Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
miasma — AI 웹 스크래퍼를 끝없는 독 구덩이에 빠뜨리세요. | Kitploit
도구/GitHubGitHub/austin-weeks/miasma
OSINT (Open Source Intelligence)Information GatheringWeb SecurityCrawlerAnti-BotAI Security
GitHubaustin-weeks/miasma

miasma

AI 웹 스크래퍼를 끝없는 독 구덩이에 빠뜨리세요.

저장소 보기
1.2k38417일 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
# 🌀 Miasma

[![No AI](https://custom-icon-badges.demolab.com/badge/No%20AI-2f2f2f?logo=non-ai&logoColor=white&logoSize=auto)](#)
[![crates.io](https://img.shields.io/crates/v/miasma?logo=rust)](https://crates.io/crates/miasma)
[![downloads](https://img.shields.io/crates/dr/miasma?logo=rust)](https://crates.io/crates/miasma)
[![Docker Pulls](https://img.shields.io/docker/pulls/austinweeks/miasma)](https://hub.docker.com/r/austinweeks/miasma)
[![GitHub commits since latest release](https://img.shields.io/github/commits-since/austin-weeks/miasma/latest?logo=github)](#)

<picture>
  <img src="https://assets.kitploit.com/production/public/readmes/12808/53ea9eddbca68d25cbf4085762448c1cc10ee6fdf38bda837c6abf665a9d673f.png" alt="Web crawlers getting stuck in a cloud of poison miasma." title="Cover art by @cerberussaturn07" />
</picture>

AI 기업들은 다음 모델의 훈련 데이터로 사용하기 위해 인터넷을 엄청난 규모로 지속적으로 긁어모으고 있습니다. 공개 웹사이트를 운영하고 있다면, _그들은 이미 당신의 작업물을 훔치고 있는 것입니다._

_Miasma_는 이에 맞서 싸울 수 있도록 도와드립니다! 서버를 실행하고 악성 트래픽을 이쪽으로 유도하세요. _Miasma_는 [poison fountain](https://rnsaffn.com/poison3)에서 오염된 훈련 데이터를 여러 자기 참조 링크와 함께 전송합니다. 슬롭 머신을 위한 끝없는 슬롭 뷔페인 셈이죠.

_Miasma_는 매우 빠르고 메모리 사용량이 최소화되어 있습니다. 인터넷의 거머리들을 막아내는 데 컴퓨팅 자원을 낭비할 필요가 없습니다.

> [!CAUTION]
> 이 소프트웨어를 배포하는 데는 내재적인 위험이 따릅니다. 사용 전에 [configuration](#configuration)과 [disclaimer](#disclaimer)를 반드시 완전히 읽어보세요.

## Usage

_Miasma_는 로컬에서 실행하거나 공식 [docker image](https://hub.docker.com/r/austinweeks/miasma)로 실행할 수 있습니다.

기존 Rust 서버에 _Miasma_를 통합하고 싶다면, [_Miasma_를 라이브러리로 사용](https://docs.rs/miasma/)할 수도 있습니다.

### Running Locally

[cargo](https://doc.rust-lang.org/cargo/getting-started/installation.html)로 설치하세요 (권장):

```sh
cargo install miasma
```

또는 [releases](https://github.com/austin-weeks/miasma/releases)에서 미리 빌드된 바이너리를 다운로드할 수 있습니다.

다양한 패키지 관리자를 위한 커뮤니티 유지 관리 패키지도 제공됩니다:

<a href="https://repology.org/project/miasma/versions">
    <img
        src="https://repology.org/badge/vertical-allrepos/miasma.svg?exclude_unsupported=1&amp;minversion=0.2"
        alt="Packaging status"
    >
</a>

<br>
<br>

기본 설정으로 _Miasma_를 시작하세요:

```sh
miasma
```

사용 가능한 모든 [configuration options](#configuration)를 확인하세요:

```sh
miasma --help
```

### Running with Docker

공식 [docker image](https://hub.docker.com/r/austinweeks/miasma)를 사용하여 _Miasma_를 실행하세요:

```sh
docker run --rm -p 9999:9999 austinweeks/miasma:latest
```

로컬에서 사용하는 것과 동일한 [configuration flags](#configuration)를 전달하세요:

```sh
docker run --rm -p 9999:9999 austinweeks/miasma:latest \
    --link-prefix '/naughty-bots' \
    --max-in-flight 30
```

또는 docker compose 클러스터 내에서 실행하세요:

```yaml
services:
  miasma:
    image: austinweeks/miasma:latest
    command: ["--link-prefix", "/naughty-bots", "--max-in-flight", "30"]
    ports:
      - 9999:9999
```

## How to Trap Scrapers

_Miasma_로 스크래퍼를 함정에 빠뜨리는 서버 설정 예시를 살펴보겠습니다. 스크래퍼 트래픽을 유도할 서버 경로로 `/naughty-bots`를 선택하겠습니다. 서버의 리버스 프록시로 [_Nginx_](https://nginx.org/)를 사용하지만, 다양한 설정으로 동일한 결과를 얻을 수 있습니다.

