we3fan Posted Saturday at 08:42 AM Posted Saturday at 08:42 AM @NotHereToPlayGames Yes, v122 has the #extension-mime-request-handling flag, I had the default "Always prompt for install", but changing it to "Download as regular file" still didn't help for Cloudflare. I remember some time ago when Cloudflare accepted v122, with "Always prompt for install" I was able to download another CRX, it prompted to install the extension initially but when I cancelled that it just downloaded the .crx file. Thanks guys. So we can't do anything for Cloudflare-protected sites, with slightly older browsers? And the only way is to use the LATEST browser? Cloudflare plays hard ball.
NotHereToPlayGames Posted Saturday at 09:44 AM Posted Saturday at 09:44 AM 54 minutes ago, we3fan said: So we can't do anything for Cloudflare-protected sites, with slightly older browsers? And the only way is to use the LATEST browser? No, we can't! I'm not saying to take my word for it, I would love for somebody to "trick" Cloudflare. But yeah, ALL SIGNS POINT TO *NO*, it can't be done! My city utilities (sewer and trash) is behind Cloudflare. Like CLOCKWORK, any browser older than a mere TWO MONTHS (just under, actually) can *NOT* be used to pay city utilities. So I've been "experimenting" for the last YEAR (at least). You can *NOT* spoof a UA, you can *NOT* fake Client Hints, you can *NOT* polyfill javascript. I've done a "million" things (exaggerating, but you get the idea). I'm not exactly a "stupid person" (how many people do you know that can FAKE CLIENT HINTS). I'm telling you, IT CAN'T BE DONE. I've been on dozens of sites that are smarter than me and they can't do it either. IT CAN'T BE DONE. The "technology" simply does not exist. Cloudflare is GREAT at what they do. I'm going to keep trying to "break" it. But so far, IT CAN'T BE DONE. 3
user57 Posted Saturday at 01:51 PM Posted Saturday at 01:51 PM 4 hours ago, NotHereToPlayGames said: No, we can't! I'm not saying to take my word for it, I would love for somebody to "trick" Cloudflare. But yeah, ALL SIGNS POINT TO *NO*, it can't be done! My city utilities (sewer and trash) is behind Cloudflare. Like CLOCKWORK, any browser older than a mere TWO MONTHS (just under, actually) can *NOT* be used to pay city utilities. So I've been "experimenting" for the last YEAR (at least). You can *NOT* spoof a UA, you can *NOT* fake Client Hints, you can *NOT* polyfill javascript. I've done a "million" things (exaggerating, but you get the idea). I'm not exactly a "stupid person" (how many people do you know that can FAKE CLIENT HINTS). I'm telling you, IT CAN'T BE DONE. I've been on dozens of sites that are smarter than me and they can't do it either. IT CAN'T BE DONE. The "technology" simply does not exist. Cloudflare is GREAT at what they do. I'm going to keep trying to "break" it. But so far, IT CAN'T BE DONE. wasnt there a user agent switcher ? j7n talked about it quite often - or why it cant be changed - it actually has to be somewhere in the code
NotHereToPlayGames Posted Saturday at 01:58 PM Posted Saturday at 01:58 PM 2 minutes ago, user57 said: wasnt there a user agent switcher ? Yes... and NO! You "can" change the User Agent, there are *TONS* of extensions that can do that, even just simple command line or Dev Tool Console methods. BUT if you don't ALSO change the CLIENT HINTS that GO WITH that User Agent, then you have DONE NOTHING except feed your own PLACEBO EFFECT. Change one *without the other* is something that even a GRADE SCHOOL "coder" can detect.
user57 Posted Saturday at 02:13 PM Posted Saturday at 02:13 PM (edited) 1 hour ago, NotHereToPlayGames said: Yes... and NO! You "can" change the User Agent, there are *TONS* of extensions that can do that, even just simple command line or Dev Tool Console methods. BUT if you don't ALSO change the CLIENT HINTS that GO WITH that User Agent, then you have DONE NOTHING except feed your own PLACEBO EFFECT. Change one *without the other* is something that even a GRADE SCHOOL "coder" can detect. we have to be more specific then https://www.useragents.me/ https://deviceatlas.com/blog/list-of-user-agent-strings these are suppose to be changed rightly not just one of them, what ones are missing? if the client-hints are missing why they are not changed either way? https://browserleaks.com/client-hints Edited Saturday at 03:17 PM by user57
NotHereToPlayGames Posted Saturday at 02:24 PM Posted Saturday at 02:24 PM (edited) You've missed the primary point. User Agent is *OLD SCHOOL*. You are better served learning NEW TRICKS and stop relying on the OLD tricks. Test your CLIENT HINTS and *STOP* focusing on User Agent. Go here: https://www.neutrinoapi.com/client-hints-analyzer/ Your old-school user agent is listed at the very top section. The next section (and this does not apply to any 'fox fork, just to any Chrome fork [ie, Supermium]) is your CLIENT HINTS. If BOTH SECTIONS do not AGREE with each other, the web site owner KNOWS THAT YOU ARE A LIAR !!! ie, "spoofing your OLD SCHOOL user agent" but not smart enough to spoof the CLIENT HINT that *goes hand in hand* with that user agent. Edited Saturday at 02:30 PM by NotHereToPlayGames
NotHereToPlayGames Posted Saturday at 03:26 PM Posted Saturday at 03:26 PM Here's an example, this CHEAP and USELESS "user agent switcher" does change the user agent. BUT... the Client Hints still tell SMART people (like CLOUDFLARE !!!) that this isn't Firefox 33, it is Chrome/Chromium 144. User Agents really are *USELESS* in this day and age. Doesn't mean to not "try" spoofing your user agent, BUT IT WILL NOT FOOL "SMART" COMPANIES (like Cloudflare).
