Live data from Hacker News

Internet Artifacts

neal.fun

141–143 of 143 posts

Re: Internet Artifacts

#141
post #137

Earlier quoted context omitted.

I visited https://www.spacejam.com/ with Chrome on Windows, Firefox on Windows, and Chrome on Android. It didn't redirect for any of them.

The loop most definitely exists. It's rather odd you're not seeing it. Everything I can use to talk to the server gets the 301/302 redirects. Using yet another machine and curl: curl -vvv --insecure https://spacejam.com 301 Moved Permanently Moved Permanently The document has moved here . ... \* Connection #0 to host www.spacejamanewlegacy.net left intact curl -vvv --insecure www.spacejamanewlegacy.net

Your request to https://spacejam.com is redirected to https://www.spacejam.com/ .

Your request to http://www.spacejamanewlegacy.net is redirected to https://www.spacejamanewlegacy.net/ .

You never tried making a request to https://www.spacejam.com/ .

Go to https://reqbin.com/ and enter https://spacejam.com . It gives 1 redirect (to https://www.spacejam.com/ ) then HTML.

Re: Internet Artifacts

#142
post #137

Earlier quoted context omitted.

The loop most definitely exists. It's rather odd you're not seeing it. Everything I can use to talk to the server gets the 301/302 redirects. Using yet another machine and curl: curl -vvv --insecure https://spacejam.com 301 Moved Permanently Moved Permanently The document has moved here . ... \* Connection #0 to host www.spacejamanewlegacy.net left intact curl -vvv --insecure www.spacejamanewlegacy.net

Your request to https://spacejam.com is redirected to https://www.spacejam.com/ . Your request to http://www.spacejamanewlegacy.net is redirected to https://www.spacejamanewlegacy.net/ . You never tried making a request to https://www.spacejam.com/ . Go to https://reqbin.com/ and enter https://spacejam.com . It gives 1 redirect (to https://www.spacejam.com/ ) then HTML.

I think you missed which servers are connected at the end of which request, there.

Reqbin receives an upgrade request to HTTP2, that it never follows.

Re: Internet Artifacts

#143
post #142

Earlier quoted context omitted.

Your request to https://spacejam.com is redirected to https://www.spacejam.com/ . Your request to http://www.spacejamanewlegacy.net is redirected to https://www.spacejamanewlegacy.net/ . You never tried making a request to https://www.spacejam.com/ . Go to https://reqbin.com/ and enter https://spacejam.com . It gives 1 redirect (to https://www.spacejam.com/ ) then HTML.

I think you missed which servers are connected at the end of which request, there. Reqbin receives an upgrade request to HTTP2, that it never follows.

The curl output you post confuses me. Can you post the full output? The output you posted didn't show a redirect loop. But since you cut out content, maybe there was a redirect loop that I can't see.

Here's my full curl output. No redirect loop:

    curl -vvv --insecure https://spacejam.com
    * Rebuilt URL to: https://spacejam.com/
    *   Trying 75.2.104.223...
    * TCP_NODELAY set
    * Connected to spacejam.com (75.2.104.223) port 443 (#0)
    * ALPN, offering h2
    * ALPN, offering http/1.1
    * Cipher selection: ALL:!EXPORT:!EXPORT40:!EXPORT56:!aNULL:!LOW:!RC4:@STRENGTH
    * successfully set certificate verify locations:
    *   CAfile: /etc/ssl/certs/ca-certificates.crt
      CApath: /etc/ssl/certs
    * TLSv1.2 (OUT), TLS header, Certificate Status (22):
    * TLSv1.2 (OUT), TLS handshake, Client hello (1):
    * TLSv1.2 (IN), TLS handshake, Server hello (2):
    * TLSv1.2 (IN), TLS handshake, Certificate (11):
    * TLSv1.2 (IN), TLS handshake, Server key exchange (12):
    * TLSv1.2 (IN), TLS handshake, Server finished (14):
    * TLSv1.2 (OUT), TLS handshake, Client key exchange (16):
    * TLSv1.2 (OUT), TLS change cipher, Client hello (1):
    * TLSv1.2 (OUT), TLS handshake, Finished (20):
    * TLSv1.2 (IN), TLS change cipher, Client hello (1):
    * TLSv1.2 (IN), TLS handshake, Finished (20):
    * SSL connection using TLSv1.2 / ECDHE-RSA-AES128-GCM-SHA256
    * ALPN, server accepted to use http/1.1
    * Server certificate:
    *  subject: C=US; ST=California; L=Burbank; O=WARNER BROS. ENTERTAINMENT INC.; CN=www.spacejam.com
    *  start date: Jul 15 15:36:27 2024 GMT
    *  expire date: Aug 16 15:36:26 2025 GMT
    *  issuer: C=BE; O=GlobalSign nv-sa; CN=GlobalSign RSA OV SSL CA 2018
    *  SSL certificate verify ok.
    > GET / HTTP/1.1
    > Host: spacejam.com
    > User-Agent: curl/7.52.1
    > Accept: */*
    >
     GET / HTTP/1.1
    > Host: www.spacejam.com
    > User-Agent: curl/7.52.1
    > Accept: */*
    >
    
    
    
            
            
            
            
                    Space Jam: A New Legacy | Official Site 
    ...
    
    * Curl_http_done: called premature == 0
    * Connection #0 to host www.spacejam.com left intact
    


    curl -vvv --insecure www.spacejamanewlegacy.net
    * Rebuilt URL to: www.spacejamanewlegacy.net/
    *   Trying 52.11.38.202...
    * TCP_NODELAY set
    * Connected to www.spacejamanewlegacy.net (52.11.38.202) port 80 (#0)
    > GET / HTTP/1.1
    > Host: www.spacejamanewlegacy.net
    > User-Agent: curl/7.52.1
    > Accept: */*
    >
    
    
    301 Moved Permanently
    
    Moved Permanently
    

The document has moved here.

* Curl_http_done: called premature == 0 * Connection #0 to host www.spacejamanewlegacy.net left intact
>Reqbin receives an upgrade request to HTTP2, that it never follows.

You mean Reqbin receives a response with an Upgrade: h2,h2c header? That's not exactly a request to upgrade. That's the server advertising that it supports those protocols for upgrading. The client is free to ignore them. Also, h2 is actually an invalid upgrade protocol, not listed in the standard:

https://www.iana.org/assignments/http-upgrade-tokens/http-up...

https://stackoverflow.com/questions/67583138/why-does-the-ht...

According to that SO post, Apache advertises Upgrade: h2, h2c in its responses, but if the client attempts to upgrade to h2, Apache ignores it. So I believe Reqbin is doing the correct thing in not upgrading to h2. As for upgrading to h2c, that also wouldn't be possible, because that header was sent in response to an https:// request, but h2c only makes sense when upgrading from an http:// request.

Post reply on HN