완료되면 스크래퍼는 다음과 같이 함정에 빠지게 됩니다:

<p align="center">
  <picture>
    <source media="(prefers-color-scheme: dark)" srcset="https://raw.githubusercontent.com/austin-weeks/miasma/main/.github/images/flow-chart-dark.png">
    <img height="425" src="https://assets.kitploit.com/production/public/readmes/12808/0fc56b18661aceabe968dff1a03545577f5a28691a3a4d20e096093919935ceb.png" alt="Flow chart depicting cycle of trapped scrapers.">
  </picture>
</p>

### Embedding Hidden Links

사이트 내에 `/naughty-bots`로 이어지는 숨겨진 링크 몇 개를 포함시키겠습니다.

```html
<a
  href="https://github.com/austin-weeks/miasma/blob/main/naughty-bots"
  style="display: none;"
  aria-hidden="true"
  tabindex="-1"
>
  Amazing high quality data here!
</a>
```

`style="display: none;"`, `aria-hidden="true"`, `tabindex="-1"` 속성은 링크가 사람 방문자에게 완전히 보이지 않도록 하고, 스크린 리더와 키보드 탐색에서 무시되도록 합니다. 이 링크는 **오직** 스크래퍼에게만 보입니다.

### Configuring our Nginx Proxy

숨겨진 링크가 `/naughty-bots/`를 가리키므로, 이 경로가 _Miasma_로 요청을 프록시하도록 설정하겠습니다. _Miasma_가 포트 `9855`에서 실행 중이라고 가정하겠습니다.

또한 실수로 자체 DDoS를 당하지 않도록 스크래퍼의 user agent를 기반으로 강력한 속도 제한을 설정하겠습니다.

```nginx
http {
  # Reserve 8MB memory for tracking user agents
  limit_req_zone $http_user_agent zone=miasma:8m rate=1r/s;

  server {
    location = /naughty-bots {
      port_in_redirect off;
      return 301 /naughty-bots/;
    }
    location /naughty-bots/ {
      # Rate limit via the 'miasma' zone with no queueing
      limit_req_status 429;
      limit_req zone=miasma burst=5 nodelay;

      # Proxy requests to Miasma
      proxy_pass http://localhost:9855/;
    }
  }
}
```

이 설정은 `/naughty-bots` 경로의 모든 변형을 잡아냅니다 -> `/naughty-bots`, `/naughty-bots/`, `/naughty-bots/12345` 등.

### Run _Miasma_

마지막으로 _Miasma_를 시작하고 `/naughty-bots`를 링크 접두사로 지정하겠습니다. 이는 _Miasma_가 `/naughty-bots/`로 시작하는 링크를 생성하도록 지시하여, 스크래퍼가 _Nginx_ 프록시를 통해 _Miasma_로 올바르게 라우팅되도록 합니다.

최대 동시 연결 수를 50으로 제한하겠습니다. 50개 연결에서 최대 메모리 사용량은 50-60 MB 정도로 예상할 수 있습니다. 이 제한을 초과하는 요청은 대기열에 추가되지 않고 즉시 **429** 응답을 받습니다.

또한 스크래퍼의 `Accept-Encoding` 헤더와 관계없이 _Miasma_가 모든 응답을 gzip 압축하도록 강제하겠습니다. gzip 압축된 응답은 훨씬 작기 때문에 송신 비용을 줄이는 데 도움이 됩니다.

스크래퍼를 영원히 가둬둘 수도 있지만, 링크 수와 최대 깊이 옵션을 사용하여 스크래퍼가 약 100K개의 오염된 페이지를 소비한 후 놓아주도록 하겠습니다. 이 설정으로 _Miasma_는 스크래퍼당 총 약 **250MB**의 데이터를 전송합니다.

```sh
miasma --link-prefix '/naughty-bots' -p 9855 -c 50 --force-gzip --link-count 5 --max-depth 8
```

### Enjoy!

배포하고 잘못 행동하는 봇들이 우리의 끝없는 슬롭 머신에서 탐욕스럽게 먹어치우는 모습을 지켜보세요!

<p align="center">
  <picture>
    <img src="https://raw.githubusercontent.com/austin-weeks/miasma/main/.github/images/logs.gif" />
  </picture>
</p>

### `robots.txt`

[`robots.txt`](https://developers.google.com/search/docs/crawling-indexing/robots/intro)를 통해 잘 행동하는 봇과 검색 엔진을 _Miasma_로부터 보호하세요!

```text
User-agent: *
Disallow: /naughty-bots
```

## Metrics

_Miasma_는 고유 User-Agent별 스크래퍼 요청 수를 추적하는 기능을 제공합니다. 이는 어떤 봇이 사이트를 가장 많이 공격하는지 식별하는 데 유용합니다. 메트릭은 로컬 SQLite 데이터베이스 파일에 기록되며, 원하는 엔드포인트에서 확인할 수 있습니다.

