Bad Request - Bad bot, go away! Request aborted.

Bug #1413665 reported by Mark A Davis
208
This bug affects 41 people
Affects Status Importance Assigned to Milestone
Canonical SSO provider
Fix Released
High
Natalia Bidart
Ubuntu Software Center
Invalid
Critical
Matias Bordese
software-center (Ubuntu)
Invalid
Critical
Unassigned

Bug Description

I'm running Ubuntu 14.04 LTS Trusty Tahr. When trying to 'Buy' through Software Center, I'm receiving an error message "Bad Request - Bad bot, go away! Request aborted." This just started happening yesterday, 01/21/2015,

Related branches

Revision history for this message
Mark A Davis (mark-davis-4) wrote :
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in software-center (Ubuntu):
status: New → Confirmed
Revision history for this message
Portaro (joaoteixeira1984) wrote :

I also have this same problem and I have 14.04. if I use terminal to launch the software-center I see this message when I try to install a new package :

$ ... Message: console message: https://login.ubuntu.com/pt/+openid @mynumber: SyntaxError: Unexpected token ','

Maybe is a problem caused by Ubuntu One (recent changes) .

Thanks.

Revision history for this message
Michael (michaelu1220) wrote :

Same problem here, Ubuntu 13.04

Revision history for this message
cbcymru (christonteg) wrote :

I am running Xubuntu 14.04.1 LTS. When trying to 'Buy' through the Ubuntu Software Centre I also receive the error message "Bad Request - Bad bot, go away! Request aborted". I first noticed this problem on Sunday 25 January 2015.

Please post when the problem has been resolved.

Michael (michaelu1220)
Changed in software-center:
status: New → Confirmed
Revision history for this message
Randy Schack (randy-schack) wrote :

Also happens on new install of 12.04 running on ASUS DSBV-DX. First noticed Monday Jan 26 2015 when attempting to install Plex Media Server

Martin Albisetti (beuno)
Changed in software-center (Ubuntu):
status: Confirmed → Triaged
importance: Undecided → Critical
Changed in software-center:
status: Confirmed → Triaged
importance: Undecided → Critical
assignee: nobody → Matias Bordese (matiasb)
Changed in canonical-identity-provider:
status: New → In Progress
assignee: nobody → Natalia Bidart (nataliabidart)
importance: Undecided → High
Changed in software-center:
status: Triaged → Invalid
Changed in software-center (Ubuntu):
status: Triaged → Invalid
Changed in canonical-identity-provider:
status: In Progress → Fix Committed
Revision history for this message
Christian (netbuk) wrote :

Same problem on my Ubuntu 14.04.

Revision history for this message
judejude (judi-deniel) wrote :

Bad bot, go away! Request aborted
same here on fresh install 14.04 32b

Revision history for this message
Vakem (vakem) wrote :

I am still getting the message when trying to "buy" a software i already bought on a newly installed system.

Revision history for this message
Horigo (ludo-surfer) wrote :

Same problem here on a fresh xubuntu. I cant install steam.

Revision history for this message
todias (toze-vdias) wrote :

same problem with me (14.04.1), it worked fine the last time i used it (a month ago).

Revision history for this message
Ananth S (response) wrote :

same problem with me 14.04 32 bit

Revision history for this message
macless (kack) wrote :

Hey I fixed it! This bug did affect my system too. I'm running Ubuntu 14.04 LTS. I was trying things like de-installing and installing the software center. I tried different software center apps. Of course I did log out and in and was creating even a new account. Nothing worked. By accident I discovered the solution:
Just go to the File menu at the software center and choose to re-install already purchased software. Then it asked again for my login data (althought I was already logged in). Entered my data and i was able to choose from my allready purchased apps. I didn't install any of these. I was directly going to All Software tab, searched for a purchasable software and clicked on buy. Usually here was the Bad Robot-message appearing. But this time it asked again for my login data. I entered them again and voila: Everything was working again! I was able to buy and install the app!

Hope this works for you others too!!

Andy

Revision history for this message
Natalia Bidart (nataliabidart) wrote :

Hello all!

Sorry for not mentioning this sooner, but we deployed the fix to the Single Sign On service (where the problem was) last week, so everyone should be able to purchase apps via the software center.

