Bad Request - Bad bot, go away! Request aborted.
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| | Canonical SSO provider |
High
|
Natalia Bidart | ||
| | Ubuntu Software Center |
Invalid
|
Critical
|
Matias Bordese | |
| | software-center (Ubuntu) |
Critical
|
Unassigned | ||
Bug Description
I'm running Ubuntu 14.04 LTS Trusty Tahr. When trying to 'Buy' through Software Center, I'm receiving an error message "Bad Request - Bad bot, go away! Request aborted." This just started happening yesterday, 01/21/2015,
Related branches
- Łukasz Czyżykowski (community): Approve on 2015-01-28
-
Diff: 84 lines (+32/-14)2 files modifiedsrc/identityprovider/middleware/honeypot.py (+2/-1)
src/identityprovider/tests/test_middleware.py (+30/-13)
- Matt Goodall (community): Approve on 2015-11-04
-
Diff: 12 lines (+1/-1)1 file modifieddjango_project/settings_base.py (+1/-1)
| Mark A Davis (mark-davis-4) wrote : | #1 |
| Portaro (joaoteixeira1984) wrote : | #3 |
I also have this same problem and I have 14.04. if I use terminal to launch the software-center I see this message when I try to install a new package :
$ ... Message: console message: https:/
Maybe is a problem caused by Ubuntu One (recent changes) .
Thanks.
| Michael (michaelu1220) wrote : | #4 |
Same problem here, Ubuntu 13.04
| cbcymru (christonteg) wrote : | #5 |
I am running Xubuntu 14.04.1 LTS. When trying to 'Buy' through the Ubuntu Software Centre I also receive the error message "Bad Request - Bad bot, go away! Request aborted". I first noticed this problem on Sunday 25 January 2015.
Please post when the problem has been resolved.
| Changed in software-center: | |
| status: | New → Confirmed |
| Randy Schack (randy-schack) wrote : | #6 |
Also happens on new install of 12.04 running on ASUS DSBV-DX. First noticed Monday Jan 26 2015 when attempting to install Plex Media Server
| Changed in software-center (Ubuntu): | |
| status: | Confirmed → Triaged |
| importance: | Undecided → Critical |
| Changed in software-center: | |
| status: | Confirmed → Triaged |
| importance: | Undecided → Critical |
| assignee: | nobody → Matias Bordese (matiasb) |
| Changed in canonical-identity-provider: | |
| status: | New → In Progress |
| assignee: | nobody → Natalia Bidart (nataliabidart) |
| importance: | Undecided → High |
| Changed in software-center: | |
| status: | Triaged → Invalid |
| Changed in software-center (Ubuntu): | |
| status: | Triaged → Invalid |
| Changed in canonical-identity-provider: | |
| status: | In Progress → Fix Committed |
| Christian (netbuk) wrote : | #7 |
Same problem on my Ubuntu 14.04.
| judejude (judi-deniel) wrote : | #8 |
Bad bot, go away! Request aborted
same here on fresh install 14.04 32b
| Vakem (vakem) wrote : | #9 |
I am still getting the message when trying to "buy" a software i already bought on a newly installed system.
| Horigo (ludo-surfer) wrote : | #10 |
Same problem here on a fresh xubuntu. I cant install steam.
| todias (toze-vdias) wrote : | #11 |
same problem with me (14.04.1), it worked fine the last time i used it (a month ago).
| Ananth S (response) wrote : | #12 |
same problem with me 14.04 32 bit
| macless (kack) wrote : | #13 |
Hey I fixed it! This bug did affect my system too. I'm running Ubuntu 14.04 LTS. I was trying things like de-installing and installing the software center. I tried different software center apps. Of course I did log out and in and was creating even a new account. Nothing worked. By accident I discovered the solution:
Just go to the File menu at the software center and choose to re-install already purchased software. Then it asked again for my login data (althought I was already logged in). Entered my data and i was able to choose from my allready purchased apps. I didn't install any of these. I was directly going to All Software tab, searched for a purchasable software and clicked on buy. Usually here was the Bad Robot-message appearing. But this time it asked again for my login data. I entered them again and voila: Everything was working again! I was able to buy and install the app!
Hope this works for you others too!!
Andy
| Natalia Bidart (nataliabidart) wrote : | #14 |
Hello all!
Sorry for not mentioning this sooner, but we deployed the fix to the Single Sign On service (where the problem was) last week, so everyone should be able to purchase apps via the software center.
Thanks to everyone involved.
| Changed in canonical-identity-provider: | |
| status: | Fix Committed → Fix Released |
| Nicolas Diogo (nicolasdiogo) wrote : | #15 |
REALLY!!!
i can no longer login into UBUNTU FORUMS due to over the top security?
and yet ... i can post here!
go figure.
| Natalia Bidart (nataliabidart) wrote : | #16 |
Hello Nicolas,
The improvements to security we applied should not interfere with logging to ubuntu forums, at all.
Could you please file a new bug and share the number here, so we track that issue separately?
Thanks.
| pavel (spvkgn) wrote : | #17 |
I have the same issue - can't login with UbuntuOne on 12.04 LTS on this page https:/
Login to ubuntuforums also not able.
Here is the message:
Bad Request
Bad bot, go away! Request aborted.
| Ricardo Kirkner (ricardokirkner) wrote : Re: [Bug 1413665] Re: Bad Request - Bad bot, go away! Request aborted. | #18 |
Hi,
can you provide more details?
- What browser are you using?
- What browser extensions do you have installed?
- Do you have JavaScript disabled?
thanks
On Sun, Apr 26, 2015 at 6:00 AM, pavel <email address hidden> wrote:
> I have the same issue - can't login with UbuntuOne on 12.04 LTS on this
> page https:/
>
> Login to ubuntuforums also not able.
