ticket_tracker_api icon indicating copy to clipboard operation
ticket_tracker_api copied to clipboard

Reese84 code stopped working

Open missvchen opened this issue 1 year ago • 21 comments

Hi,

It seems that TM implemented a new anti-bot mechanism as of Aug 1. The reese84 tokens are being generated but they are invalid. HTTP calls with the generated tokens result in 403 forbidden.

Thanks

missvchen avatar Aug 02 '23 16:08 missvchen

@Jackiebibili FYI

missvchen avatar Aug 02 '23 20:08 missvchen

That's right, I see the same "403 forbidden" on each request, regardless IP, proxy, country.

smokesmoke avatar Aug 02 '23 20:08 smokesmoke

We will try to get it fixed within the next one or two months.

cc: @Jackiebibili

FrankQixiangGao avatar Aug 02 '23 23:08 FrankQixiangGao

Hi @FrankQixiangGao @Jackiebibili any update for this?

alanting850420 avatar Aug 07 '23 09:08 alanting850420

Is there any temporary solution to get the reese84 token?

Hassan4243884 avatar Aug 07 '23 12:08 Hassan4243884

@Jackiebibili @FrankQixiangGao I'm almost sure the only change was in reese84 generation algo. I have a token from my old tests, it should be at least couple of months old, but it's still working if I manually feed that token. The same way it's working if I grab a fresh token from the browser and feed it manually to the script.

smokesmoke avatar Aug 10 '23 03:08 smokesmoke

I don't know what's wrong, Sometimes It works, and sometimes It does't work.

Hassan4243884 avatar Aug 13 '23 16:08 Hassan4243884

Hello! Has this issue been resolved?

TimBeggs avatar Sep 26 '23 14:09 TimBeggs

No yet, unfortunately.

smokesmoke avatar Sep 26 '23 17:09 smokesmoke

No yet, unfortunately.

I was sick last week. I tried to investigate into the new logic Ticketmaster has implemented, and currently there is no luck from me. Some interesting findings worth mentioning: the p value in the interrogation object is now actively dynamic; The p value's length varies significantly from 27k to 120k in characters. The Ticketmaster backend for token generation gives a token but cannot be used in api calls (403 forbidden).

Jackiebibili avatar Sep 26 '23 18:09 Jackiebibili

No yet, unfortunately.

I was sick last week. I tried to investigate into the new logic Ticketmaster has implemented, and currently there is no luck from me. Some interesting findings worth mentioning: the p value in the interrogation object is now actively dynamic; The p value's length varies significantly from 27k to 120k in characters. The Ticketmaster backend for token generation gives a token but cannot be used in api calls (403 forbidden).

My findings are: There are some paid services out there that require only Javascript file URL for reese84. In Ticketmaster's case it's https://epsf.ticketmaster.com/eps-d?d=www.ticketmaster.com and these services return a valid payload. The one I've tested is https://clearcaptcha.gitbook.io/clearcaptcha-api/incapsula/incapsula-reese84-data-subscription-version This means there's a way of generating a valid payload just having and using the Javascript file. But unfortunately I couldn't make it work myself.

smokesmoke avatar Sep 26 '23 19:09 smokesmoke

any updates on this?

SeanNFT avatar Oct 08 '23 18:10 SeanNFT

Any update on this @smokesmoke @Jackiebibili ? Cheers

washedimg avatar Feb 12 '24 09:02 washedimg

@smokesmoke maybe this is a dumb question, but how can you have a reese token working from months ago? Don't they expire in like 10-20min? Can't you just abuse that working token for many requests? I guess it's IP-locked?

washedimg avatar Feb 12 '24 11:02 washedimg

@washedimg, They aren't iplocked as such, but def dont last for months, that doesn't sound right...

spikeruk avatar Mar 03 '24 20:03 spikeruk

Abandoned?

danofun avatar Aug 19 '24 11:08 danofun

any updates on this?

gilrodar avatar Sep 18 '24 23:09 gilrodar

Worked on this for many months and also reverse engineered their add to cart api successfully. For the Reese token, I found it easy enough to use a third party api harvester (for low quantity polling), or just create a frontend token fetcher. If anyone needs help on this or wishes to purchase an add to cart module, let me know.

washedimg avatar Oct 01 '24 18:10 washedimg

I have a working solution for reese84 at affordable rate. Feel free to contact me to discuss further. https://github.com/ganhj99/imperva-reese84-api

ganhj99 avatar Oct 01 '24 19:10 ganhj99

Are you selling the code for working solution to generate valid payloads? Or you are selling token generation service?

washedimg avatar Oct 01 '24 19:10 washedimg

Both are available.

ganhj99 avatar Oct 01 '24 19:10 ganhj99