403 forbidden - what`s this all about?

MyE28.com Forum system comments and questions. Please post registration, login, or general forum usage problems here.
Post Reply
12valves
Posts: 407
Joined: Aug 03, 2009 9:29 PM
Contact:

403 forbidden - what`s this all about?

Post by 12valves »

Image
Jeremy
Beamter
Beamter
Posts: 15843
Joined: Feb 12, 2006 12:00 PM
Location: Connecticut

Post by Jeremy »

Holy crap, you're still on Windows 3?? Your ID string indicates NT 3.51 and Firefox 2.0.

I think the message is self-explanatory. You're running (or it thinks you're running) a very outdated browswer version that isn't maintained, and has known security flaws. That makes it a very dangerous browswer to use, because it could be compromised in any number of different ways.
12valves
Posts: 407
Joined: Aug 03, 2009 9:29 PM
Contact:

Post by 12valves »

I don't usually use the old NT but I've never seen another site that had a blanket ban on old browsers. (A lot of sites won't work right, but that is different than showing a giant error message, and most forums work fine.) It seems pretty arbitrary and I don't know why you would care. How much malware is targetting NT 3.51? More importantly, user agents can be spoofed.
mooseheadm5
Beamter
Beamter
Posts: 23035
Joined: Apr 08, 2009 10:30 PM
Location: Charlottesville, VA
Contact:

Post by mooseheadm5 »

12valves wrote:I don't usually use the old NT but I've never seen another site that had a blanket ban on old browsers.
I have.
Jeremy
Beamter
Beamter
Posts: 15843
Joined: Feb 12, 2006 12:00 PM
Location: Connecticut

Post by Jeremy »

I can't say for certain the reasoning behind it, but FF 2.0 is ancient. When it comes to site security, I largely defer to Justin's judgement. We've had relatively few issues from a security standpoint, and I'd prefer to keep it that way.

You must have a more modern machine you can use for browsing the site, don't you?
Last edited by Jeremy on Aug 15, 2013 6:51 PM, edited 1 time in total.
mooseheadm5
Beamter
Beamter
Posts: 23035
Joined: Apr 08, 2009 10:30 PM
Location: Charlottesville, VA
Contact:

Post by mooseheadm5 »

12valves
Posts: 407
Joined: Aug 03, 2009 9:29 PM
Contact:

Post by 12valves »

Well, I mostly disagree with this. It's reasonable for sites handling financial transactions and the like to block unsecure clients. Otherwise I don't think old hard/software should be deliberately blocked anymore than old cars should be banned from the road. But I'm not going to tell you guys how to run your site.

FYI, I was only on NT3.51 "because I can." I have it setup to dual-boot on an XP machine and occasionally test FreeBASIC code on it.
mooseheadm5
Beamter
Beamter
Posts: 23035
Joined: Apr 08, 2009 10:30 PM
Location: Charlottesville, VA
Contact:

Post by mooseheadm5 »

Another issue is that if the site does not work properly on older browsers, we will get complaints that the phpbb stuff is broken, when the problem is just your antique software.

In many states, busted old cars that aren't fit for the road are not allowed.

Also, the reason given in the 403 notice is pretty explanatory. Hackbots and spambots often use older protocols because of the exploits that can be used.
Kyle in NO
Posts: 17638
Joined: Feb 12, 2006 12:00 PM
Location: Nasty Orleans------> Batten-Rooehjch------>More Souther LA

Post by Kyle in NO »

I get the same bullshit Forbidden message all the time on my iPhone using the most up to date Safari browser. I don't think it has anything to do with his old ass browser.
mooseheadm5
Beamter
Beamter
Posts: 23035
Joined: Apr 08, 2009 10:30 PM
Location: Charlottesville, VA
Contact:

Post by mooseheadm5 »

