Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed
495 Pages « < 14 15 16 17 18 > » Bottom

Outline · [ Standard ] · Linear+

Unifi Official TM UniFi High Speed Broadband Thread V42, READ 1ST PAGE FOR RELEVANT WIFI INFO!

views
     
Doraku
post Dec 17 2023, 04:39 PM

Old threads digger
******
Senior Member
1,155 posts

Joined: Apr 2016


There is seems like login issues with Bitwarden Android app, a lot reported are from Malaysian with Unifi ISP.
https://community.bitwarden.com/t/login-pro...ndroid/60958/20
Oltromen Ripot
post Dec 17 2023, 04:44 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(Doraku @ Dec 17 2023, 04:39 PM)
There is seems like login issues with Bitwarden Android app, a lot reported are from Malaysian with Unifi ISP.
https://community.bitwarden.com/t/login-pro...ndroid/60958/20
*
oh no, wife and me are using bitwarden.

Doraku
post Dec 17 2023, 08:32 PM

Old threads digger
******
Senior Member
1,155 posts

Joined: Apr 2016


QUOTE(Oltromen Ripot @ Dec 17 2023, 04:44 PM)
oh no, wife and me are using bitwarden.
*
seems like the login issues only affects Android app, no such issues logging on vault.bitwarden.com
zellleonhart
post Dec 17 2023, 10:08 PM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(Doraku @ Dec 17 2023, 04:39 PM)
There is seems like login issues with Bitwarden Android app, a lot reported are from Malaysian with Unifi ISP.
https://community.bitwarden.com/t/login-pro...ndroid/60958/20
*
yes I reported that, people on reddit also facing the same issue with Unifi.

I checked with my adguard home logs, whenever I am connected to wifi and try to login on android, there is not a single request sent to bitwarden. It is like either the app never requested that. But adguard home shows the request when I am on mobile network or VPN.

I have no idea whose fault is this - Unifi, bitwarden, or the app itself. Accessing vault.bitwarden.com on android phone still works, just not the app.
BenYeeHua
post Dec 17 2023, 11:51 PM

Regular
******
Senior Member
1,873 posts

Joined: Nov 2010


QUOTE(zellleonhart @ Dec 17 2023, 10:08 PM)
yes I reported that, people on reddit also facing the same issue with Unifi.

I checked with my adguard home logs, whenever I am connected to wifi and try to login on android, there is not a single request sent to bitwarden. It is like either the app never requested that. But adguard home shows the request when I am on mobile network or VPN.

I have no idea whose fault is this - Unifi, bitwarden, or the app itself. Accessing vault.bitwarden.com on android phone still works, just not the app.
*
Maybe DNS?
If you get no respond from DNS, sure there will be no single request to bitwarden.
kwss
post Dec 18 2023, 02:38 AM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(zellleonhart @ Dec 17 2023, 10:08 PM)
yes I reported that, people on reddit also facing the same issue with Unifi.

I checked with my adguard home logs, whenever I am connected to wifi and try to login on android, there is not a single request sent to bitwarden. It is like either the app never requested that. But adguard home shows the request when I am on mobile network or VPN.

I have no idea whose fault is this - Unifi, bitwarden, or the app itself. Accessing vault.bitwarden.com on android phone still works, just not the app.
*
What's the faulty domain name?

I don't have bitwarden so took a blind test with api.bitwarden.com

Unifi fiber, Maxis fiber and Celcom mobile (using Google DNS) resolve to:
2606:4700:4400::6812:28cc
2606:4700:4400::ac40:9334
172.64.147.52
104.18.40.204

However, Unifi fiber goes to Singapore server while Maxis fiber and Celcom mobile goes to Kuala Lumpur server.

