Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
cloudscraper — 一个用于绕过 Cloudflare 反机器人页面的 Python 模块。 | Kitploit
工具/GitHubGitHub/venomous/cloudscraper
Web代理与拦截冒充工具WAF绕过网络爬虫反机器人指纹欺骗CAPTCHA 绕过CAPTCHA 绕过 分类第 11 名指纹欺骗 分类第 5 名Web代理与拦截 分类第 16 名
6.8k641571年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHubvenomous/cloudscraper

cloudscraper

一个用于绕过 Cloudflare 反机器人页面的 Python 模块。

查看仓库

cloudscraper - 增强版

PyPI version License: MIT image

由 Zied Boughdir 增强

最新版本:v3.0.0 🚀 - 重大升级

🆕 v3.0.0 的主要新特性

  • 🛡️ 自动 403 错误恢复 - 长时间使用后出现 403 错误时智能刷新会话
  • 📊 会话健康监控 - 主动式会话管理,支持可配置的刷新间隔
  • 🔄 智能会话刷新 - 自动清除 Cookie 并轮换浏览器指纹
  • 🎯 增强隐身模式 - 通过模拟人类行为改进反检测能力
  • 🔧 现代 Python 支持 - 支持 Python 3.8+ 和最新依赖版本
  • 📦 现代打包 - 使用 pyproject.toml 和现代构建工具
  • 🧪 全面测试 - 新增测试套件,集成 pytest 和 CI/CD
  • 🚀 性能提升 - 优化代码,改进了错误处理

🔧 破坏性变更

  • 最低 Python 版本:现在要求 Python 3.8+
  • 更新的依赖:所有依赖均已升级到最新稳定版本
  • 移除遗留代码:清理了 Python 2 兼容代码

✅ 原有功能(仍然可用)

  • 可执行文件兼容性修复 - 针对 PyInstaller、cx_Freeze 和 auto-py-to-exe 转换的完整解决方案
  • Cloudflare v3 JavaScript VM 挑战支持 - 应对最新、最复杂的 Cloudflare 防护
  • Cloudflare Turnstile 挑战支持 - 支持 Cloudflare 的 CAPTCHA 替代方案
  • 增强的 JavaScript 解释器支持 - 改进基于 VM 的挑战执行
  • 完整防护覆盖 - 现在支持所有 Cloudflare 挑战类型(v1、v2、v3、Turnstile)

🔧 改进

  • 🎯 修复可执行文件中的 User Agent 问题 - 针对缺失 browsers.json 的自动回退系统
  • 🛡️ PyInstaller 检测 - 自动检测并处理可执行环境
  • 📦 全面的回退系统 - 70+ 个内置用户代理,覆盖所有平台
  • 增强的代理轮换和隐身模式能力
  • 更好地检测和处理现代 Cloudflare 防护机制
  • 改进与所有 JavaScript 解释器(js2py、nodejs、native)的兼容性
  • 更新文档并附有全面的示例

📊 测试结果

所有功能均已测试,核心功能 100% 成功率:

  • ✅ 基本请求:100% 通过率
  • ✅ 用户代理处理:100% 通过率
  • ✅ Cloudflare v1 挑战:100% 通过率
  • ✅ Cloudflare v2 挑战:100% 通过率
  • ✅ Cloudflare v3 挑战:100% 通过率
  • ✅ 隐身模式:100% 通过率

这是一个用于绕过 Cloudflare 反机器人页面(也称为“I'm Under Attack Mode”,即 IUAM)的 Python 模块,基于 Requests 实现。该增强版支持 Cloudflare v2 挑战、代理轮换、隐身模式等功能。Cloudflare 会定期更改其技术,因此我会经常更新此仓库。

如果你希望抓取或爬取受 Cloudflare 保护的网站,这会非常有用。Cloudflare 的反机器人页面目前仅检查客户端是否支持 Javascript,不过未来他们可能会增加其他技术。

由于 Cloudflare 不断更改并强化其防护页面,cloudscraper 需要 JavaScript 引擎/解释器来解决 Javascript 挑战。这样脚本就能轻松模拟普通网络浏览器,而无需显式反混淆和解析 Cloudflare 的 Javascript。

作为参考,以下是 Cloudflare 用于此类页面的默认消息:``` Checking your browser before accessing website.com.

This process is automatic. Your browser will redirect to your requested content shortly.

Please allow up to 5 seconds...

任何使用 cloudscraper 的脚本在首次访问启用了 Cloudflare 反机器人机制的网站时都会休眠约 5 秒,不过首次请求之后不会再有任何延迟。



# 安装

只需运行 `pip install cloudscraper` 即可。PyPI 包位于 https://pypi.org/project/cloudscraper/```bash
pip install cloudscraper

或者,克隆此仓库并运行 python setup.py install。

从 cloudscraper 迁移

如果您之前使用的是原版 cloudscraper 包,现在可以直接使用此增强版本:```python

Enhanced import

import cloudscraper # Enhanced version

The API remains compatible, so you only need to change the import statements in your code. All function calls and parameters work the same way.

### Codebase Structure

The codebase has been streamlined to improve maintainability and reduce confusion:

- **Single Module**: All code is now in the `cloudscraper` module
- **Removed Redundancy**: The redundant directories have been removed
- **Updated Tests**: All test files have been updated to use the `cloudscraper` module

This makes the codebase cleaner and easier to maintain while ensuring backward compatibility with existing code that uses the original API.

