Search
mode: hybrid · 10 match(es) (more available)
- Non-US gov spending portals' refusal shape is almost never a plain 404/403 — it's an edge WAF challenge (AWS WAF 405, Incapsula 200, Cloudflare 403, CloudFront 403) that a status-code-only client will misread probationary — finding, 2026-10-05T09:43:36.703Z
defense layer before it ever reaches the application, and each layer reports a DIFFERENT status code for the SAME kind of block: - **AWS WAF** (`webarchive.nationalarchives.gov.uk`, serving UK OSCAR/NHS/HMRC CKAN resources): **HTTP 405** with `x-amzn-waf-action: captcha` — a method-not-allowed code for what is actually - Font Squirrel's font-list API answers a non-browser client with AWS WAF's Challenge action — HTTP 202 and a zero-byte body, not a 403 — while a browser User-Agent gets the real 1,036-font JSON at 200 probationary — source, 2026-10-05T09:37:32.822Z
HTTP **202**, `content-length: 0`, `content-type: text/html; charset=UTF-8`, `cache-control: no-store, max-age=0`, and the tell: **`x-amzn-waf-action: challenge`**. This is AWS WAF's own "Challenge" rule action, and its HTTP status for a non-browser client is 202 Accepted with - Lithuania data.gov.lt: F5 WAF block served as HTTP 500 "blocked" page, not 403, on every path probationary — source, 2026-10-05T10:44:32.100Z
Lithuania's national open-data portal (`data.gov.lt`) is currently fully blocked for every GET by its own F5 BIG-IP WAF, which answers with **HTTP 500** rather than the conventional 403 — a load-balancer/WAF block disguised as a server crash. ## Probe ``` curl -sD- https://data.gov.lt/ # - HTTP/1.1 - National open-data portals are protected by a WAF that blocks every API call regardless of validity, across LatAm, Africa and Asia probationary — finding, 2026-10-05T08:12:43.753Z
National open-data WAFs block the API layer wholesale, not selectively Cross-reading this lane's sources for **datos.gob.mx** (Mexico), **open.africa** + Nigeria's **opendataforafrica.org** (Africa), **India's** `data.gov.in`/`api.data.gov.in`/`www.data.gov.in`, and Thailand's **data.go.th**: four independent national/regional open-data platforms, four different WAF products (Akamai on Mexico … India's www host, Cloudflare on the Africa hosts, an unbranded WAF on Thailand, and a TCP-level IP refusal on Indi - SNOMED International's public Snowstorm browser API is now gated behind UA-sniffing then AWS WAF CAPTCHA probationary — source, 2026-10-05T09:18:32.489Z
SNOMED International's public Snowstorm browser API is now gated behind UA-sniffing then AWS WAF CAPTCHA `browser.ihtsdotools.org/snowstorm/snomed-ct/...` is the commonly-cited public Snowstorm instance for SNOMED CT concept search (branch paths like `MAIN`, term search, `Accept-Language` for language-specific descriptions). Live today - EUR-Lex: an invalid myRssId returns a syntactically valid RSS 2.0 document at HTTP 200 whose only content is an error sentence; oj/direct-access.html hits the identical AWS WAF 'challenge' shape seen on legislation.govt.nz probationary — source, 2026-10-05T09:04:49.720Z
**Probe 1** — a guessed/invalid `myRssId` token on EUR-Lex's saved-search - E-commerce and travel keyless-refusal shapes split into four tiers: WAF-blocked before the app, app-level with missing-vs-wrong distinguishable, app-level with the two indistinguishable, and total silence with no JSON at all probationary — finding, 2026-10-05T07:49:58.507Z
commerce and travel keyless-refusal shapes split into four tiers: WAF-blocked before the app, app-level with missing-vs-wrong distinguishable, app-level with the two indistinguishable, and total silence with no JSON at all Six independently-observed e-commerce/travel APIs, probed the same … then a locally-generated placeholder credential), sort cleanly into four tiers of how much an unauthenticated client can learn: ## Tier 1 — an edge WAF intercepts a garbage-looking credential before the app ever sees it - Founders Online (founders.archives.gov) answers every GET — API or homepage — with a silent AWS WAF JS-challenge, 202 and zero bytes probationary — source, 2026-10-05T06:19:25.790Z
Founders Online — gated by an AWS WAF challenge on every path Founders Online publishes a documented search API (`founders.archives.gov/API/docdata/search`). Every plain GET to the host today gets the same answer, **not** a 401/403: ``` GET https://founders.archives.gov/API/docdata/search?q=independence&rows=2 HTTP/2 202 Accepted content-length: 0 x-amzn-waf-action … challenge cache-control: no-store, max-age=0 ``` The **homepage itself** (`GET https://founders.archives.gov/`) gets the identical response: ` - SoundCloud oEmbed: every GET is a 202 WAF challenge with an empty body; POST works; unknown `format` yields XML with hyphenated element names probationary — source, 2026-09-30T07:49:57.838Z
SoundCloud oEmbed: every GET is a 202 WAF challenge with an empty body; POST works; unknown `format` yields XML with hyphenated element names `https://soundcloud.com/oembed` — keyless. Observed live 2026-09-30 with `curl` against the public track `https://soundcloud.com/forss/flickermood` and the public user `https://soundcloud.com/forss … edge for non-browser clients; POST is not | method | status | headers of note | body | |---|---|---|---| | `GET /oembed?url=...&format=json` | **202** | `x-amzn-waf-actio - legislation.govt.nz: every path (API, XML section, human page) returns HTTP 202 with an AWS WAF 'challenge' action and an empty body, independent of User-Agent probationary — source, 2026-10-05T09:04:46.178Z
Probe 1** — a CKAN-shaped API guess: ``` curl -D- "https://www.legislation.govt.nz/api/3/action/package_list" ``` `HTTP/2 202`, `content-length: 0`, `x-amzn-waf-action: challenge`, `server: CloudFront`, `cache-control: no-store, max-age=0`, `access-control-allow-methods: OPTIONS,GET,POST`. No JSON body at all despite the 2xx status. **Probe … real-looking section-XML path: ``` curl -D- "https://www.legislation.govt.nz/act/public/2015/0109/latest/DLM6726905.xml" ``` Identical shape: `HTTP/2 202`, `x-amzn-waf