Maxis:
CODE

fl=56f102
h=api.bitwarden.com
ip=2001:d08:d6:......
ts=1702837789.938
visit_scheme=https
uag=Mozilla/5.0 (Android 11; Mobile; rv:121.0) Gecko/121.0 Firefox/121.0
colo=KUL
sliver=none
http=http/2
loc=MY
tls=TLSv1.3
sni=plaintext
warp=off
gateway=off
rbi=off
kex=X25519


Unifi:
CODE

l=632f100
h=api.bitwarden.com
ip=2001:e68:5427:......
ts=1702837500.22
visit_scheme=https
uag=Wget/1.21.3
colo=SIN
sliver=none
http=http/1.1
loc=MY
tls=TLSv1.3
sni=plaintext
warp=off
gateway=off
rbi=off
kex=X25519


Celcom:
CODE

l=496f6
h=api.bitwarden.com
ip=2404:160:8172:......
ts=1702838555.439
visit_scheme=https
uag=Mozilla/5.0 (Android 11; Mobile; rv:121.0) Gecko/121.0 Firefox/121.0
colo=KUL
sliver=none
http=http/2
loc=MY
tls=TLSv1.3
sni=plaintext
warp=off
gateway=off
rbi=off
kex=X25519


My guess is Cloudflare problem. Maybe you need to pass this info to Bitwarden support for further escalation.

EDIT: Tested all the application endpoints listed here with same result:
https://bitwarden.com/help/bitwarden-addresses/

Definitely a Cloudflare issue. Or at least between Cloudflare and Bitwarden server

This post has been edited by kwss: Dec 18 2023, 03:12 AM
BenYeeHua
post Dec 18 2023, 07:59 AM

Regular
******
Senior Member
1,873 posts

Joined: Nov 2010


QUOTE(kwss @ Dec 18 2023, 02:38 AM)
What's the faulty domain name?

I don't have bitwarden so took a blind test with api.bitwarden.com

» Click to show Spoiler - click again to hide... «

Definitely a Cloudflare issue. Or at least between Cloudflare and Bitwarden server
*
Just test for fun.

It might be request the server list data from in.appcenter.ms, so there is some misconfiguration on Microsoft side.
If you connect directly, there is no server loaded, only bitwarden.com available, and no connection made to vault.bitwarde.com.


But...
If you use a VPN(I tested using 1.1.1.1 WARP, on KUL and on SG), it will success on receiving correct data from in.appcenter.ms.

By testing without clear data.
First, it request you to select "Self-hosted" at "logging in on", then saved it, there will be new server bitwarden.eu shown as second choice.
Then, it will success for connecting to vault.bitwarden.com, or vault.bitwarden.eu if you select .eu server.

And, if you reset app(clear data) with VPN enabled, the server list will be requested successful, and showing 2 server which is .com and .eu.
---
So, conclusion, someone at bitwarden fxxked up their server configuration list, and give the wrong server list + configuration to TM/UniFi IP range.
Or
Someone at Microsoft la.

I will said, complain to bitwarden to speed up the fixing. tongue.gif
BenYeeHua
post Dec 18 2023, 08:13 AM

Regular
******
Senior Member
1,873 posts

Joined: Nov 2010


And correction to my part, so it seem like there is some skip over DNS that I failed to capture, maybe DNS caching happen on my Android phone, lol.

So I find the f-droid version which removed Microsoft appcenter.

https://github.com/bitwarden/mobile/issues/1828

And confirmed it will request the server list from vault.bitwarden.com.
And yes, same issues, the server list will be failed to request.

If I keep looking into github for bitwarden's source code, I sure gonna find which API they are looking to fetch the server list.
But, nah, better keep complain to bitwarden la, lol. laugh.gif
kwss
post Dec 18 2023, 08:37 AM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(BenYeeHua @ Dec 18 2023, 07:59 AM)
Just test for fun.

It might be request the server list data from in.appcenter.ms, so there is some misconfiguration on Microsoft side.
If you connect directly, there is no server loaded, only bitwarden.com available, and no connection made to vault.bitwarde.com.
But...
If you use a VPN(I tested using 1.1.1.1 WARP, on KUL and on SG), it will success on receiving correct data from in.appcenter.ms.

By testing without clear data.
First, it request you to select "Self-hosted" at "logging in on", then saved it, there will be new server bitwarden.eu shown as second choice.
Then, it will success for connecting to vault.bitwarden.com, or vault.bitwarden.eu if you select .eu server.