Thanks to everyone involved.

Changed in canonical-identity-provider:
status: Fix Committed → Fix Released
Revision history for this message
reliable-robin-22 (nicolasdiogo) wrote :

REALLY!!!

i can no longer login into UBUNTU FORUMS due to over the top security?

and yet ... i can post here!

go figure.

Revision history for this message
Natalia Bidart (nataliabidart) wrote :

Hello Nicolas,

The improvements to security we applied should not interfere with logging to ubuntu forums, at all.

Could you please file a new bug and share the number here, so we track that issue separately?

Thanks.

Revision history for this message
Pavel (spvkgn) wrote :

I have the same issue - can't login with UbuntuOne on 12.04 LTS on this page https://launchpad.net/people/+me/+editpgpkeys

Login to ubuntuforums also not able.

Here is the message:

Bad Request

Bad bot, go away! Request aborted.

Revision history for this message
Ricardo Kirkner (ricardokirkner) wrote : Re: [Bug 1413665] Re: Bad Request - Bad bot, go away! Request aborted.

Hi,

can you provide more details?

- What browser are you using?
- What browser extensions do you have installed?
- Do you have JavaScript disabled?

thanks

On Sun, Apr 26, 2015 at 6:00 AM, pavel <email address hidden> wrote:
> I have the same issue - can't login with UbuntuOne on 12.04 LTS on this
> page https://launchpad.net/people/+me/+editpgpkeys
>
> Login to ubuntuforums also not able.
>
> Here is the message:
>
> Bad Request
>
> Bad bot, go away! Request aborted.
>
> --
> You received this bug notification because you are a member of Canonical
> ISD hackers, which is subscribed to Canonical SSO provider.
> https://bugs.launchpad.net/bugs/1413665
>
> Title:
> Bad Request - Bad bot, go away! Request aborted.
>
> To manage notifications about this bug go to:
> https://bugs.launchpad.net/canonical-identity-provider/+bug/1413665/+subscriptions

Revision history for this message
John Rose (johnaaronrose) wrote :

Same here with Trusty 64 bit fully up to date. Using Firefox 37.0.2. I've disabled all browser extensions but still occurs. JavaScript is not disabled.
PS I'm using Chromium browser to do successful SSO on same PC & posting this message using Chromium.

Revision history for this message
Pavel (spvkgn) wrote :

This occurs using Firefox 36, in Safe mode with JS enabled.

Revision history for this message
ruru (ruru) wrote :

Also occurs for me using Firefox 38.0.1 on OS X with JS enabled. Attempts to reset Ubuntu One password meet with the 'bad bot' response.
Works from Safari.

Revision history for this message
Matthias Baur (matthiasbaur) wrote :

Same here on Ubuntu 14.04 on Firefox 38.08. Works on Chromium 41.0.2272.76, though.

Revision history for this message
McPeter (mcpeter) wrote :

Ubuntu 14.04.2 on firefox 38.0 don't work

Revision history for this message
Natalia Bidart (nataliabidart) wrote :

Hello all!

I've tested all reported browsers, and they work for me. Please note that the error you are getting with the "Bad bot" means that the form submission process received more fields that those visible to the end user, thus indicating that the form was likely submitted by an automatic script that is filling more fields than what it should.

One more questions to keep debugging further:

* Do you use any password vault extension? LastPass or similar. If so, can you please try removing the SSO entry from there, and login manually in login.ubuntu.com?

Thanks.

Revision history for this message
John Rose (johnaaronrose) wrote : Re: [Bug 1413665] Re: Bad Request - Bad bot, go away! Request aborted.

I'm using the Autofill Forms Firefox addon. So it's possible that that
is filling in the invisible fields. If you tell me the names of the
invisible fields, I'll see if I have preset values for any of them in
the addon.

I don't use LastPass. Since I don't even know what a password vault
extension is, it's unlikely that I'm using one.

John

On 10/06/15 15:15, Natalia Bidart wrote:
> Hello all!
>
> I've tested all reported browsers, and they work for me. Please note
> that the error you are getting with the "Bad bot" means that the form
> submission process received more fields that those visible to the end
> user, thus indicating that the form was likely submitted by an automatic
> script that is filling more fields than what it should.
>
> One more questions to keep debugging further:
>
> * Do you use any password vault extension? LastPass or similar. If so,
> can you please try removing the SSO entry from there, and login manually
> in login.ubuntu.com?
>
> Thanks.
>

Revision history for this message
Natalia Bidart (nataliabidart) wrote :

Hello John!

