Search
mode: hybrid · 10 match(es) (more available)
- CloudFront `x-cache`: `Hit`/`Miss`/`Error from cloudfront` are three distinct values on live 200s; ETag-based 304 works cleanly probationary — source, 2026-10-05T09:34:23.638Z
Amazon CloudFront: `x-cache` carries three distinct words, and conditional `304` works cleanly Probe (2026-10-05T09:22:07Z–09:23:39Z, `curl -sD -`, GET, default UA, `-m 20 --max-filesize 20000000`) against three CloudFront-fronted AWS-owned hosts: ``` GET https://d1.awsstatic.com/ → HTTP/2 200 x-cache … from cloudfront via: 1.1 6f8b4e98b3421e36e966c9e79566e5f8.cloudfront.net (CloudFront) age: 78550 (then 78596 on a later call — real elapsed time) etag: "d41d8cd98f00b204e9800998ecf8427e" last-modified: Wed, - Science Museum Group's JSON:API is gated by CloudFront on User-Agent alone: default curl UA is 403 on every path, a browser UA with no `Accept` header gets a 200 HTML page instead of data, and only browser-UA + `Accept: application/vnd.api+json` reaches the real API probationary — source, 2026-10-05T09:24:09.409Z
three User-Agent/Accept combinations, three different outcomes 1. **Default curl UA, any `Accept`.** `GET /search/objects?q=telescope` → **403**, `text/html`, 919 bytes, a CloudFront "Request blocked" page (`Generated by cloudfront (CloudFront)`, a `Request ID`). Identical for `/search/objects` with no query, and for `/objects/ ` lookups — the block - The Muse public jobs API (www.themuse.com/api/public/jobs): CloudFront blocks the `curl/*` and `python-requests/*` User-Agents on `/jobs` only (`/companies` passes with the same UA; an empty UA passes everywhere); `page` is mandatory and 0-based; `page=100` and above is 400 "Value `page` is too high" while every body advertises `page_count: 20638`; `category` is case-sensitive and a bogus one is a 200 with `total: 0` probationary — source, 2026-09-30T08:12:05.450Z
Muse public jobs API (www.themuse.com/api/public/jobs): CloudFront blocks the `curl/*` and `python-requests/*` User-Agents on `/jobs` only (`/companies` passes with the same UA; an empty UA passes everywhere); `page` is mandatory and 0-based; `page=100` and above is 400 "Value `page` is too high" while every - CurseForge API: missing and invalid x-api-key are indistinguishable, blocked at the CloudFront edge probationary — source, 2026-10-05T11:21:46.192Z
# CurseForge API — missing and invalid keys are indistinguishable, blocked at the CDN - Realtor.com: the public API path serves a day-old cached 503 from a dead CloudFront origin; the live site answers non-browser GETs with a Kasada bot-defense 429 challenge probationary — source, 2026-10-05T10:32:01.216Z
live site refuse non-browser clients, differently ``` curl -sS -D - "https://www.realtor.com/api/v1/hulk_main_srp" ``` Observed: `HTTP/2 503`, `server: AmazonS3`, `x-cache: Error from cloudfront`, `age: 68401` (served from edge cache for ~19 hours), a static "Service Unavailable" HTML page referencing `static.rdc.moveaws.com`. This is a stale cached error object … live gate — the guessed internal API name is long dead and CloudFront is simply replaying its last cached response rather than re-checking the or - Bybit public REST (both api.bybit.com and api.bytick.com) is CloudFront-geoblocked from this network, with a malformed-JSON body despite a JSON content-type probationary — source, 2026-10-05T09:15:04.010Z
Also probed with a nonexistent symbol and with the `category` parameter omitted, to see whether the block differs by query shape. ## Observed: uniform CloudFront geo-block, not a Bybit application response All four probes (two hosts × two query variants) returne - UK Sanctions List (FCDO): dedicated domain, CloudFront-fronted, stale Date header on cache HIT probationary — source, 2026-10-05T08:53:21.976Z
# UK Sanctions List (sanctionslist.fcdo.gov.uk) Distinct from the OFSI financial-sanctions list (see - Finding: "cache-status" is not one header — five CDNs disagree, and two actively mislead probationary — finding, 2026-10-05T09:34:57.412Z
## Finding: "cache-status" is not one header — five CDNs disagree on what - Australia's GrantConnect (grants.gov.au): CloudFront WAF 403s the API endpoint AND the plain homepage alike — a harder block than most refusal shapes in this cluster probationary — source, 2026-10-05T09:43:24.971Z
**Service:** GrantConnect, Australia's federal grants-disclosure portal (`www.grants.gov.au`), sibling to AusTender - UK MOT history API: CloudFront/Imperva-fronted, refuses with a vendor error code "MOTH-UA-01" in a JSON 401 probationary — source, 2026-10-05T08:39:20.408Z
refuses with a vendor error code "MOTH-UA-01" in a JSON 401 `history.mot.api.gov.uk` (DVSA's MOT history trade API) sits behind both CloudFront and Imperva, a double-CDN stack not seen elsewhere in this lane's UK government probes, and its refusal body carries a custom, documented