All Projects → codemanki → Cloudscraper

codemanki / Cloudscraper

Licence: mit
--DEPRECATED -- 🛑 🛑 Node.js library to bypass cloudflare's anti-ddos page

Programming Languages

javascript
184084 projects - #8 most used programming language

Projects that are alternatives of or similar to Cloudscraper

Boringtun
Userspace WireGuard® Implementation in Rust
Stars: ✭ 3,760 (+566.67%)
Mutual labels:  cloudflare
Hatcloud
discontinued
Stars: ✭ 418 (-25.89%)
Mutual labels:  cloudflare
Docker Cloudflare Ddns
A small amd64/ARM/ARM64 Docker image that allows you to use CloudFlare as a DDNS / DynDNS Provider.
Stars: ✭ 467 (-17.2%)
Mutual labels:  cloudflare
Slickstack
SlickStack is a free LEMP stack automation script written in Bash designed to enhance and simplify WordPress provisioning, performance, and security.
Stars: ✭ 311 (-44.86%)
Mutual labels:  cloudflare
Warp Plus Cloudflare
Script for getting unlimited GB on Warp+ ( https://1.1.1.1/ )
Stars: ✭ 381 (-32.45%)
Mutual labels:  cloudflare
Meantorrent
meanTorrent - MEAN.JS BitTorrent Private Tracker - Full-Stack JavaScript Using MongoDB, Express, AngularJS, and Node.js, A BitTorrent Private Tracker CMS with Multilingual, and IRC announce support, CloudFlare support. Demo at:
Stars: ✭ 438 (-22.34%)
Mutual labels:  cloudflare
Api Covid19 In
COVID Rest API for India data, using Cloudflare Workers
Stars: ✭ 283 (-49.82%)
Mutual labels:  cloudflare
Fav Up
IP lookup by favicon using Shodan
Stars: ✭ 550 (-2.48%)
Mutual labels:  cloudflare
Substats
📈📉 Shhhh...we're counting your subscribers!
Stars: ✭ 396 (-29.79%)
Mutual labels:  cloudflare
Encrypted Dns
Configuration profiles for DNS HTTPS and DNS over TLS for iOS 14 and MacOS Big Sur
Stars: ✭ 455 (-19.33%)
Mutual labels:  cloudflare
Ddns Go
简单好用的DDNS。自动更新域名解析到公网IP(支持阿里云、腾讯云dnspod、Cloudflare、华为云)
Stars: ✭ 307 (-45.57%)
Mutual labels:  cloudflare
Keepass2 Haveibeenpwned
Simple Have I Been Pwned checker for KeePass
Stars: ✭ 381 (-32.45%)
Mutual labels:  cloudflare
Nginx Autoinstall
Compile Nginx from source with custom modules on Debian and Ubuntu
Stars: ✭ 443 (-21.45%)
Mutual labels:  cloudflare
Graphql Starter
💥 Monorepo template (seed project) pre-configured with GraphQL API, PostgreSQL, React, Relay, and Material UI.
Stars: ✭ 3,377 (+498.76%)
Mutual labels:  cloudflare
Onedrive Index Cloudflare Worker
DEPRECATED: Please use https://github.com/spencerwooo/onedrive-cf-index instead
Stars: ✭ 485 (-14.01%)
Mutual labels:  cloudflare
Nginx Lua Anti Ddos
A Anti-DDoS script to protect Nginx web servers using Lua with a HTML Javascript based authentication puzzle inspired by Cloudflare I am under attack mode an Anti-DDoS authentication page protect yourself from every attack type All Layer 7 Attacks Mitigating Historic Attacks DoS DoS Implications DDoS All Brute Force Attacks Zero day exploits Social Engineering Rainbow Tables Password Cracking Tools Password Lists Dictionary Attacks Time Delay Any Hosting Provider Any CMS or Custom Website Unlimited Attempt Frequency Search Attacks HTTP Basic Authentication HTTP Digest Authentication HTML Form Based Authentication Mask Attacks Rule-Based Search Attacks Combinator Attacks Botnet Attacks Unauthorized IPs IP Whitelisting Bruter THC Hydra John the Ripper Brutus Ophcrack unauthorized logins Injection Broken Authentication and Session Management Sensitive Data Exposure XML External Entities (XXE) Broken Access Control Security Misconfiguration Cross-Site Scripting (XSS) Insecure Deserialization Using Components with Known Vulnerabilities Insufficient Logging & Monitoring Drupal WordPress Joomla Flash Magento PHP Plone WHMCS Atlassian Products malicious traffic Adult video script avs KVS Kernel Video Sharing Clip Bucket Tube sites Content Management Systems Social networks scripts backends proxy proxies PHP Python Porn sites xxx adult gaming networks servers sites forums vbulletin phpbb mybb smf simple machines forum xenforo web hosting video streaming buffering ldap upstream downstream download upload rtmp vod video over dl hls dash hds mss livestream drm mp4 mp3 swf css js html php python sex m3u zip rar archive compressed mitigation code source sourcecode chan 4chan 4chan.org 8chan.net 8ch 8ch.net infinite chan 8kun 8kun.net anonymous anon tor services .onion torproject.org nginx.org nginx.com openresty.org darknet dark net deepweb deep web darkweb dark web mirror vpn reddit reddit.com adobe flash hackthissite.org dreamhack hack hacked hacking hacker hackers hackerz hackz hacks code coding script scripting scripter source leaks leaked leaking cve vulnerability great firewall china america japan russia .gov government http1 http2 http3 quic q3 litespeedtech litespeed apache torrents torrent torrenting webtorrent bittorrent bitorrent bit-torrent cyberlocker cyberlockers cyber locker cyberbunker warez keygen key generator free irc internet relay chat peer-to-peer p2p cryptocurrency crypto bitcoin miner browser xmr monero coinhive coin hive coin-hive litecoin ethereum cpu cycles popads pop-ads advert advertisement networks banner ads protect ovh blazingfast.io amazon steampowered valve store.steampowered.com steamcommunity thepiratebay lulzsec antisec xhamster pornhub porn.com pornhub.com xhamster.com xvideos xvdideos.com xnxx xnxx.com popads popcash cpm ppc
Stars: ✭ 295 (-47.7%)
Mutual labels:  cloudflare
Edge Sql
Cloudflare Workers providing a SQL API
Stars: ✭ 429 (-23.94%)
Mutual labels:  cloudflare
Kanye.rest
🌊 A free REST API for random Kanye West quotes (Kanye as a Service)
Stars: ✭ 558 (-1.06%)
Mutual labels:  cloudflare
Letsencrypt Heroku
Make any Heroku application secure in just a couple of minutes.
Stars: ✭ 530 (-6.03%)
Mutual labels:  cloudflare
React Starter Kit
React Starter Kit — front-end starter kit using React, Relay, GraphQL, and JAM stack architecture
Stars: ✭ 21,060 (+3634.04%)
Mutual labels:  cloudflare

