-ches-Shad