And, if you reset app(clear data) with VPN enabled, the server list will be requested successful, and showing 2 server which is .com and .eu.
---
So, conclusion, someone at bitwarden fxxked up their server configuration list, and give the wrong server list + configuration to TM/UniFi IP range.
Or
Someone at Microsoft la.

I will said, complain to bitwarden to speed up the fixing. tongue.gif
*
I didn't install the app and test, so I just blindly find some domain and hit it.
If you mitmproxy the app then I trust your analysis is correct.

BTW can I have the endpoint and perhaps the full GET or POST request? I just want to test it.
None of the listed endpoint in the "Bitwarden Addresses" belongs to Microsoft. However I noted func.bitwarden.com indeed is an Azure Function.

It is weird to have an endpoint reply differently based on IP address or telco.
BenYeeHua
post Dec 18 2023, 08:44 AM

Regular
******
Senior Member
1,873 posts

Joined: Nov 2010


After retest a few time, confirmed it should be cloudflare or bitwarden side issues, because I tried to changing the CloudFlare IP address by modifying the host file, still the same result.

So there is special result given to TM/UniFi customer IP address la...

QUOTE(kwss @ Dec 18 2023, 08:37 AM)
I didn't install the app and test, so I just blindly find some domain and hit it.
If you mitmproxy the app then I trust your analysis is correct.

BTW can I have the endpoint and perhaps the full GET or POST request? I just want to test it.
None of the listed endpoint in the "Bitwarden Addresses" belongs to Microsoft. However I noted func.bitwarden.com indeed is an Azure Function.

It is weird to have an endpoint reply differently based on IP address or telco.
*
As above, it still requesting the list of server configuration from vault.bitwarden.com or vault.bitwarden.eu.
For the which get or post request it is asking from, I kind of lazy on performing MiTM the request, lol...

Anyways, if you interesting on looking the source code, here it is.

https://github.com/bitwarden/mobile/pull/2454
https://github.com/bitwarden/mobile/blob/ma...nmentService.cs
https://github.com/bitwarden/mobile/blob/ma...nmentUrlData.cs

Still seeking which one is for the requesting server list, lol.
I wonder why they setup different API than the website version, which is https://vault.bitwarden.com/api/config

A bit tired to looking forward, as I not sleep yet. laugh.gif
kwss
post Dec 18 2023, 08:50 AM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(BenYeeHua @ Dec 18 2023, 08:44 AM)
After retest a few time, confirmed it should be cloudflare or bitwarden side issues, because I tried to changing the CloudFlare IP address by modifying the host file, still the same result.

So there is special result given to TM/UniFi customer IP address la...
As above, it still requesting the list of server configuration from vault.bitwarden.com or vault.bitwarden.eu.
For the which get or post request it is asking from, I kind of lazy on performing MiTM the request, lol...

Anyways, if you interesting on looking the source code, here it is.

https://github.com/bitwarden/mobile/pull/2454
https://github.com/bitwarden/mobile/blob/ma...nmentService.cs
https://github.com/bitwarden/mobile/blob/ma...nmentUrlData.cs

Still seeking which one is for the requesting server list, lol.
I wonder why they setup different API than the website version, which is https://vault.bitwarden.com/api/config

A bit tired to looking forward, as I not sleep yet. laugh.gif
*
Alright. Then just leave it as it is. Since I don't use it, doesn't affect me. At least confirmed is not telco issue.
Full diagnostic can only happen with mitmproxy. Let that be an exercise for bitwarden user.
gaman
post Dec 18 2023, 08:55 AM

Getting Started
**
Junior Member
86 posts

Joined: Apr 2006
What to do with Unifi? I thought Bitwarden app can be opened even without any internet access at all?

That's not good.

This post has been edited by gaman: Dec 18 2023, 09:50 AM
BenYeeHua
post Dec 18 2023, 09:03 AM

Regular
******
Senior Member
1,873 posts

Joined: Nov 2010


QUOTE(kwss @ Dec 18 2023, 08:50 AM)
Alright. Then just leave it as it is. Since I don't use it, doesn't affect me. At least confirmed is not telco issue.
Full diagnostic can only happen with mitmproxy. Let that be an exercise for bitwarden user.
*
Done a bit with mitmproxy, it is getting as this.

https://vault.bitwarden.eu:443/api/config.

