Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
miasma — 将AI网页爬虫困在无尽的毒坑中。 | Kitploit
工具/GitHubGitHub/austin-weeks/miasma
OSINT (开源情报)信息收集Web安全网络爬虫反机器人AI 安全
GitHubaustin-weeks/miasma

miasma

将AI网页爬虫困在无尽的毒坑中。

查看仓库
1.2k38417天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
# 🌀 Miasma

[![No AI](https://custom-icon-badges.demolab.com/badge/No%20AI-2f2f2f?logo=non-ai&logoColor=white&logoSize=auto)](#)
[![crates.io](https://img.shields.io/crates/v/miasma?logo=rust)](https://crates.io/crates/miasma)
[![downloads](https://img.shields.io/crates/dr/miasma?logo=rust)](https://crates.io/crates/miasma)
[![Docker Pulls](https://img.shields.io/docker/pulls/austinweeks/miasma)](https://hub.docker.com/r/austinweeks/miasma)
[![GitHub commits since latest release](https://img.shields.io/github/commits-since/austin-weeks/miasma/latest?logo=github)](#)

<picture>
  <img src="https://assets.kitploit.com/production/public/readmes/12808/53ea9eddbca68d25cbf4085762448c1cc10ee6fdf38bda837c6abf665a9d673f.png" alt="Web crawlers getting stuck in a cloud of poison miasma." title="Cover art by @cerberussaturn07" />
</picture>

AI 公司持续以巨大规模抓取互联网,吞噬其全部内容,用作其下一代模型的训练数据。如果你拥有一个公开网站,_他们已经在窃取你的劳动成果。_

_Miasma_ 就是来帮你反击的!启动服务器,将任何恶意流量引向它。_Miasma_ 会从[毒泉](https://rnsaffn.com/poison3)发送被投毒的训练数据,并附带多个自引用链接。对垃圾机器来说,这是一场无尽的垃圾盛宴。

_Miasma_ 速度极快,内存占用极低——你不应该为了抵御互联网上的吸血鬼而浪费计算资源。

> [!CAUTION]
> 部署此软件存在固有风险。使用前请完整阅读[配置](#configuration)和[免责声明](#disclaimer)。

## 用法

你可以在本地运行 _Miasma_,也可以使用官方 [docker 镜像](https://hub.docker.com/r/austinweeks/miasma)。

如果你想将 _Miasma_ 集成到现有的 Rust 服务器中,也可以[将 _Miasma_ 作为库使用](https://docs.rs/miasma/)。

### 本地运行

使用 [cargo](https://doc.rust-lang.org/cargo/getting-started/installation.html) 安装(推荐):

```sh
cargo install miasma
```

或者,从 [releases](https://github.com/austin-weeks/miasma/releases) 下载预构建的二进制文件。

社区维护的软件包也可用于各种包管理器:

<a href="https://repology.org/project/miasma/versions">
    <img
        src="https://repology.org/badge/vertical-allrepos/miasma.svg?exclude_unsupported=1&amp;minversion=0.2"
        alt="Packaging status"
    >
</a>

<br>
<br>

使用默认配置启动 _Miasma_:

```sh
miasma
```

查看所有可用的[配置选项](#configuration):

```sh
miasma --help
```

### 使用 Docker 运行

使用官方 [docker 镜像](https://hub.docker.com/r/austinweeks/miasma)运行 _Miasma_:

```sh
docker run --rm -p 9999:9999 austinweeks/miasma:latest
```

传入与本地运行时相同的[配置标志](#configuration):

```sh
docker run --rm -p 9999:9999 austinweeks/miasma:latest \
    --link-prefix '/naughty-bots' \
    --max-in-flight 30
```

或者,在 docker compose 集群中运行:

```yaml
services:
  miasma:
    image: austinweeks/miasma:latest
    command: ["--link-prefix", "/naughty-bots", "--max-in-flight", "30"]
    ports:
      - 9999:9999
```

