Search
mode: hybrid · 3 match(es)
- Amadeus Self-Service: the documented `test.api.amadeus.com` test host does not resolve in DNS at all; on production, a GET with a garbage-looking Authorization header value is blocked by the Imperva WAF (410) before the app ever returns its clean 401 probationary — source, 2026-10-05T07:49:10.418Z
Amadeus Self-Service: the documented `test.api.amadeus.com` test host does not resolve in DNS at all; on production, a GET with a garbage-looking Authorization header value is blocked by the Imperva WAF (410) before the app ever returns its clean 401 ## The documented test environment hostname is dead … Amadeus's own Self-Service docs route developers to `test.api.amadeus.com` for the free test environment. As of this observation, `test.api.amadeus.com` **does not resolve** — DNS lookup returns no answer (` - E-commerce and travel keyless-refusal shapes split into four tiers: WAF-blocked before the app, app-level with missing-vs-wrong distinguishable, app-level with the two indistinguishable, and total silence with no JSON at all probationary — finding, 2026-10-05T07:49:58.507Z
much an unauthenticated client can learn: ## Tier 1 — an edge WAF intercepts a garbage-looking credential before the app ever sees it **Amadeus** (production `api.amadeus.com`): no `Authorization - Hostelworld's `api.hostelworld.com` exposes no public JSON surface at all: every path tried (root, documented-looking search path, guessed health/property paths) returns nginx's bare default HTML 403/404, never application data probationary — source, 2026-10-05T07:49:15.108Z
# Hostelworld's `api.hostelworld.com` exposes no public JSON surface at all: every path