• TalkBass has been independent since 1998. Add your voice.
    Create a free account to reply to discussions, view embedded media, and browse with fewer display ads.
    Join freeLog in
    Want zero display ads or expanded classifieds tools? Compare plans.

Cloudflare Rejection: "Sorry, you have been blocked"

Once again, Cloudflare gets in the way of actual human beings trying to browse the internet. I know their sales pitch is selling people on how they block bots and hackers, but I am neither and they're blocking me. For every technically-inclined user who cares enough to report it, there are probably 100 who don't bother.

I was browsing through my VPN about 15 minutes ago, looking at page 2 of the Basses for Sale in the TB classifieds, and when I clicked the link for page 3, I got the "Sorry, you have been blocked" message, which goes on to say "You are unable to access talkbass.com" It provides the Cloudflare Ray ID 76ee7478ceb37e47 at the bottom of the page and suggests that I email the site owner.
 
I refreshed the page a couple of hours later and it worked OK. I clicked another link and that worked too. I figured it must be resolved, but the next link I clicked showed the error message again.

In summary, despite the fact that Cloudflare has clearly decided that I'm up to no good, they let 67% of my allegedly malicious HTTP requests through. In other words, they not only block legitimate traffic, they are inept when it comes to actually blocking traffic they previously identified as suspect.
 
Once again, Cloudflare gets in the way of actual human beings trying to browse the internet. I know their sales pitch is selling people on how they block bots and hackers, but I am neither and they're blocking me. For every technically-inclined user who cares enough to report it, there are probably 100 who don't bother.

I was browsing through my VPN about 15 minutes ago, looking at page 2 of the Basses for Sale in the TB classifieds, and when I clicked the link for page 3, I got the "Sorry, you have been blocked" message, which goes on to say "You are unable to access talkbass.com" It provides the Cloudflare Ray ID 76ee7478ceb37e47 at the bottom of the page and suggests that I email the site owner.

76ee7478ceb37e47 Triggered bot fight mode on Cloudflare. It’s a Romanian IP. Can you use a different vpn node?
 
  • Like
Reactions: Karl Kaminski
Thanks for the response. The subnet is actually in a Las Vegas datacenter, but owned by a Romanian ISP called M247 SRL (which is a subsidiary of M247, headquartered in the UK). I can use a different VPN node in a different city and will do that if I encounter the problem again (and will post the ray ID if I do).

However, I will mention that I have browsed at least 30 pages on talkbass.com during the past 24 hours (including just a few minutes ago) using the same browser through the same IP on the same VPN node where I experienced the problem on Wednesday night. 100% of those requests have been successful. I'm not sure whether that's a result of the change you made or just good luck on my part, but I figured I'd mention it. Thanks again for looking into this problem.
 
Cloudflare have been blocking me for more than a week now. I've been trying to use a temporary static IP (on a different subnet) from AAISP to get past it and that didn't work. I'm currently bypassing a local proxy that I need to use to provide centralised certification for different browsers that need to connect to it.

This bypass may not last long so I'm posting this while I can.

The latest block, when using the local proxy:
Cloudflare Ray ID: 771b888009bd88bb
If there is any chance of whitelisting my IP, please do it. It's static, it won't be used by or assigned to anyone else, and I don't think I've done anything that justifies Cloudflare locking me out without warning or explanation.

If I knew more about why the block happens I might be able to change how Proxomitron is working to do what I need, but it's more likely I can do nothing. I don't understand why normal activity that was ok for months suddenly became equivalent to a banning offence.. Cloudflare is a menace (as is Captcha). These tools do not make it easier to be secure, they just make horrible new problems for people who have no possibility of getting past them without help.
 
Cloudflare have been blocking me for more than a week now. I've been trying to use a temporary static IP (on a different subnet) from AAISP to get past it and that didn't work. I'm currently bypassing a local proxy that I need to use to provide centralised certification for different browsers that need to connect to it.

This bypass may not last long so I'm posting this while I can.

The latest block, when using the local proxy:
Cloudflare Ray ID: 771b888009bd88bb
If there is any chance of whitelisting my IP, please do it. It's static, it won't be used by or assigned to anyone else, and I don't think I've done anything that justifies Cloudflare locking me out without warning or explanation.

If I knew more about why the block happens I might be able to change how Proxomitron is working to do what I need, but it's more likely I can do nothing. I don't understand why normal activity that was ok for months suddenly became equivalent to a banning offence.. Cloudflare is a menace (as is Captcha). These tools do not make it easier to be secure, they just make horrible new problems for people who have no possibility of getting past them without help.

Looking up that ray ID, it appears it triggered CloudFlare's "Bot Fight Mode for Definite Bots". In other words, the IP you're coming in from is flagged as a bad bot's IP. This is for the IP ending in 19.110
 
Looking up that ray ID, it appears it triggered CloudFlare's "Bot Fight Mode for Definite Bots". In other words, the IP you're coming in from is flagged as a bad bot's IP. This is for the IP ending in 19.110

Ok, but I told you what I'm using, and what I'm doing with it. Does that sound like a 'bot fight' to you?

If I tell the browser not to use Proxomitron, it gets through, so the IP isn't the problem. Yesterday I used a different static IP that differed in both C and D addresses, so if you're using an IP-related block it's cutting out at least 64000 possible users of one ISP, and you might not want to be doing that. It's a very big sledgehammer for a very small nut. Again, if the browser is forced to connect directly, the block is not triggered.

There is no 'bot' here. Never has been. The last time I had malware on board was Code Red/Nimda, nearly 25 years ago, and that was only because I was curious and wanted a look at it. :)

Now, it is possible that Cloudflare is suspicious of a local proxy as a means of 'amplification' that can accelerate a DDoS attack, and is guarding against it on principle the way an ISP might scan its users for DNS servers, for the same reason. (Legitimate services that can be exploited in this way). That begs the question of how Cloudflare can even assume that my local proxy can be a risk. It's explicitly NOT accepting WAN connections of any kind, so it's not possible to attack it, or use it in any attack.

Whatever settings you're using, they're causing unrest, and you may be losing many users for all I know. If they are blocked, many won't know a way to get back to tell you! It's probably worth backtracking on those changes and looking for another way.

I wasn't doing things any differently for the last four months, so the fact that the same normal forum activity is now considered suspect is not down to me. By your own admission, you have been changing things. :) Using a security system that flags false positives is like using antivirus instead of antitrojan, it's like using a policeman who uses prejudice instead of watching what the suspect actually does.
 
Last edited:
Can you tell me about your setup? Do you have javascript disabled? Are you connecting through a proxy? I can understand the frustration if you're getting a cloudflare challenge more than once. But it's a matter of finding a balance and tuning the sensitivity of the bot management. Yesterday cloudflare blocked nearly 900,000 requests from bad bots and likely bad bots, most of them hitting the /login url to try and bust into people's accounts. If we're catching humans, I can turn down the sensitivity of our bot management.