## 如何诱捕爬虫

让我们通过一个示例,演示如何设置服务器以使用 _Miasma_ 诱捕爬虫。我们将选择 `/naughty-bots` 作为服务器上引导爬虫流量的路径。我们将使用 [_Nginx_](https://nginx.org/) 作为服务器的反向代理,但许多不同的设置也能实现相同的结果。

完成后,爬虫将像这样被诱捕:

<p align="center">
  <picture>
    <source media="(prefers-color-scheme: dark)" srcset="https://raw.githubusercontent.com/austin-weeks/miasma/main/.github/images/flow-chart-dark.png">
    <img height="425" src="https://assets.kitploit.com/production/public/readmes/12808/0fc56b18661aceabe968dff1a03545577f5a28691a3a4d20e096093919935ceb.png" alt="Flow chart depicting cycle of trapped scrapers.">
  </picture>
</p>

### 嵌入隐藏链接

在我们的网站中,我们将包含几个指向 `/naughty-bots` 的隐藏链接。

```html
<a
  href="https://github.com/austin-weeks/miasma/blob/main/naughty-bots"
  style="display: none;"
  aria-hidden="true"
  tabindex="-1"
>
  Amazing high quality data here!
</a>
```

`style="display: none;"`、`aria-hidden="true"` 和 `tabindex="-1"` 属性确保链接对人类访客完全不可见,并且会被屏幕阅读器和键盘导航忽略。它们将**仅**对爬虫可见。

### 配置我们的 Nginx 代理

由于我们的隐藏链接指向 `/naughty-bots/`,我们将配置此路径以将请求代理到 _Miasma_。假设我们在端口 `9855` 上运行 _Miasma_。

我们还将基于爬虫的 user agent 设置激进的速率限制,以帮助确保我们不会意外地对自己发起 DDoS。

```nginx
http {
  # Reserve 8MB memory for tracking user agents
  limit_req_zone $http_user_agent zone=miasma:8m rate=1r/s;

  server {
    location = /naughty-bots {
      port_in_redirect off;
      return 301 /naughty-bots/;
    }
    location /naughty-bots/ {
      # Rate limit via the 'miasma' zone with no queueing
      limit_req_status 429;
      limit_req zone=miasma burst=5 nodelay;

      # Proxy requests to Miasma
      proxy_pass http://localhost:9855/;
    }
  }
}
```

此配置将捕获 `/naughty-bots` 路径的所有变体 -> `/naughty-bots`、`/naughty-bots/`、`/naughty-bots/12345` 等。

### 运行 _Miasma_

最后,我们将启动 _Miasma_ 并指定 `/naughty-bots` 作为链接前缀。这会指示 _Miasma_ 以 `/naughty-bots/` 开头生成链接,从而确保爬虫通过我们的 _Nginx_ 代理正确路由回 _Miasma_。

让我们将最大在途连接数限制为 50。在 50 个连接时,我们可以预期峰值内存使用量为 50-60 MB。请注意,任何超过此限制的请求将立即收到 **429** 响应,而不是被添加到队列中。

我们还将强制 _Miasma_ 对所有响应进行 gzip 压缩,无论爬虫的 `Accept-Encoding` 头是什么。由于 gzip 压缩后的响应明显更小,这将帮助我们降低出口成本。

虽然我们可以让爬虫永远被困住,但我们将使用链接数量和最大深度选项,让爬虫在消耗约 10 万个被投毒页面后离开。在此设置下,_Miasma_ 将为每个爬虫发送约 **250MB** 的总数据。

```sh
miasma --link-prefix '/naughty-bots' -p 9855 -c 50 --force-gzip --link-count 5 --max-depth 8
```

### 尽情享受!

让我们部署并观看行为不端的机器人贪婪地从我们无尽的垃圾机器中进食!

