Re: Fingerprinting lessons from 'curl-impersonate'
"Kevin Koster" <dillo-PpymaetoNy61Z/[email protected]> Thu, 02 Jan 2025 09:26:13 +1100
| Newsgroups | gmane.comp.web.dillo.devel |
|---|---|
| Organization | OmberTech |
| Message-ID | <173577039683.28.16851428718573749519@e3c451e65321> |
Rodrigo Arias wrote: > On Wed, Jan 01, 2025 at 04:16:58PM +0100, a1ex-J7K0XVabL0iELgA04lAiVw-XMD5yJDbdMReXY1tMh2IBg@public.gmane.org wrote: >> Here are a few example sites which seem to be doing something like that: >> >> https://www.spacecoastdaily.com > > This one seems to be loading for me. Also for me with Dillo 3.1.0 using mbed TLS 2.26.0. >> https://www.lowes.com/ > > Fails with: > > SSL_read() failed: SSL_ERROR_SYSCALL > Tls_close_by_key: Avoiding SSL shutdown for: https://www.lowes.com/ This URL loads for me. Log: Nav_open_url: new url='https://www.lowes.com/' Dns_server [0]: www.lowes.com is 23.54.30.24 23.54.30.14 Connecting to 23.54.30.24:443 www.lowes.com TLSv1.2, cipher TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256 >> https://elokata.santanderconsumer.pl > > Fails with: > > TLS ALERT on write: decode error > SSL_read() failed: error:0A000126:SSL routines::unexpected eof while reading > Tls_close_by_key: Avoiding SSL shutdown for: https://elokata.santanderconsumer.pl For me this redirects to: https://elokata.santanderconsumer.pl/Error/SecurityError?Reason=12573334125608309175 Log: Nav_open_url: new url='https://elokata.santanderconsumer.pl' Dns_server [0]: elokata.santanderconsumer.pl is 195.138.208.195 Connecting to 195.138.208.195:443 elokata.santanderconsumer.pl TLSv1.2, cipher TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384 Nav_open_url: new url='https://elokata.santanderconsumer.pl/Error/SecurityError?Reason=12573334125608309175' Connecting to 195.138.208.195:443 But that second URL never loads (no error logged). https://elokata.santanderconsumer.pl redirects to and sucessfully loads an error page in Firefox 128 with NoScript. > Thanks for the list, I will check later each one in case we are doing > something wrong. > >> And of course washingtonpost.com, which you are already aware of. I'm >> sure there are more. > > Yeah, the case of washingtonpost.com is truly appaling. They were just > banning right away anything that is not HTTP/2. When I complained with a > curl reproducer so they allow Dillo via HTTP/1.1, they also banned > curl... https://washingtonpost.com/ redirects to https://www.washingtonpost.com/ and loads fine for me. > Similar problem with ebay.com, due to Akamai (edgesuite). I also > reported it, but so far no reply (this time, no curl reproducer). https://ebay.com/ redirects to https://www.ebay.com/ and loads for me (I browse ebay.com.au in Dillo often). _______________________________________________ Dillo-dev mailing list -- dillo-dev-lx9mn2B4QYRWk0Htik3J/[email protected] To unsubscribe send an email to dillo-dev-leave-lx9mn2B4QYRWk0Htik3J/[email protected]