GET /api/config/ HTTP/1.1
Accept: application/json
Device-Type: 0
Bitwarden-Client-Name: mobile
Bitwarden-Client-Version: 2023.12.0
User-Agent: Bitwarden: Mobile/2023.12.0 (Android 10; SDK 29; Model HMA-L29)
Accept-Encoding: identify
Host: bitwarden.eu
Connection: Keep-Alive

Then it is dead silence from cloudflare, until timeout.
But should be the MiTM app got issues la, as it get frozen, lol. laugh.gif
---
Hmm, either MiTM app got issues, or it is the real cause found.
Nothing captured, except request head and empty body. tongue.gif

So cloudflare somehow refuse to answer?
Let me see with VPN.
-
And forgot MiTM is works as VPN lol.
Anyways, should enough data, wget etc with http/1.1 might get the answer out la.

vault.bitwarden.eu seem working, only vault.bitwarden.com got issues, hmm...

As the app got cert pin written, so I kind of failed to intercept it la...
---
Yes, if I fill in valut.bitwarden.eu as self-hosted, it works.
Only bitwarden.com down.

And this MiTM not working as it should be lol, lazy to install self-cert then go with fiddler on windows laptop.
Then let it go la, bitwarden issues, lol. tongue.gif

This post has been edited by BenYeeHua: Dec 18 2023, 09:15 AM
BenYeeHua
post Dec 18 2023, 09:19 AM

Regular
******
Senior Member
1,873 posts

Joined: Nov 2010


Done, with the power of, FIREFOX!!!!!

Someone was DDoS with TM/UniFi IP range of address, with the stupid of HTTP/1.1
So CloudFlare blocked TM/UniFi IP range with the power of, well, "Checking if the site connection is secure"

Solved, bitwarden is stupid one by requesting with old HTTP/1.1, and not supporting the blocking of CloudFlare, lol.

user posted image
user posted image
user posted image
BenYeeHua
post Dec 18 2023, 09:21 AM

Regular
******
Senior Member
1,873 posts

Joined: Nov 2010


QUOTE(kwss @ Dec 18 2023, 08:50 AM)
Alright. Then just leave it as it is. Since I don't use it, doesn't affect me. At least confirmed is not telco issue.
Full diagnostic can only happen with mitmproxy. Let that be an exercise for bitwarden user.
*
Result out, simple, blocked of cloudflare with request of HTTP/1.1, someone must be brute force with bot/zombie/infected computer running on TM IP range, lol. laugh.gif

And app failed to handle the blocking of cloudflare, double lol.
While app requesting with HTTP/1.1 or app's UA, triple lol!!!
(As that mitm app got issues, it might forcing downgrade the app's connection to HTTP/1.1 for capturing, based on my Tachiyomi skill, CloudFlare partial block based on UA)

In the end, lol!!! rclxms.gif
---
Also extra, it is same blocking happen on IPv4 and/or IPv6, as long as it is under TM la. laugh.gif

This post has been edited by BenYeeHua: Dec 18 2023, 09:25 AM
kwss
post Dec 18 2023, 09:25 AM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(BenYeeHua @ Dec 18 2023, 09:21 AM)
Result out, simple, blocked of cloudflare with request of HTTP/1.1, someone must be brute force with bot/zombie/infected computer running on TM IP range, lol. laugh.gif

And app failed to handle the blocking of cloudflare, double lol.
While app requesting with HTTP/1.1, triple lol!!!

In the end, lol!!! rclxms.gif
---
Also extra, it is same blocking happen on IPv4 and/or IPv6, as long as it is under TM la. laugh.gif
*
MMM.... I cannot reproduce this problem...
I am on public IP... Those with problem, are you all behind CGNAT?

wget indeed fail on .com but not the .eu... 403.
My Firefox however works beautifully

This post has been edited by kwss: Dec 18 2023, 09:26 AM
BenYeeHua
post Dec 18 2023, 09:27 AM

Regular
******
Senior Member
1,873 posts

Joined: Nov 2010


QUOTE(kwss @ Dec 18 2023, 09:25 AM)
MMM.... I cannot reproduce this problem...
I am on public IP... Those with problem, are you all behind CGNAT?
*
Yes, 60.53.x.x.