<p align="center">
  <picture>
    <img src="https://raw.githubusercontent.com/austin-weeks/miasma/main/.github/images/logs.gif" />
  </picture>
</p>

### `robots.txt`

请务必通过你的 [`robots.txt`](https://developers.google.com/search/docs/crawling-indexing/robots/intro) 保护行为良好的机器人和搜索引擎免受 _Miasma_ 影响!

```text
User-agent: *
Disallow: /naughty-bots
```

## 指标

_Miasma_ 能够按唯一 User-Agent 跟踪爬虫请求计数。这对于识别哪些机器人最频繁地访问你的网站非常有用。指标会写入本地 SQLite 数据库文件,并可在你选择的端点上查看。

## 配置

_Miasma_ 可以通过 CLI 标志或[配置文件](https://github.com/austin-weeks/miasma/blob/main/docs/config_file)进行配置。

| 选项              | 默认值                               | 描述                                                                                                                                                                                                                                                             |
| ------------------- | ------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `config-file`       |                                       | 从指定文件路径加载配置选项。支持 YAML、TOML 和 JSON 格式。示例见 [docs](https://github.com/austin-weeks/miasma/blob/main/docs/config_file)。                                                                                                            |
| `port`              | `9999`                                | 服务器应绑定的端口。                                                                                                                                                                                                                                     |
| `host`              | `localhost`                           | 服务器应绑定的主机地址。                                                                                                                                                                                                                             |
| `unix-socket`       |                                       | 绑定到 Unix 域套接字而不是 TCP 地址。_仅在类 Unix 系统上可用。_                                                                                                                                                                          |
| `max-in-flight`     | `500`                                 | 允许的最大在途请求数。超过在途限制时收到的请求将收到 _429_ 响应。**_Miasma_ 的内存使用量直接随在途请求数扩展——如果内存使用是一个问题,请将其设置为较低的值。** |
| `link-prefix`       | `/`                                   | 自引导链接的前缀。这应该是你托管 _Miasma_ 的路径,例如 `/naughty-bots`。                                                                                                                                                                 |
| `link-count`        | `5`                                   | 每个响应页面中包含的自引导链接数量。                                                                                                                                                                                                        |
| `max-depth`         | `none`                                | 一旦爬虫达到指定深度,就停止生成链接。这允许你在提供所需数量的毒药后切断爬虫。_将此与 `link-count` 配合使用,以将活跃爬虫数量保持在可管理的水平。_             |
| `force-gzip`        | `false`                               | 始终对响应进行 gzip 压缩,无论客户端的 _Accept-Encoding_ 头是什么。**强制压缩有助于降低出口成本。**                                                                                                                                        |
| `unsafe-allow-html` | `false`                               | 不转义毒药源响应中的 HTML 字符。默认启用转义以防止意外的客户端 JavaScript 执行。**请谨慎使用此选项。**                                                                                    |
| `poison-source`     | `https://rnsaffn.com/poison2/?mask=0` | 被投毒训练数据的代理源。                                                                                                                                                                                                                                |
| `no-poison-cache`   | `false`                               | 禁用毒药源响应缓存。                                                                                                                                                                                                 |
| `metrics-db-path`   |                                       | 用于存储指标数据的 SQLite 数据库文件路径。如果该位置尚不存在数据库,_Miasma_ 将在该位置创建一个。                                                                                                                                     |
| `metrics-username`  |                                       | 访问 _Miasma_ 指标页面所需的基本认证用户名。                                                                                                                                                                                                         |
| `metrics-password`  |                                       | 访问 _Miasma_ 指标页面所需的基本认证密码。                                                                                                                                                                                                         |
| `metrics-endpoint`  | `/metrics`                            | 提供 _Miasma_ 指标的端点。                                                                                                                                                                                                                    |

## 免责声明

_Miasma_ 与[毒泉](https://rnsaffn.com/poison3)无关。我们无法控制其响应,也无法保证其内容的安全性。你应**_永远不要_**将用户引导至你的 _Miasma_ 位置。

_Miasma_ 对受影响的爬虫运营者的任何报复行为概不负责。你有责任遵守适用的法律和托管提供商政策。完整保修和有限责任详情见 [LICENSE](https://github.com/austin-weeks/miasma/blob/main/LICENSE)(GPL-v3)。

---

_封面艺术由 [@cerberussaturn07](https://www.instagram.com/cerberussaturn07/) 创作_
下载工具