user57 Posted Saturday at 04:44 PM Posted Saturday at 04:44 PM 1 hour ago, NotHereToPlayGames said: Here's an example, this CHEAP and USELESS "user agent switcher" does change the user agent. BUT... the Client Hints still tell SMART people (like CLOUDFLARE !!!) that this isn't Firefox 33, it is Chrome/Chromium 144. User Agents really are *USELESS* in this day and age. Doesn't mean to not "try" spoofing your user agent, BUT IT WILL NOT FOOL "SMART" COMPANIES (like Cloudflare). ok then just change these too, they are probaly some strings somewhere you have the source code you probaly can search its connections, my computer is not very fast chrome in v110 or something already took 2 weeks to compile - but with a compiler and compiled i could certainly change these, so i think you can do this too
feodor2 Posted Saturday at 05:47 PM Posted Saturday at 05:47 PM 7 hours ago, NotHereToPlayGames said: I've done a "million" things (exaggerating, but you get the idea). I'm not exactly a "stupid person" (how many people do you know that can FAKE CLIENT HINTS). May be you please tell private what did you find about, exactly what it wants. 7 hours ago, NotHereToPlayGames said: My city utilities (sewer and trash) is behind Cloudflare. Like CLOCKWORK, any browser older than a mere TWO MONTHS (just under, actually) can *NOT* be used to pay city utilities. Also I just wanted to tell that sites I check with the thing still works on the firefox 115.
Dave-H Posted Saturday at 07:17 PM Posted Saturday at 07:17 PM This is getting off-topic. It's not a uniquely Supermium issue, and the latest 144 version does not show the problem, at least not for me. Please start a new thread about spoofing client hints if you want to keep up this conversation.
NotHereToPlayGames Posted Saturday at 07:23 PM Posted Saturday at 07:23 PM (edited) You have OVERPLAYED that card! And I say that with respect! The issue was Supermium not passing Cloudflare (edit: not the crx topic, but the Cloudflare topic!) and all of that discussion that rolled out was ON-TOPIC. PERIOD. Edited Saturday at 07:25 PM by NotHereToPlayGames
Dave-H Posted Saturday at 10:03 PM Posted Saturday at 10:03 PM OK, but I'm at a loss to understand why anyone would want to potentially go to a lot of trouble, if it's even possible, to work around this when the answer is just to use the current version of the browser rather than one which is 22 Chromium versions older.
NotHereToPlayGames Posted Saturday at 10:24 PM Posted Saturday at 10:24 PM AGREED. But remember, not all Cloudflare capcha's are "identical". The one for my city utilites goes into an ENDLESS LOOP for SUPERMIUM v144, Chrome v144, and Chromium v144. But yet that is the "newest" we have for SUPERMIUM. Supermium CAN pass the Cloudflare capcha offered up by BING if I want an AI-generated javascript kick-in-the-right-direction. But it can NOT pass the Cloudflare capcha to pay my city utilities. 2
we3fan Posted Sunday at 08:51 AM Posted Sunday at 08:51 AM @NotHereToPlayGames I see, thanks ArcticFoxie, I appreciate it.
Dave-H Posted Sunday at 10:23 AM Posted Sunday at 10:23 AM 11 hours ago, NotHereToPlayGames said: AGREED. But remember, not all Cloudflare capcha's are "identical". The one for my city utilites goes into an ENDLESS LOOP for SUPERMIUM v144, Chrome v144, and Chromium v144. But yet that is the "newest" we have for SUPERMIUM. Supermium CAN pass the Cloudflare capcha offered up by BING if I want an AI-generated javascript kick-in-the-right-direction. But it can NOT pass the Cloudflare capcha to pay my city utilities. You've probably already looked at this, but there's some information here about possible causes of challenges looping. https://developers.cloudflare.com/cloudflare-challenges/troubleshooting/challenge-solve-issues/
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now