An extension for autofill will definitely cause this issue, since this measure aims specifically at avoiding non-human filling out the form.

Could you please remove the extension and retry? Or ensure the extension do not fill anything automatically for login.ubuntu.com? (the same mechanism for avoiding bots is present in every form).

Let me know how that goes.
Thanks, Natalia.

Revision history for this message
John Rose (johnaaronrose) wrote :

Natalia,

Sorry for delay in replying due to not receiving an email about your reply. I've tried removing Autofill but it made no difference.

Revision history for this message
Marc De Spiegeleer (mdespiegeleer) wrote :

For me the problem is clearly related to LastPass, as I have to log out from LastPass if I want to log in ubuntu1 (and that is boring).

Changed in canonical-identity-provider:
status: Fix Released → Fix Committed
Revision history for this message
Natalia Bidart (nataliabidart) wrote :

We did some more debugging based on reports we had in the support line.

Apparently Firefox's feature for autocompleting forms and password autofill mess with our bot checks in the reset password flow.
We have applied and published a fix for this specific issue, closing the bug as fix released again.

If anyone come across this issue again, please state:

* Browser and version
* Plugin list
* Steps to reproduce

Thank you!

Changed in canonical-identity-provider:
status: Fix Committed → Fix Released
Revision history for this message
Marc De Spiegeleer (mdespiegeleer) wrote :

On my side the problem is fixed. Thank you.

Revision history for this message
Pasi Koistinen (pasi-u) wrote :

I have the same problem.
Client: Mac OSX + Chrome Version 48.0.2564.97 (64-bit)

When I try to login with my browser to https://login.ubuntu.com/+login and enter username + password I also get this bad bot nag.

In my case I'm using Dashlane which prefills my email address and also password, if I want to. The problem is, I've got about a thousand passwords stored there and I'm pretty sure I'm not going to remove the browser password plugin for some single login purpose.

So if you've included a hidden field that fools valid security tools such as secure passwd managers to malfunction, please fix the issue.

Revision history for this message
Aurel Branzeanu (thunder-riscom) wrote :

The problem is not fixed.

* Firefox 45.0.2 on Ubuntu 16.04 x64
* KeeFox 1.6.1b1 plugin

KeeFox has the options either to just auto-fill the form, or to submit it after auto-fill.
In either case I got "Bad Request - Bad bot, go away! Request aborted."

Only turning off completely auto-fill and submit make the log in possible.

Revision history for this message
Aaron Whitehouse (aaron-whitehouse) wrote :

Yes, not fixed for me either.

* Ubuntu 16.04 x64
* Firefox 47.0
* Keefox 1.6.0

Trying to log into help.ubuntu.com, I get the
"
Bad Request

Bad bot, go away! Request aborted.
"
message.

Revision history for this message
peterdv (peter-dahl-vestergaard) wrote :

Keefox+Firefox fails,
Keefox+Chromium (53.0.2785.143-0ubuntu0.16.04.1.1254) works.

Revision history for this message
hackel (hackel) wrote :

STILL experiencing this problem.

Revision history for this message
hackel (hackel) wrote :

FYI — To "fix" this obnoxious issue in order to use KeeFox, you need to tell it to use the "email" field instead of "openid.usernamesecret" for the username. You can do this by editing the entry in KeePass, going to the KeeFox tab, form fields, and edit the "{USERNAME}" form field, changing the name to "email" (the default is blank).

Revision history for this message
Dale C. Anderson (dale-c-anderson) wrote :

It seems any password auto filler gets fooled by the honeypot on the page and results in the error.

The irony is that in order to comment or mark "it affects me", you have to get past the very form that's causing the problem. I suspect this affects a lot more people than is indicated.

Revision history for this message
Daniel Manrique (roadmr) wrote :

Wrong - not "any" password auto filler is fooled, I use Lastpass and it works just fine.

Dale, are you by chance using Chrome/Chromium with the browser's built-in password auto-filler? Let me know.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.