Can be me testing too much and get blocked, possible, but I was testing on my phone, which is under different IPv6 address, hmm.... hmm.gif
Did cloudflare block whole IPv6 range that assigned to each TM customer?
---
Retested again, Firefox

Disabled HTTP2 and HTTP3, only HTTP/1.1 get blocked by CloudFlare
Reenabled HTTP2 and/or HTTP3, solved this issues.

Might better look into the source code of this bitwarden app, see did it support HTTP2/HTTP3 or not? hmm.gif

This post has been edited by BenYeeHua: Dec 18 2023, 09:29 AM
kwss
post Dec 18 2023, 09:30 AM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(BenYeeHua @ Dec 18 2023, 09:27 AM)
Yes, 60.53.x.x.

Can be me testing too much and get blocked, possible, but I was testing on my phone, which is under different IPv6 address, hmm.... hmm.gif
Did cloudflare block whole IPv6 range that assigned to each TM customer?
*
I wget with -4 and -6... Both got 403. So yes looks like the whole 2001:e68/32 is blocked.
BenYeeHua
post Dec 18 2023, 09:34 AM

Regular
******
Senior Member
1,873 posts

Joined: Nov 2010


QUOTE(kwss @ Dec 18 2023, 09:30 AM)
I wget with -4 and -6... Both got 403. So yes looks like the whole 2001:e68/32 is blocked.
*
Then it is kind of bitwarden's app issues la, even my comic reader app Tachiyomi know to inform me it get blocked by CloudFlare, and asking me to passing the test by opening website via WebView... doh.gif

Who the hell still using HTTP/1.1 at year 2023, aiyo...

Conclusion, bitwarden(at least Android version) is a lazy developer product, it is better to skip using it, as it seem like iOS app out of this issues... hmm.gif
---
QUOTE
Is this to mean you're using Cloudflare's CAPTCHA/bot detection on the API? If this is the case, that will cause many things to break as Cloudflare cannot natively handle API traffic with a CAPTCHA as it will respond with HTML or a JS response, which breaks the Bitwarden client. You would need to contain or custom-filter based on /path in Cloudflare's more advanced configuration to separate the API from the web vault SPA itself.

https://github.com/bitwarden/mobile/issues/...mment-975740275

QUOTE
@atjbramley I was able to debug the issue. The problem is that, when logging in, instead of getting the response, the extension (or android app, or desktop app) gets the Cloudflare "Verify that you are human" screen, and the request, of course, fails since it gets a different stuff than expected.
I'd say this is a problem in the relationship frontend - backend, not a customer support issue.

https://github.com/bitwarden/mobile/issues/...ment-1823211981

Kind of reminding me that app showing tips of "Network issues" when it is server caboom, lol. laugh.gif

This post has been edited by BenYeeHua: Dec 18 2023, 09:41 AM
kwss
post Dec 18 2023, 09:41 AM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(BenYeeHua @ Dec 18 2023, 09:34 AM)
Then it is kind of bitwarden's app issues la, even my comic reader app Tachiyomi know to inform me it get blocked by CloudFlare, and asking me to passing the test by opening website via WebView... doh.gif

Who the hell still using HTTP/1.1 at year 2023, aiyo...

Conclusion, bitwarden(at least Android version) is a lazy developer product, it is better to skip using it, as it seem like iOS app out of this issues... hmm.gif
*
curl which has http2 support indeed success...
So its a combination of factor:
1. The Xamarin used by the Android app (explains why Apple iOS and browser works)
2. Cloudflare DDoS protection is trigger for TM with HTTP/1.1

Why Cloudflare only kills HTTP/1.1 on TM prefix is a mystery. Supposedly if there is an attack, IPv6 should still works since its not NAT.
But seems like they kill the whole AS4788.

495 Pages « < 14 15 16 17 18 > » Top
Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0176sec    0.21    6 queries    GZIP Disabled
Time is now: 29th November 2025 - 04:35 AM