Kyle in NO wrote:I get the same bullshit Forbidden message all the time on my iPhone using the most up to date Safari browser. I don't think it has anything to do with his old ass browser.
His is very specifically due to his browser. Yours could be that the ip address your phone uses could be part of a banned block. If you can get that IP address and tell Justin, he can unblock it if that is the issue or just post the screencap. I don't have a problem with Safari on the ipad.
Jeremy
Beamter
Beamter
Posts: 15843
Joined: Feb 12, 2006 12:00 PM
Location: Connecticut

Post by Jeremy »

12valves wrote:Well, I mostly disagree with this. It's reasonable for sites handling financial transactions and the like to block unsecure clients. Otherwise I don't think old hard/software should be deliberately blocked anymore than old cars should be banned from the road. But I'm not going to tell you guys how to run your site.

FYI, I was only on NT3.51 "because I can." I have it setup to dual-boot on an XP machine and occasionally test FreeBASIC code on it.
Again, read the actual message.

I'll quote:
"The detected reason(s) you were blocked are:
You are running a severely outdated version of Firefox which matches a hackbot or spambot profile."

As I stated earlier, those older browsers are very vulnerable. Any flaws they have are not going to be patched. Ever. This makes them attractive targets for people running spambot networks.

Ever wonder why you don't see a ton of spam on this site? First off, it's because we kill it with fire when it pops up. Second, we do what we can to stop it from getting in to begin with.

All this over an issue that really doesn't affect you much at all. Kyle's issue is actually more concerning. Screen cap the error you get and post it, please, Kyle.
Kyle in NO
Posts: 17638
Joined: Feb 12, 2006 12:00 PM
Location: Nasty Orleans------> Batten-Rooehjch------>More Souther LA

Post by Kyle in NO »

I will do that next time it happens.
wkohler
Posts: 50924
Joined: Oct 05, 2006 11:04 PM
Location: Phönix, Arizona, USA
Contact:

Post by wkohler »

I have been getting that pretty regularly myself recently.
mooseheadm5
Beamter
Beamter
Posts: 23035
Joined: Apr 08, 2009 10:30 PM
Location: Charlottesville, VA
Contact:

Post by mooseheadm5 »

Sounds like an issue that we need to have Justin look at then. If anyone else is having this problem, try to get a screen cap and post it.
Kyle in NO
Posts: 17638
Joined: Feb 12, 2006 12:00 PM
Location: Nasty Orleans------> Batten-Rooehjch------>More Souther LA

Post by Kyle in NO »

Here is what I keep getting, mixed in with Safari telling me the page is not available.
Image
Justin_FL
MyE28 IT Guru
MyE28 IT Guru
Posts: 2822
Joined: Feb 12, 2006 12:00 PM
Location: Palm Beach
Contact:

Post by Justin_FL »

Kyle in NO wrote:Here is what I keep getting, mixed in with Safari telling me the page is not available.[/img]
That IP appears to have recently expired out of the StopForumSpam database, refreshed the cached copy on the server so it should be clean. You were only blocked from login functions and shouldn't have experienced problems browsing as a guest.

Cell phone networks are dirty and a growing preference for spammers/hackers in the US as an Internet connection, so it is likely that IPs shared amongst many subscribers can and will get blocked...

I did turn on a function on the error page that should allow innocent users to compose an email with the block details so it is easier to report false positives.
Kyle in NO
Posts: 17638
Joined: Feb 12, 2006 12:00 PM
Location: Nasty Orleans------> Batten-Rooehjch------>More Souther LA

Post by Kyle in NO »

When that pops up, I am not even able to access the basic www.mye28.com web page as a guest.

Edit:
Maybe I screen cap'd that message during a login attempt. I'll send one of the other message when it happens again.
MIK911
Posts: 185
Joined: Jul 29, 2013 6:41 PM
Location: SoCal

Post by MIK911 »

On my Android cellphone, I am blocked, and the "403 Forbidden" reason is.....
"Hurricane Electric (ASN-HE1-087)"

whatever that means.

Can someone tell me how to rectify this problem so I can log onto this site from my Android?

thanks
Post Reply