>
> Here is the message:
>
> Bad Request
>
> Bad bot, go away! Request aborted.
>
> --
> You received this bug notification because you are a member of Canonical
> ISD hackers, which is subscribed to Canonical SSO provider.
> https:/
>
> Title:
> Bad Request - Bad bot, go away! Request aborted.
>
> To manage notifications about this bug go to:
> https:/
| John Rose (johnaaronrose) wrote : | #19 |
Same here with Trusty 64 bit fully up to date. Using Firefox 37.0.2. I've disabled all browser extensions but still occurs. JavaScript is not disabled.
PS I'm using Chromium browser to do successful SSO on same PC & posting this message using Chromium.
| pavel (spvkgn) wrote : | #20 |
This occurs using Firefox 36, in Safe mode with JS enabled.
| ruru (ruru) wrote : | #21 |
Also occurs for me using Firefox 38.0.1 on OS X with JS enabled. Attempts to reset Ubuntu One password meet with the 'bad bot' response.
Works from Safari.
| Matthias Baur (matthiasbaur) wrote : | #22 |
Same here on Ubuntu 14.04 on Firefox 38.08. Works on Chromium 41.0.2272.76, though.
| McPeter (mcpeter) wrote : | #23 |
Ubuntu 14.04.2 on firefox 38.0 don't work
| Natalia Bidart (nataliabidart) wrote : | #24 |
Hello all!
I've tested all reported browsers, and they work for me. Please note that the error you are getting with the "Bad bot" means that the form submission process received more fields that those visible to the end user, thus indicating that the form was likely submitted by an automatic script that is filling more fields than what it should.
One more questions to keep debugging further:
* Do you use any password vault extension? LastPass or similar. If so, can you please try removing the SSO entry from there, and login manually in login.ubuntu.com?
Thanks.
| John Rose (johnaaronrose) wrote : Re: [Bug 1413665] Re: Bad Request - Bad bot, go away! Request aborted. | #25 |
I'm using the Autofill Forms Firefox addon. So it's possible that that
is filling in the invisible fields. If you tell me the names of the
invisible fields, I'll see if I have preset values for any of them in
the addon.
I don't use LastPass. Since I don't even know what a password vault
extension is, it's unlikely that I'm using one.
John
On 10/06/15 15:15, Natalia Bidart wrote:
> Hello all!
>
> I've tested all reported browsers, and they work for me. Please note
> that the error you are getting with the "Bad bot" means that the form
> submission process received more fields that those visible to the end
> user, thus indicating that the form was likely submitted by an automatic
> script that is filling more fields than what it should.
>
> One more questions to keep debugging further:
>
> * Do you use any password vault extension? LastPass or similar. If so,
> can you please try removing the SSO entry from there, and login manually
> in login.ubuntu.com?
>
> Thanks.
>
| Natalia Bidart (nataliabidart) wrote : | #26 |
Hello John!
An extension for autofill will definitely cause this issue, since this measure aims specifically at avoiding non-human filling out the form.
Could you please remove the extension and retry? Or ensure the extension do not fill anything automatically for login.ubuntu.com? (the same mechanism for avoiding bots is present in every form).
Let me know how that goes.
Thanks, Natalia.
| John Rose (johnaaronrose) wrote : | #27 |
Natalia,
Sorry for delay in replying due to not receiving an email about your reply. I've tried removing Autofill but it made no difference.
For me the problem is clearly related to LastPass, as I have to log out from LastPass if I want to log in ubuntu1 (and that is boring).
| Changed in canonical-identity-provider: | |
| status: | Fix Released → Fix Committed |
| Natalia Bidart (nataliabidart) wrote : | #29 |
We did some more debugging based on reports we had in the support line.
Apparently Firefox's feature for autocompleting forms and password autofill mess with our bot checks in the reset password flow.
We have applied and published a fix for this specific issue, closing the bug as fix released again.
If anyone come across this issue again, please state:
* Browser and version
* Plugin list
* Steps to reproduce
Thank you!
| Changed in canonical-identity-provider: | |
| status: | Fix Committed → Fix Released |
On my side the problem is fixed. Thank you.
| Pasi Koistinen (pasi-u) wrote : | #31 |
I have the same problem.
Client: Mac OSX + Chrome Version 48.0.2564.97 (64-bit)
When I try to login with my browser to https:/
In my case I'm using Dashlane which prefills my email address and also password, if I want to. The problem is, I've got about a thousand passwords stored there and I'm pretty sure I'm not going to remove the browser password plugin for some single login purpose.
So if you've included a hidden field that fools valid security tools such as secure passwd managers to malfunction, please fix the issue.
| Aurel Branzeanu (thunder-riscom) wrote : | #32 |
The problem is not fixed.
* Firefox 45.0.2 on Ubuntu 16.04 x64
* KeeFox 1.6.1b1 plugin
KeeFox has the options either to just auto-fill the form, or to submit it after auto-fill.
In either case I got "Bad Request - Bad bot, go away! Request aborted."
Only turning off completely auto-fill and submit make the log in possible.
Yes, not fixed for me either.
* Ubuntu 16.04 x64
* Firefox 47.0
* Keefox 1.6.0
Trying to log into help.ubuntu.com, I get the
"
Bad Request
Bad bot, go away! Request aborted.
"
message.
| peterdv (peter-dahl-vestergaard) wrote : | #34 |
Keefox+Firefox fails,
Keefox+Chromium (53.0.2785.
| hackel (hackel) wrote : | #35 |
STILL experiencing this problem.
| hackel (hackel) wrote : | #36 |
FYI — To "fix" this obnoxious issue in order to use KeeFox, you need to tell it to use the "email" field instead of "openid.


Status changed to 'Confirmed' because the bug affects multiple users.