🛑 THIS LIBRARY IS NO LONGER SUPPORTED AND IS DEPRECATED 🛑

cloudscraper

Node.js library to bypass Cloudflare's anti-ddos page.

js-semistandard-style

Build status Coverage Dependency Status Greenkeeper badge

If the page you want to access is protected by Cloudflare, it will return special page, which expects client to support Javascript to solve challenge.

This small library encapsulates logic which extracts challenge, solves it, submits and returns the request page body.

You can use cloudscraper even if you are not sure if Cloudflare protection is turned on.

In general, Cloudflare has 4 types of common anti-bot pages:

  • Simple html+javascript page with challenge
  • Page which redirects to original site
  • Page with reCAPTCHA
  • Page with error ( your ip was banned, etc)

If you notice that for some reason cloudscraper stops working, do not hesitate and get in touch with me ( by creating an issue here, for example), so i can update it.

Install

npm install cloudscraper

Saving the request module as a dependency is compulsory.

# Pin the request version
npm install --save request

Support for Brotli encoded responses is enabled by default when using Node.js v10 or later. If you wish to enable support for older Node.js versions, you may install brotli. It is recommended but not required.

Usage

Cloudscraper uses request-promise by default since v3. You can find the migration guide here.

var cloudscraper = require('cloudscraper');

cloudscraper.get('https://website.com/').then(console.log, console.error);

or for POST action:

var options = {
  uri: 'https://website.com/',
  formData: { field1: 'value', field2: 2 }
};

cloudscraper.post(options).then(console.log).catch(console.error);

Examples live in the docs directory of the Github repo and can be found here.

A generic request can be made with cloudscraper(options). The options object should follow request's options. Not everything is supported however, for example http methods other than GET and POST. If you wanted to request an image in binary data you could use the encoding option:

var options = {
  method: 'GET',
  url:'http://website.com/',
};

cloudscraper(options).then(console.log);

Advanced usage

Cloudscraper allows you to specify your own requester, one of either request or request-promise. Cloudscraper wraps the requester and accepts the same options, so using cloudscraper is pretty much like using those two libraries.

  • Cloudscraper exposes the same HTTP verb methods as request:
    • cloudscraper.get(options, callback)
    • cloudscraper.post(options, callback)
    • cloudscraper(uri)
  • Cloudscraper uses request-promise by default, promise chaining is done exactly the same as described in docs:
 cloudscraper(options)
   .then(function (htmlString) {
   })
   .catch(function (err) {
   });

Please refer to the requester's documentation for further instructions.

Sucuri

Cloudscraper can also identify and automatically bypass Sucuri WAF. No actions are required.

ReCAPTCHA

Cloudscraper may help you with the reCAPTCHA page. Take a look at this example and an example using promises.