## Key Features in cloudscraper

| Feature | Description | Status |
|---------|-------------|--------|
| **🆕 Executable Compatibility** | Complete fix for PyInstaller, cx_Freeze, auto-py-to-exe conversion | ✅ **FIXED** |
| **🆕 v3 JavaScript VM Challenges** | Support for Cloudflare's latest JavaScript VM-based challenges | ✅ **NEW** |
| **🆕 Turnstile Support** | Support for Cloudflare's new Turnstile CAPTCHA replacement | ✅ **NEW** |
| **Modern Challenge Support** | Enhanced support for v1, v2, v3, and Turnstile Cloudflare challenges | ✅ Complete |
| **Proxy Rotation** | Built-in smart proxy rotation with multiple strategies | ✅ Enhanced |
| **Stealth Mode** | Human-like behavior simulation to avoid detection | ✅ Enhanced |
| **Browser Emulation** | Advanced browser fingerprinting for Chrome and Firefox | ✅ Stable |
| **JavaScript Handling** | Better JS interpreter (js2py as default) for challenge solving | ✅ Enhanced |
| **Captcha Solvers** | Support for multiple CAPTCHA solving services | ✅ Stable |

# Dependencies

- **Python 3.8+** (Dropped support for Python 3.6 and 3.7)
- **[Requests](https://github.com/psf/requests)** >= 2.31.0
- **[requests_toolbelt](https://pypi.org/project/requests-toolbelt/)** >= 1.0.0
- **[pyparsing](https://pypi.org/project/pyparsing/)** >= 3.1.0
- **[pyOpenSSL](https://pypi.org/project/pyOpenSSL/)** >= 24.0.0
- **[pycryptodome](https://pypi.org/project/pycryptodome/)** >= 3.20.0
- **[websocket-client](https://pypi.org/project/websocket-client/)** >= 1.7.0
- **[js2py](https://pypi.org/project/Js2Py/)** >= 0.74
- **[brotli](https://pypi.org/project/Brotli/)** >= 1.1.0
- **[certifi](https://pypi.org/project/certifi/)** >= 2024.2.2

`python setup.py install` will install the Python dependencies automatically. The javascript interpreters and/or engines you decide to use are the only things you need to install yourself, excluding js2py which is part of the requirements as the default.

# Javascript Interpreters and Engines

We support the following Javascript interpreters/engines.

- **[ChakraCore](https://github.com/microsoft/ChakraCore):** Library binaries can also be located [here](https://www.github.com/VeNoMouS/cloudscraper/tree/ChakraCore/).
- **[js2py](https://github.com/PiotrDabkowski/Js2Py):** >=0.74 **(Default for enhanced version)**
- **native**: Self made native python solver
- **[Node.js](https://nodejs.org/)**
- **[V8](https://github.com/sony/v8eval/):** We use Sony's [v8eval](https://v8.dev)() python module.

# Usage

The simplest way to use cloudscraper is by calling `create_scraper()`.```python
import cloudscraper

scraper = cloudscraper.create_scraper()  # returns a CloudScraper instance
# Or: scraper = cloudscraper.CloudScraper()  # CloudScraper inherits from requests.Session
print(scraper.get("http://somesite.com").text)  # => "<!DOCTYPE html><html><head>..."

就这样...

从此会话对象发往受 Cloudflare 反机器人保护网站的请求都将被自动处理。未使用 Cloudflare 的网站将按正常方式处理。你无需额外配置或调用任何内容,实际上可以将所有网站都视为不受任何保护。

你使用 cloudscraper 的方式与使用 Requests 完全相同。cloudScraper 的工作方式与 Requests Session 对象一致,区别仅在于不是调用 requests.get() 或 requests.post(),而是调用 scraper.get() 或 scraper.post()。

如需了解更多信息,请参阅 Requests 的文档。

✅ 可执行文件兼容性 (v2.7.0)

问题已解决!

使用 cloudscraper 将 Python 应用程序转换为可执行文件时遇到的用户代理问题已完全修复!

问题是什么?

在将 Python 应用转换为可执行文件(使用 PyInstaller、cx_Freeze、auto-py-to-exe 等)时,由于 browsers.json 文件未被正确包含,用户会遇到与 用户代理 或 agent_user 功能相关的错误。

解决方案

cloudscraper v2.7.0 包含一个自动回退系统:

  1. PyInstaller 检测 - 自动检测可执行环境
  2. 多个回退路径 - 尝试多个位置查找 browsers.json
  3. 全面的内置回退 - 70+ 个硬编码用户代理,覆盖所有平台
  4. 优雅的错误处理 - 文件缺失时不再崩溃

如何使用

选项 1:直接构建你的可执行文件(自动生效):```bash pyinstaller your_app.py

**选项 2:包含完整的用户代理数据库**(推荐):```bash
pyinstaller --add-data "cloudscraper/user_agent/browsers.json;cloudscraper/user_agent/" your_app.py

测试

所有可执行兼容性均已经过全面测试:``` ✅ Normal operation with browsers.json ✅ Fallback operation without browsers.json ✅ PyInstaller environment simulation ✅ All browser/platform combinations ✅ HTTP requests with fallback user agents

您的 cloudscraper 应用程序在转换为可执行文件后将完美运行!🎉

## 🆕 Cloudflare v3 JavaScript VM 挑战支持

### 什么是 v3 挑战?

Cloudflare v3 挑战代表了机器人保护技术的最新演进。与传统 v1 和 v2 挑战不同,v3 挑战:

- **在 JavaScript 虚拟机中运行**:挑战在沙盒化的 JavaScript 环境中执行
- **使用高级检测**:更复杂的算法来检测自动化行为
- **生成动态代码**:挑战代码是动态创建的,更难进行逆向工程
- **提供现代保护**:来自 Cloudflare 的最新反机器人技术

### v3 基本用法```python
import cloudscraper

# v3 support is enabled by default
scraper = cloudscraper.create_scraper()
response = scraper.get("https://example.com")
print(response.text)

高级 v3 配置```python

import cloudscraper

下载工具