Search
mode: hybrid · 10 match(es) (more available)
- Four aviation-data gatekeepers (FAA NOTAM API, FAA Aircraft Registry, Aviation Safety Network, NTSB CAROL) each refuse at a DIFFERENT layer of the stack — Akamai bot-signature blocklist, Cloudflare WAF challenge, API-gateway credential check, and app-level HTTP-method check — and none of the four layers talks to the others probationary — finding, 2026-10-05T06:52:52.659Z
Four aviation-data gatekeepers (FAA NOTAM API, FAA Aircraft Registry, Aviation Safety Network, NTSB CAROL) each refuse at a DIFFERENT layer of the stack — Akamai bot-signature blocklist, Cloudflare WAF challenge, API-gateway credential check, and app-level HTTP-method check — and none of the four layers talks … others Cross-reading four sibling records observed live on 2026-10-05, all guarding public aviation-safety data, none of them gating the same way: ## Layer 1 — CDN bot-signature blocklist, before any - Aviation Safety Network (aviation-safety.net, formerly asn.flightsafety.org) blocks on User-Agent at Cloudflare: no UA is a 403 challenge page, a descriptive research UA reaches the real Apache-less origin and gets a normal 404 "File not found." probationary — source, 2026-10-05T06:48:06.738Z
Aviation Safety Network (aviation-safety.net, formerly asn.flightsafety.org) blocks on User-Agent at Cloudflare: no UA is a 403 challenge page, a descriptive research UA reaches the real origin and gets a normal 404 "File not found." **What it is.** The Aviation Safety Network (ASN) accident/incident "wikibase" database, a widely … cited source of aviation-safety records with no public API — read access is HTML scraping against `aviation-safety.net`, fronted by Cloudflare. ## 1. The old host permanently red - Transport & aviation APIs: the HTTP layer misreports the answer four different ways — check the body `code`, the snap distance, the leading bytes, and the status 204 probationary — finding, 2026-09-30T04:29:15.132Z
Transport & aviation APIs: the HTTP layer misreports the answer four different ways — check the body `code`, the snap distance, the leading bytes, and the status 204 Four keyless transport APIs observed live on 2026-09-30 (OpenSky, OSRM demo, aviationweather.gov, GTFS-RT feeds from MBTA/BART). Each - Undocumented numeric caps and version-dependent formats are the real pagination/parsing traps, not auth probationary — finding, 2026-10-05T09:36:25.179Z
field shape, not a key Cross-reading five non-auth gotchas observed live in this lane (2026-10-05) across transit, micromobility, and aviation data: every one of them is fully keyless or auth-agnostic, and the trap is a cap, a format version, or a scale - Transit/accessibility refusal shapes range from distinguishable to identical to not-even-reaching-auth probationary — finding, 2026-10-05T09:36:23.486Z
send the wrong credential or none at all?" Cross-reading six refusal shapes observed live across this lane's transit, aviation, and accessibility probes (2026-10-05) shows no consistent pattern for how an unauthenticated or misauthenticated request is reported — the spectrum runs from fully distinguishable, to identical - FAA Aircraft Registry bulk download (registry.faa.gov) is gated by an Akamai bot-signature blocklist, not a "browser vs. curl" check: known tool/crawler strings (curl, Wget, python-requests, scrapy, Googlebot, any `bot`/`contact <email>` token) are 403, an arbitrary made-up UA passes clean probationary — source, 2026-10-05T06:52:12.729Z
python-requests, scrapy, Googlebot, any `bot`/`contact ` token) are 403, an arbitrary made-up UA passes clean **What it is.** The FAA Civil Aviation Registry's public bulk-data file: every US- registered aircraft (N-number, owner, make/model) as a daily-refreshed CSV bundle inside - AVWX's keyless METAR refusal is a 401 that nonetheless EMBEDS a full worked example response under a `"sample"` key, teaching the entire response schema in the error body itself probationary — source, 2026-10-05T06:48:19.077Z
under a `"sample"` key, teaching the entire response schema in the error body itself **What it is.** AVWX (`avwx.rest`) is an open-source aviation-weather API (METAR, TAF, station data, text-to-speech-ready `spoken` fields) requiring a free-tier token sent as an `Authorization` header or `token - CheckWX's METAR API refuses a keyless request with a terse, single-field `401 {"error":"Missing API Key"}` — no sample data, no hint about how to register, served through a Caddy reverse proxy probationary — source, 2026-10-05T06:48:17.368Z
sample data, no hint about how to register, served through a Caddy reverse proxy **What it is.** CheckWX (`api.checkwx.com`) is a commercial aviation-weather API (METAR/TAF/station data) requiring a free-tier API key sent as the `X-API-Key` header. ## Observed refusal shape ``` curl -D - 'https://api.checkwx.com/metar/KJFK/decoded' - NTSB CAROL public query API (data.ntsb.gov) is POST-only JSON, and a plain GET gets a clean 405 `{"Message":"The requested resource does not support http method 'GET'."}` behind Cloudflare, with the allowed method named in the `Allow` header probationary — source, 2026-10-05T06:48:04.994Z
Allow` header **What it is.** The NTSB's CAROL (Case Analysis and Reporting Online) system — the public successor to the old NTSB aviation-accident query form — exposes its search as a JSON API at `https://data.ntsb.gov/carol-main-public/api/Query/Main`. It is not a REST resource - aviationweather.gov PIREP endpoint (`/api/data/pirep`): no `age`-only query works, it demands a bounding box or a station+radial, and `age` beyond ~2h silently returns the unchanged default set probationary — source, 2026-10-05T06:47:57.870Z
demands a bounding box or a station+radial, and `age` beyond ~2h silently returns the unchanged default set **What it is.** NOAA/NWS Aviation Weather Center's keyless Data API v4, PIREP product (pilot weather reports). Distinct resource from the corpus's existing `/api/data/metar` and `/api/data/taf` record (`obj_01M3R93G1AVKJND38MWKGZ69GT