Cloudflare may send a reCAPTCHA depending on the negotiated TLS cipher suite and extensions. Reducing the default cipher suite to only ciphers supported by Cloudflare may mitigate the problem: https://developers.cloudflare.com/ssl/ssl-tls/cipher-suites/

Only specifying the Cloudflare preferred TLSv1.2 cipher is also an option:

var cloudscraper = require('cloudscraper').defaults({
  agentOptions: {
    ciphers: 'ECDHE-ECDSA-AES128-GCM-SHA256'
  }
})

More information on TLS issues can be found here.

Defaults method

cloudscraper.defaults is a very convenient way of extending the cloudscraper requests with any of your settings.

var cloudscraper = require('cloudscraper').defaults({ 'proxy': 'http://localproxy.com' });
// Overriding headers to remove them or using uncommon headers will cause reCAPTCHA responses
var headers = { /* ... */ };
var cloudscraper = require('cloudscraper').defaults({ headers: headers });

cloudscraper(options).then(console.log);

Configuration

Cloudscraper exposes the following options that are required by default but might be changed. Please note that the default values eliminate the chance of getting sent a CAPTCHA.

var options = {
  uri: 'https://website',
  jar: requestModule.jar(), // Custom cookie jar
  headers: {
    // User agent, Cache Control and Accept headers are required
    // User agent is populated by a random UA.
    'User-Agent': 'Ubuntu Chromium/34.0.1847.116 Chrome/34.0.1847.116 Safari/537.36',
    'Cache-Control': 'private',
    'Accept': 'application/xml,application/xhtml+xml,text/html;q=0.9, text/plain;q=0.8,image/png,*/*;q=0.5'
  },
  // Cloudscraper automatically parses out timeout required by Cloudflare.
  // Override cloudflareTimeout to adjust it.
  cloudflareTimeout: 5000,
  // Reduce Cloudflare's timeout to cloudflareMaxTimeout if it is excessive
  cloudflareMaxTimeout: 30000,
  // followAllRedirects - follow non-GET HTTP 3xx responses as redirects
  followAllRedirects: true,
  // Support only this max challenges in row. If CF returns more, throw an error
  challengesToSolve: 3,
  // Remove Cloudflare's email protection, replace encoded email with decoded versions
  decodeEmails: false,
  // Support gzip encoded responses (Should be enabled unless using custom headers)
  gzip: true,
  // Removes a few problematic TLSv1.0 ciphers to avoid CAPTCHA
  agentOptions: { ciphers }
};

cloudscraper(options).then(console.log);

You can access the default configuration with cloudscraper.defaultParams

Error object

Cloudscraper error object inherits from Error has following fields:

  • name - RequestError/CaptchaError/CloudflareError/ParserError
  • options - The request options
  • cause - An alias for error
  • response - The request response
  • errorType - Custom error code Where errorType can be following:
  • 0 if request to page failed due to some native reason as bad url, http connection or so. error in this case will be error event
  • 1 Cloudflare returned CAPTCHA. Nothing to do here. Bad luck
  • 2 Cloudflare returned page with some inner error. error will be Number within this range 1012, 1011, 1002, 1000, 1004, 1010, 1006, 1007, 1008. See more here
  • 3 this error is returned when library failed to parse and solve js challenge. error will be String with some details. ⚠️ ⚠️ Most likely it means that Cloudflare have changed their js challenge.
  • 4 CF went into a loop and started to return challenge after challenge. If number of solved challenges is greater than 3 and another challenge is returned, throw an error

Errors are descriptive. You can find a list of all known errors here.

Do not always rely on error.cause to be an error, it can be a string.

Running tests

Clone this repo, do npm install and then just npm test

Unknown error? Library stopped working?

Let me know, by opening an issue in this repo and I will update library asap. Please, provide url and body of page where cloudscraper failed.

WAT

Current Cloudflare implementation requires browser to respect the timeout of 5 seconds and cloudscraper mimics this behaviour. So everytime you call cloudscraper.get/post you should expect it to return result after minimum 6 seconds. If you want to change this behaviour, you would need to make a generic request as described in above and pass cloudflareTimeout options with your value. But be aware that Cloudflare might track this timeout and use it against you ;)

TODO

  • [x] Check for reCAPTCHA
  • [x] Support cookies, so challenge can be solved once per session
  • [x] Support page with simple redirects
  • [x] Add proper testing
  • [x] Remove manual 302 processing, replace with followAllRedirects param
  • [x] Parse out the timeout from challenge page
  • [x] Reorder the arguments in get/post/request methods and allow custom options to be passed in
  • [x] Support reCAPTCHA solving
  • [x] Promisification

Kudos to contributors

In the beginning cloudscraper was a port of python module cloudflare-scrape. Thank you Anorov for an inspiration.

Dependencies

Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].