Skip to content

Instantly share code, notes, and snippets.

@baudneo
Last active April 30, 2023 16:24
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save baudneo/469b990c788cc958a1047762021106f1 to your computer and use it in GitHub Desktop.
Save baudneo/469b990c788cc958a1047762021106f1 to your computer and use it in GitHub Desktop.
CloudFlare browser secuirty check error for apps hosted via CF (cloudflared) tunnels - Started mid April 2023
Apr 30, 2023 09:45:48:605 AM DEBUG *** Inside native HTTP error for
url:{
"status":403,
"url":"https://zm.<<<REDACTED>>>.com/zm/api/host/login.json?token=<<<REDACTED>>>L3zzdPc0jKc_AkhrsQlJG87IsSHUk_qm7Rwc6XXe-nI",
"headers":{
"date":"Sun, 30 Apr 2023 15:45:48 GMT",
"server":"cloudflare",
"expires":"Thu, 01 Jan 1970 00:00:01 GMT",
"cf-ray":"7c00e9f65bae842b-YVR",
"transfer-encoding":"chunked",
"x-android-selected-protocol":"http/1.1",
"vary":"Accept-Encoding",
"x-android-response-source":"NETWORK 403",
"x-android-received-millis":"1682869548600",
"x-android-sent-millis":"1682869548508",
"x-frame-options":"SAMEORIGIN",
"permissions-policy":"
accelerometer=(),
autoplay=(),
camera=(),
clipboard-read=(),
clipboard-write=(),
fullscreen=(),
geolocation=(),
gyroscope=(),
hid=(),
interest-cohort=(),
magnetometer=(),
microphone=(),
payment=(),
publickey-credentials-get=(),
screen-wake-lock=(),
serial=(),
sync-xhr=(),
usb=()",
"cross-origin-opener-policy":"same-origin",
"cf-mitigated":"challenge",
"nel":"{
\"success_fraction\":0,
\"report_to\":\"cf-nel\",
\"max_age\":604800
}",
"referrer-policy":"same-origin",
"connection":"close",
"content-type":"text/html; charset=UTF-8",
"cross-origin-embedder-policy":"require-corp",
"cross-origin-resource-policy":"same-origin",
"report-to":"{
\"endpoints\":[{\"url\":\"https:\\/\\/a.nel.cloudflare.com\\/report\\/v3?s=9CiIHj2pxwWrH6tFE8iZuMRVFJnorSHEkk%2BbP5fBCfuZTP2u268HfzHULFRL7dTmX%2Foi0LraY7EsDMGLiLMKZWR%2Bwt%2BqaF7zG1lWsxAYLT8bipAu8HIBNS6Gy8%2B7BPyI1g%3D%3D\"}],
\"group\":\"cf-nel\",
\"max_age\":604800
}",
"alt-svc":"h3=\":443\"; ma=86400,h3-29=\":443\"; ma=86400",
"cache-control":"private,max-age=0,no-store,no-cache,must-revalidate,post-check=0,pre-check=0"
},
"error":"
<!DOCTYPE html>\n
<html lang=\"en-US\">\n
<head>\n
<title>Just a moment...</title>\n
<meta http-equiv=\"Content-Type\" content=\"text/html; charset=UTF-8\">\n
<meta http-equiv=\"X-UA-Compatible\" content=\"IE=Edge\">\n
<meta name=\"robots\" content=\"noindex,nofollow\">\n
<meta name=\"viewport\" content=\"width=device-width,initial-scale=1\">\n
<link href=\"/cdn-cgi/styles/challenges.css\" rel=\"stylesheet\">\n