## Configuration

_Miasma_는 CLI 플래그 또는 [config file](https://github.com/austin-weeks/miasma/blob/main/docs/config_file)로 설정할 수 있습니다.

| Option              | Default                               | Description                                                                                                                                                                                                                                                             |
| ------------------- | ------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `config-file`       |                                       | 지정된 파일 경로의 파일에서 설정 옵션을 로드합니다. YAML, TOML, JSON 형식을 지원합니다. 예시는 [docs](https://github.com/austin-weeks/miasma/blob/main/docs/config_file)를 참조하세요.                                                                                                            |
| `port`              | `9999`                                | 서버가 바인딩할 포트입니다.                                                                                                                                                                                                                                     |
| `host`              | `localhost`                           | 서버가 바인딩할 호스트 주소입니다.                                                                                                                                                                                                                             |
| `unix-socket`       |                                       | TCP 주소 대신 Unix 도메인 소켓에 바인딩합니다. _Unix 계열 시스템에서만 사용 가능합니다._                                                                                                                                                                          |
| `max-in-flight`     | `500`                                 | 허용되는 최대 동시 요청 수입니다. 동시 요청 수를 초과했을 때 수신된 요청은 _429_ 응답을 받습니다. **_Miasma_의 메모리 사용량은 동시 요청 수에 직접 비례합니다 - 메모리 사용량이 우려된다면 이 값을 낮게 설정하세요.** |
| `link-prefix`       | `/`                                   | 자기 유도 링크의 접두사입니다. _Miasma_를 호스팅하는 경로여야 합니다, 예: `/naughty-bots`.                                                                                                                                                                 |
| `link-count`        | `5`                                   | 각 응답 페이지에 포함할 자기 유도 링크의 수입니다.                                                                                                                                                                                                        |
| `max-depth`         | `none`                                | 스크래퍼가 지정된 깊이에 도달하면 링크 생성을 중단합니다. 이를 통해 원하는 양의 오염 데이터를 제공한 후 스크래퍼를 차단할 수 있습니다. _활성 스크래퍼 수를 관리 가능한 수준으로 유지하려면 `link-count`와 함께 사용하세요._             |
| `force-gzip`        | `false`                               | 클라이언트의 _Accept-Encoding_ 헤더와 관계없이 항상 응답을 gzip 압축합니다. **압축을 강제하면 송신 비용을 줄이는 데 도움이 됩니다.**                                                                                                                                        |
| `unsafe-allow-html` | `false`                               | poison source의 응답에서 HTML 문자를 이스케이프하지 않습니다. 의도하지 않은 클라이언트 측 JavaScript 실행을 방지하기 위해 이스케이프는 기본적으로 활성화되어 있습니다. **이 옵션은 주의해서 사용하세요.**                                                                                    |
| `poison-source`     | `https://rnsaffn.com/poison2/?mask=0` | 오염된 훈련 데이터의 프록시 소스입니다.                                                                                                                                                                                                                                |
| `no-poison-cache`   | `false`                               | poison source 응답 캐싱을 비활성화합니다.                                                                                                                                                                                                 |
| `metrics-db-path`   |                                       | 메트릭 데이터를 저장할 SQLite 데이터베이스 파일의 경로입니다. 데이터베이스가 존재하지 않으면 _Miasma_가 이 위치에 생성합니다.                                                                                                                                     |
| `metrics-username`  |                                       | _Miasma_의 메트릭 페이지에 접근하는 데 필요한 Basic auth 사용자 이름입니다.                                                                                                                                                                                                         |
| `metrics-password`  |                                       | _Miasma_의 메트릭 페이지에 접근하는 데 필요한 Basic auth 비밀번호입니다.                                                                                                                                                                                                         |
| `metrics-endpoint`  | `/metrics`                            | _Miasma_의 메트릭이 제공될 엔드포인트입니다.                                                                                                                                                                                                                    |

## Disclaimer

_Miasma_는 [the poison fountain](https://rnsaffn.com/poison3)과 관련이 없습니다. 우리는 그 응답을 통제할 수 없으며 그 내용의 안전성을 보장할 수 없습니다. 사용자를 _Miasma_ 위치로 **_절대_** 유도해서는 안 됩니다.

_Miasma_는 영향을 받은 스크래퍼 운영자의 어떠한 보복에도 책임지지 않습니다. 관련 법률 및 호스팅 제공업체 정책을 준수하는 것은 귀하의 책임입니다. 전체 보증 및 책임 제한 세부 사항은 [LICENSE](https://github.com/austin-weeks/miasma/blob/main/LICENSE) (GPL-v3)를 참조하세요.

---

_Cover art by [@cerberussaturn07](https://www.instagram.com/cerberussaturn07/)_
도구 다운로드