\n
\n
</head>\n
<body class=\"no-js\">\n
<div class=\"main-wrapper\" role=\"main\">\n
<div class=\"main-content\">\n
<noscript>\n
<div id=\"challenge-error-title\">\n
<div class=\"h2\">\n
<span class=\"icon-wrapper\">\n
<div class=\"heading-icon warning-icon\"></div>\n
</span>\n
<span id=\"challenge-error-text\">\n
Enable JavaScript and cookies to continue\n
</span>\n
</div>\n
</div>\n
</noscript>\n
<div id=\"trk_jschal_js\" style=\"display:none;background-image:url('/cdn-cgi/images/trace/managed/nojs/transparent.gif?ray=7c00e9f65bae842b')\"></div>\n
<form id=\"challenge-form\" action=\"/zm/api/host/login.json?token=<<<REDACTED>>>L3zzdPc0jKc_AkhrsQlJG87IsSHUk_qm7Rwc6XXe-nI&amp;__cf_chl_f_tk=W2Lk8wFD2js3V1xeVXjZ_8UXpSFrjWbECu.AsB1TCp4-1682869548-0-gaNycGzNDFA\" method=\"POST\" enctype=\"application/x-www-form-urlencoded\">\n
<input type=\"hidden\" name=\"md\" value=\"DIS14p9oYKo9r3P.AFsQ5DDyUMF0m5FqHHWdmuyV05Q-1682869548-0-Ae7yqEgPAllxt5iPWBnFJDGXY8nSU-B8S96BBu496VRPxZKiOGZE0x_QX_bZhfn-paSSldraE6FyYcQf9Bwhv8lg-2hDGKMvggyPckQurSmz1IYHZtbafpydwGyi2rjJTOH_GI2jshXkU2P5HmxF-YXJHXAjcx_se3EVd-SRQ7L7xexX4yOkH-ary5251osW6kcyKCBTMWqcuLE6HDIzXwZN2o4DszC7rWWXeXzmAyKLGgPF0QHRHsuQWbnh3mNvFHdE4ARwH8W2DKqvU6o_SKADbjjpVN56q3-xWBzKYBkYKQqJ3lD811yAyPBbbGjSVPCOkimCKtRH5bHEb1gCGu11_AyaLP4rigDWZwJ0hC2iufhTGdgBsLbcGXpwe11QF9pg74bQ2luFXzpd97GpJWGm8FK2_vQFDASltHNdDZ7omkn6nmbIvh1pQ-nbcSpPzrMVDQJEseUXmzdp48UukBYERyyIa2wY9ap9SFvNUcsWwyiiAAgOeizyZ0E2z_DV9T4DlFY6_jKgg13z4wOzC3IcAG7IVHBZcjl0Pwf31ygSGAgTgzwB2QlBRPcTJdBNHxp1AMqkX7YrXerTj0Qc-UGX6kmt4388m6-og9h9ZnOAfR6sDCCHkRAIFjDiv33R9nZD-QlQXCxqt_xTU713CQBW4A6q0UzyhNTHovcLQv1Ffa8tufkkKaiBJr0LxktriFmYJznoNcMOYkv3pNzUtgTCRSsvVym_ZcUV2NWRwpd9oc8060WuT36fQhyD6mgr67I31xsO3qz1O6uOJrpPLzNvAF8AkGh84wmAG9ZUuarIkTaSAHYCDX6Ukd4u5UD6-qOLUqgAe-jpxWb6UjQ3q7DMnnB2p7U3AyEiNwSC4AGDyhKSDvKTRrGG0TcVEBPXRWa0J5k_XivLxHOYnd0dHPbKyi1nML3jrH5O5gaz600pTKqh1LNmSkg4DtW10bX9CEGPTCyxsKRO2KT9_72Nr71bKwhBaCtxLc3TI6s0_rv40xgIZ700c0NkBTzKRBpRK7LhCh2aOuEdngA5Z7l4fnskEfoGpkjSj9Jg0vvITN_8Y2OtcQgzm-fg8OWLn4hz-PMx1Va0vk-jn3yi8Hi2CLw4rQHsYIJxPKG_yZzPkymQnTCVQYd26TVRp3-Iq0WlQejP7t7MKZOHhrqNfvV-LPDiPBMbeF6tw0BMzwjyCBb194NRqL1Tzcm0vnyW6J3hVdsGEXQJu6tI0vq1d4ZPU_HTogQxG0MVusjkoubRb5gE9bPUGA6-2ZIVqVTwOmu_Dlo0yYLTmiPcDXtdqiHzBbh0R40Zf2XICBrLUjXTEhiiXSGa7s2EtakwWfvuaFFiy1dgsjCkLGXy16O6NR8AlF9QtwuHEEUFaY5L3qY5p43C8MBF8XM8OLQA8zo0-9GAQFlL7-JIvcpxyEQFOYsRwWahSOi4nude6lHNyocWwndL15-4Hp3dSf6macTbGBipKp6rjUmyoKm4WJn2UgVrt-lk1v50ZLTjERm0TecS09ZUtbPQRnQHNCxLkGjTCOQkrFQ7X0i2du5cFLATwegdpTyUsDb3CEiwlgezk8THLxOAHhc7NqZz8OvYaPV88r7PjB3v2O5LxV9BuokFnBgqjRHLzxpv48Ck_UpwrKHATqqRtbms90wCa1vNKGW3OK71afbfX3c-iYR_mwx4SSr2JMFd5x3PRLcknRVaJoGmsSsWMmZ-sxhwT38WJCFF8DBgwj3umxnEQqGefSKtjzjdu398qP9eQK6tHr9sfgFxqZc7gxRf-mkS0uXBel3QBbHojQFaaxFdZgLInnZ-2tTmbwQedF-cIvLyWblyhLaouN0o7Hh7aBT-JfE_LMdghMgzXfAaPOOzinKzbIPz-0LZqKnOMLKY_KJI4rVo1L2cGzf6-ZwCECICaif5le8bNd3P_HTlS-HFRLbTTk3GPUoQ1Iv-w422DFYbtYOAnN1afVVL6hqTRKjm5Dh8eA739OJRnwEmjukJFP76dyxhyozqHBw9fuZizcJULM7jqsMdtHc4ex-WKnqUb-B2wgpARWLHjTw0H4ceLn--FfaGBSZEmJwPZdPChIkItgMOuWwte0nuk57HrFEq6D0eNUMlnbC0Op5yCHstmbLU2UOJGe252eojSxEzlcdxoE5reOYVccgAwrJgeuCviSeQ8JeONP4mRyJv8B9Ts-gDTyZMA8Gcw0SbZgJFp-kcGPmxf88WwaaGQ368K-VwRQ2JzlSBHpWeK__R0uH6SF9HOS2lsKjhLLhZ7YYjGJ4el6Z3yaEizbVcfN_tEAolcItg2Rgy_CASGWHNBA1fcesedqeh1nhmiifGIZWHkxIL2LF89RQ14HqO47ef8AApxfmrZqXnFL6XGStFZLyEigva8qRxNOCUUQ8L2kXoD6XU65q-rHqCNqieMwgZOjAeAwfhIWrPSTxN-9VXUKwtmH4cv7NjxbuKhmgw4ia-aHBAfV5DGd2JnMnqXPLSvQDM5tK1AlvZIkFiuNIZWG6pwsz5gkMrD9EMf-e7Mk-SHSs7QGaeZK8l6Kdt1sXBMxSuAKduVvoHvmIoyUUSO7Si8de83AMqqFpjcXFOOga4-hVDwyuzf0DHHgDEpQcpDS13yd0lKigjFKYst4UjausVykPgcTQmmxL3322zum7Iun_iZ8NXLDveKySPhmWKewLlyer-Pnr_X-vDuJWaRkq43rzU_d3JoAzAUZa6CfAugznWvhRO6cjegLbz72CZ7Dms_HJ1EaJFeLXbZ9vYgAbgJsF8KG0LYfK6D0BUqs_Q-3_X9mONtySYG6yfhZi7xoNpNPAK6sh0wzgzfPS6tVUDKJwOkIj4Dt628qg_brlGVNeUgH-iJxyV6RjrvT0Vz4cXx8CHzsiad7v6mUrlx6eeTeG6gSKBblDBGNj2JraMc6NTcc0WCxJrS9-pgxAHC6A10HbAuNhrKpAhGPbVCYEAH2RmvevuJg5LI176n-21mW9VD8BfXBE_0tb-w--7hCWBiDyGes5uznf6CevgcAJ6V5HYql0YSx7sXwwsrxTfJM0W6aKMZ9yOxm5ly7ugLRNdp1Mh0BAwiLDjVYEqmsUG_YF1BZRrPbDfYIg\">\n
</form>\n
</div>\n
</div>\n
<script>\n
(function(){\n
window._cf_chl_opt={\n
cvId: '2',\n
cZone: 'zm.<<<REDACTED>>>.com',\n
cType: 'managed',\n
cNounce: '65352',\n
cRay: '7c00e9f65bae842b',\n
cHash: '3ac3c21ad50132f',\n
cUPMDTk: \"\\/zm\\/api\\/host\\/login.json?token=<<<REDACTED>>>L3zzdPc0jKc_AkhrsQlJG87IsSHUk_qm7Rwc6XXe-nI&__cf_chl_tk=W2Lk8wFD2js3V1xeVXjZ_8UXpSFrjWbECu.AsB1TCp4-1682869548-0-gaNycGzNDFA\",\n
cFPWv: 'g',\n
cTTimeMs: '1000',\n
cMTimeMs: '0',\n
cTplV: 5,\n
cTplB: 'cf',\n
cK: \"\",\n
cRq: {\n
ru: 'aHR0cHM6Ly96bS5iYXVkbmVvLmNvbS96bS9hcGkvaG9zdC9sb2dpbi5qc29uP3Rva2VuPWV5SjBlWEFpT2lKS1YxUWlMQ0poYkdjaU9pSklVekkxTmlKOS5leUpwYzNNaU9pSmFiMjVsVFdsdVpHVnlJaXdpYVdGMElqb3hOamd5TnpnNE9UWXdMQ0psZUhBaU9qRTJPREk0TnpVek5qQXNJblZ6WlhJaU9pSjZiVzVwYm1waElpd2lkSGx3WlNJNkluSmxabkpsYzJnaWZRLkwzenpkUGMwaktjX0FraHJzUWxKRzg3SXNTSFVrX3FtN1J3YzZYWGUtbkk=',\n
ra: 'RGFsdmlrLzIuMS4wIChMaW51eDsgVTsgQW5kcm9pZCAxMzsgU00tUzkwOFcgQnVpbGQvVFAxQS4yMjA2MjQuMDE0KQ==',\n
rm: 'R0VU',\n
d: '0poog5dv9Y3tcsq8K4sLzXpS9LV8ERRYHIpTnPAY8A9bJZdLPxEKRPZ52civwAmn5nkpF2F7R7NonfuuYV6KDpi7o8TGDbllm+HX2kJSpZaMbiPhdsalQ4sh2cy6RIyRPN+C7xTbAoiJHPJhbpOK4HobL6zljyrwRcrN/531vxS1lDubOvC/5diYp1wBy4sfP/t88H30TN2BhS8vQg1AsXiJRO8Nm4Vnu7rClqxp7xPQB3SDsTEIjtW/VmgtrINsjHiZB3Kg+cP3oDE/XW0zGviWLh6yBJRESSb13G63WJwhtZIQ72Ha3U9i0nyojiMXf/AfQvZTcncIBwaKThjgqdtZsz2lCwhjS4Fd5afNd1Lwr20t9BH/TbIVDmN7YLhuHYJgBg85dIxnQpI/lo3mkM6PIXiR00hNEK4+6Zp4iilN1aWbTLpsCWo9uHY+qTdFC6OaqkrHtZx/DZDnN10at6eQVxqIzx5ZOv5zqov6/SxbX+cnvJH1NJKLYJvMh8ssT4CdUAuBjR+hqEYWwSXDYohFd7+6o+n314cWxtVSYcY1XT3mJKRP21NOs9ftdP/FKLXg5aMtq5CyO2hNDkPSTeOjcGAeg3hmZyIQSLvS8+sGPwjUgYiXVjv+x7LRSJ6O',\n
t: 'MTY4Mjg2OTU0OC41NDQwMDA=',\n
m: 'SAxZMLyq+wNh03TveGuHS7pR0qLeuO7PkdJKkHccP1I=',\n
i1: 'kQM2BTEjDSU0ZnQJPmdQ+Q==',\n
i2: 'gUicCsN7ZwhrywfcjhSn7Q==',\n
zh: 'izx77VnZjtNsJEeBvboXN+cuphQv+MpZZlLKzsqsPyk=',\n
uh: 'kdJ+D8BnNve0vc19mLmOVsJZJZqVVABKuIbO08Jn0CQ=',\n
hh: 'QIM8qZhMLcWsfjb8IK5sTuvWKUDXw4IkHfgO6PASLLk=',\n
}\n
};\n
var trkjs = document.createElement('img');\n
trkjs.setAttribute('src', '/cdn-cgi/images/trace/managed/js/transparent.gif?ray=7c00e9f65bae842b');\n
trkjs.setAttribute('alt', '');\n
trkjs.setAttribute('style', 'display: none');\n
document.body.appendChild(trkjs);\n
var cpo = document.createElement('script');\n
cpo.src = '/cdn-cgi/challenge-platform/h/g/orchestrate/managed/v1?ray=7c00e9f65bae842b';\n
window._cf_chl_opt.cOgUHash = location.hash === '' && location.href.indexOf('#') !== -1 ? '#' : location.hash;\n
window._cf_chl_opt.cOgUQuery = location.search === '' && location.href.slice(0, location.href.length - window._cf_chl_opt.cOgUHash.length).indexOf('?') !== -1 ? '?' : location.search;\n
if (window.history && window.history.replaceState) {\n
var ogU = location.pathname + window._cf_chl_opt.cOgUQuery + window._cf_chl_opt.cOgUHash;\n
history.replaceState(null, null, \"\\/zm\\/api\\/host\\/login.json?token=<<<REDACTED>>>L3zzdPc0jKc_AkhrsQlJG87IsSHUk_qm7Rwc6XXe-nI&__cf_chl_rt_tk=W2Lk8wFD2js3V1xeVXjZ_8UXpSFrjWbECu.AsB1TCp4-1682869548-0-gaNycGzNDFA\" + window._cf_chl_opt.cOgUHash);\n
cpo.onload = function() {\n
history.replaceState(null, null, ogU);\n
};\n
}\n
document.getElementsByTagName('head')[0].appendChild(cpo);\n
}());\n
</script>\n
\n
\n
</body>\n
</html>\n
"}
@baudneo
Copy link
Author

baudneo commented Apr 30, 2023

Cloudflare error when trying to issue simple HTTP commands to API routed through cloudflare tunnels (cloudflared).

This is the "browser security check" that seems to have been rolled out earlier this month (April 2023), I see the new browser security check pages all over the internet when I'm browsing as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment