fourmovie commited on
Commit
6a44051
·
1 Parent(s): d8b1c2e
Files changed (9) hide show
  1. Dockerfile +26 -0
  2. README.md +1 -3
  3. api_test.py +26 -0
  4. cache/cache.json +10 -0
  5. endpoints/antibot.js +84 -0
  6. endpoints/cloudflare.js +79 -0
  7. endpoints/turnstile.js +84 -0
  8. index.js +165 -0
  9. package.json +18 -0
Dockerfile ADDED
@@ -0,0 +1,26 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ FROM node:20-slim
2
+
3
+ RUN apt update && apt install -y \
4
+ wget gnupg ca-certificates xvfb \
5
+ fonts-liberation libappindicator3-1 libasound2 libatk-bridge2.0-0 \
6
+ libatk1.0-0 libxss1 libnss3 libxcomposite1 libxdamage1 libxrandr2 libgbm1 \
7
+ && wget https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb \
8
+ && apt install -y ./google-chrome-stable_current_amd64.deb \
9
+ && rm google-chrome-stable_current_amd64.deb
10
+
11
+ WORKDIR /app
12
+
13
+ RUN mkdir -p /app/endpoints && \
14
+ mkdir -p /app/cache
15
+
16
+ COPY package*.json ./
17
+ RUN npm install
18
+
19
+ COPY . .
20
+
21
+ EXPOSE 7860
22
+
23
+ CMD rm -f /tmp/.X99-lock && \
24
+ Xvfb :99 -screen 0 1024x768x24 & \
25
+ export DISPLAY=:99 && \
26
+ npm start
README.md CHANGED
@@ -3,10 +3,8 @@ title: Antibot
3
  emoji: 📉
4
  colorFrom: green
5
  colorTo: gray
6
- sdk: gradio
7
  sdk_version: 5.49.1
8
- app_file: app.py
9
- pinned: false
10
  license: apache-2.0
11
  short_description: bypass antibot
12
  ---
 
3
  emoji: 📉
4
  colorFrom: green
5
  colorTo: gray
6
+ sdk: docker
7
  sdk_version: 5.49.1
 
 
8
  license: apache-2.0
9
  short_description: bypass antibot
10
  ---
api_test.py ADDED
@@ -0,0 +1,26 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ import asyncio
2
+ import httpx
3
+
4
+ async def main():
5
+ async with httpx.AsyncClient(timeout=30.0) as client:
6
+ resp1 = await client.post(
7
+ "http://localhost:8080/cloudflare",
8
+ json={
9
+ "domain": "https://olamovies.watch/generate",
10
+ "mode": "iuam",
11
+ },
12
+ )
13
+ print(resp1.json())
14
+
15
+ resp2 = await client.post(
16
+ "http://localhost:8080/cloudflare",
17
+ json={
18
+ "domain": "https://lksfy.com/",
19
+ "siteKey": "0x4AAAAAAA49NnPZwQijgRoi",
20
+ "mode": "turnstile",
21
+ },
22
+ )
23
+ print(resp2.json())
24
+
25
+ if __name__ == "__main__":
26
+ asyncio.run(main())
cache/cache.json ADDED
@@ -0,0 +1,10 @@
 
 
 
 
 
 
 
 
 
 
 
1
+ {
2
+ "{\"domain\":\"https://v2links.org\",\"mode\":\"iuam\"}": {
3
+ "timestamp": 1758616160392,
4
+ "value": {
5
+ "cf_clearance": "qqs5f4MpFMgA0v78Qmh_HYDWoKhbwqlQ57bTW5KeIr8-1758616161-1.2.1.1-D5PdpmheHl.26ssIRKQBsXzPtPPkSXntEZ_H9FUJVt7MMTS_BEE8iH.E48MDzKtFBLwZqRYxE_1GLo1gj3ChXrwatOGEJcmGRUwavy2qvGgUPizn7qufd.sW0ULfhaRO7Gz_H_eO1TU3iEqCzltEUDNk0SviKRFkF8ozbvJ91MW_qmO.qrjQorbu_jxcgJv5BHs6rTNOitWtVDAmYMDukASq0viHXIUAIvTM.LIfQ88",
6
+ "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36",
7
+ "elapsed_time": 5.028
8
+ }
9
+ }
10
+ }
endpoints/antibot.js ADDED
@@ -0,0 +1,84 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ const Tesseract = require('tesseract.js');
2
+ const { Jimp } = require('jimp');
3
+ const fs = require('fs');
4
+
5
+ function buf(b64) {
6
+ return Buffer.from(b64.replace(/^data:image\/\w+;base64,/, ""), "base64");
7
+ }
8
+
9
+ const images = {
10
+ main: null,
11
+ bots: []
12
+ };
13
+
14
+ const WORD_TO_NUM = {
15
+ zero:0, one:1, two:2, three:3, four:4,
16
+ five:5, six:6, seven:7, eight:8, nine:9, ten:10
17
+ };
18
+
19
+ function normalizeWords(t) {
20
+ return t.replace(/,/g,' ')
21
+ .replace(/\s+/g,' ')
22
+ .trim()
23
+ .split(' ')
24
+ .filter(Boolean);
25
+ }
26
+
27
+ function convertToken(t) {
28
+ t = t.toLowerCase();
29
+ if (WORD_TO_NUM[t] !== undefined) return WORD_TO_NUM[t];
30
+ if (/^\d+$/.test(t)) return parseInt(t);
31
+ const m = t.match(/(\w+)\s*([\+\-\*x])\s*(\w+)/);
32
+ if (m) {
33
+ const L = convertToken(m[1]);
34
+ const R = convertToken(m[3]);
35
+ if (typeof L === 'number' && typeof R === 'number') {
36
+ if (m[2] === '+') return L + R;
37
+ if (m[2] === '-') return L - R;
38
+ if (m[2] === '*' || m[2] === 'x') return L * R;
39
+ }
40
+ }
41
+ return null;
42
+ }
43
+
44
+ async function readTextFromBase64(b64) {
45
+ const img = await Jimp.read(buf(b64));
46
+ img.greyscale().contrast(0.5).normalize().resize(400, Jimp.AUTO);
47
+
48
+ const tmp = './tmp_' + Date.now() + '.png';
49
+ await img.writeAsync(tmp);
50
+
51
+ const res = await Tesseract.recognize(tmp,'eng');
52
+ const text = res.data.text.replace(/[^a-zA-Z0-9 ]/g,' ').toLowerCase().trim();
53
+
54
+ fs.unlinkSync(tmp);
55
+ return text;
56
+ }
57
+
58
+ module.exports = async (data) => {
59
+ images.main = data.main;
60
+ images.bots = data.bots;
61
+
62
+ const mainText = await readTextFromBase64(images.main);
63
+ const words = normalizeWords(mainText);
64
+ const orderNumbers = words.map(convertToken).filter(n => n !== null);
65
+
66
+ const botResults = [];
67
+ for (let b of images.bots) {
68
+ const raw = await readTextFromBase64(b.img);
69
+ const num = parseInt(raw.replace(/\D/g,''));
70
+ botResults.push({ id: b.id, number: num });
71
+ }
72
+
73
+ const finalOrder = orderNumbers.map(n => {
74
+ const x = botResults.find(a => a.number === n);
75
+ return x ? x.id : null;
76
+ });
77
+
78
+ return {
79
+ words,
80
+ orderNumbers,
81
+ botResults,
82
+ result: finalOrder
83
+ };
84
+ };
endpoints/cloudflare.js ADDED
@@ -0,0 +1,79 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ async function cloudflare(data, page) {
2
+ return new Promise(async (resolve, reject) => {
3
+ if (!data.domain) return reject(new Error("Missing domain parameter"))
4
+
5
+ const startTime = Date.now()
6
+ let isResolved = false
7
+ let userAgent = null
8
+
9
+ const cl = setTimeout(() => {
10
+ if (!isResolved) {
11
+ isResolved = true
12
+ const elapsedTime = (Date.now() - startTime) / 1000
13
+ resolve({
14
+ cf_clearance: null,
15
+ user_agent: userAgent,
16
+ elapsed_time: elapsedTime,
17
+ })
18
+ }
19
+ }, 20000)
20
+
21
+ try {
22
+ if (data.proxy?.username && data.proxy?.password) {
23
+ await page.authenticate({
24
+ username: data.proxy.username,
25
+ password: data.proxy.password,
26
+ })
27
+ }
28
+
29
+ page.removeAllListeners("request")
30
+ page.removeAllListeners("response")
31
+ await page.setRequestInterception(true)
32
+
33
+ page.on("request", async (req) => {
34
+ try {
35
+ await req.continue()
36
+ } catch (_) {}
37
+ })
38
+
39
+ page.on("response", async (res) => {
40
+ try {
41
+ const url = res.url()
42
+ if (url.includes("/cdn-cgi/challenge-platform/")) {
43
+ const headers = res.headers()
44
+ if (headers["set-cookie"]) {
45
+ const match = headers["set-cookie"].match(/cf_clearance=([^;]+)/)
46
+ if (match) {
47
+ const cf_clearance = match[1]
48
+ const userAgent = (await res.request().headers())["user-agent"]
49
+ const elapsedTime = (Date.now() - startTime) / 1000
50
+
51
+ if (!isResolved) {
52
+ isResolved = true
53
+ clearTimeout(cl)
54
+
55
+ resolve({
56
+ cf_clearance,
57
+ user_agent: userAgent,
58
+ elapsed_time: elapsedTime,
59
+ })
60
+ }
61
+ }
62
+ }
63
+ }
64
+ } catch (_) {}
65
+ })
66
+
67
+ await page.goto(data.domain, { waitUntil: "domcontentloaded" })
68
+ userAgent = await page.evaluate(() => navigator.userAgent)
69
+ } catch (err) {
70
+ if (!isResolved) {
71
+ isResolved = true
72
+ clearTimeout(cl)
73
+ reject(err)
74
+ }
75
+ }
76
+ })
77
+ }
78
+
79
+ module.exports = cloudflare
endpoints/turnstile.js ADDED
@@ -0,0 +1,84 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ async function turnstile({ domain, proxy, siteKey }, page) {
2
+ if (!domain) throw new Error("Missing domain parameter");
3
+ if (!siteKey) throw new Error("Missing siteKey parameter");
4
+
5
+ const timeout = global.timeOut || 60000;
6
+ let isResolved = false;
7
+
8
+ const cl = setTimeout(async () => {
9
+ if (!isResolved) {
10
+ throw new Error("Timeout Error");
11
+ }
12
+ }, timeout);
13
+
14
+ try {
15
+ if (proxy?.username && proxy?.password) {
16
+ await page.authenticate({
17
+ username: proxy.username,
18
+ password: proxy.password,
19
+ });
20
+ }
21
+
22
+ const htmlContent = `
23
+ <!DOCTYPE html>
24
+ <html lang="en">
25
+ <body>
26
+ <div class="turnstile"></div>
27
+ <script src="https://challenges.cloudflare.com/turnstile/v0/api.js?onload=onloadTurnstileCallback" defer></script>
28
+ <script>
29
+ window.onloadTurnstileCallback = function () {
30
+ turnstile.render('.turnstile', {
31
+ sitekey: '${siteKey}',
32
+ callback: function (token) {
33
+ var c = document.createElement('input');
34
+ c.type = 'hidden';
35
+ c.name = 'cf-response';
36
+ c.value = token;
37
+ document.body.appendChild(c);
38
+ },
39
+ });
40
+ };
41
+ </script>
42
+ </body>
43
+ </html>
44
+ `;
45
+
46
+ await page.setRequestInterception(true);
47
+ page.removeAllListeners("request");
48
+ page.on("request", async (request) => {
49
+ if ([domain, domain + "/"].includes(request.url()) && request.resourceType() === "document") {
50
+ await request.respond({
51
+ status: 200,
52
+ contentType: "text/html",
53
+ body: htmlContent,
54
+ });
55
+ } else {
56
+ await request.continue();
57
+ }
58
+ });
59
+
60
+ await page.goto(domain, { waitUntil: "domcontentloaded" });
61
+
62
+ await page.waitForSelector('[name="cf-response"]', { timeout });
63
+
64
+ const token = await page.evaluate(() => {
65
+ try {
66
+ return document.querySelector('[name="cf-response"]').value;
67
+ } catch {
68
+ return null;
69
+ }
70
+ });
71
+
72
+ isResolved = true;
73
+ clearTimeout(cl);
74
+
75
+ if (!token || token.length < 10) throw new Error("Failed to get token");
76
+ return token;
77
+
78
+ } catch (e) {
79
+ clearTimeout(cl);
80
+ throw e;
81
+ }
82
+ }
83
+
84
+ module.exports = turnstile;
index.js ADDED
@@ -0,0 +1,165 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ const express = require('express');
2
+ const { connect } = require("puppeteer-real-browser");
3
+ const fs = require('fs');
4
+ const path = require('path');
5
+
6
+ const app = express();
7
+ const port = process.env.PORT || 7860;
8
+ const authToken = process.env.authToken || null;
9
+ const domain = process.env.DOMAIN || `https://fourstore-antibot.hf.space`;
10
+
11
+ global.browserLimit = Number(process.env.browserLimit) || 20;
12
+ global.timeOut = Number(process.env.timeOut) || 60000;
13
+
14
+ const CACHE_DIR = path.join(__dirname, "cache");
15
+ const CACHE_FILE = path.join(CACHE_DIR, "cache.json");
16
+ const CACHE_TTL = 5 * 60 * 1000;
17
+
18
+ function loadCache() {
19
+ if (!fs.existsSync(CACHE_FILE)) return {};
20
+ try {
21
+ return JSON.parse(fs.readFileSync(CACHE_FILE, 'utf-8'));
22
+ } catch {
23
+ return {};
24
+ }
25
+ }
26
+
27
+ function saveCache(cache) {
28
+ if (!fs.existsSync(CACHE_DIR)) {
29
+ fs.mkdirSync(CACHE_DIR, { recursive: true });
30
+ }
31
+ fs.writeFileSync(CACHE_FILE, JSON.stringify(cache, null, 2), 'utf-8');
32
+ }
33
+
34
+ function readCache(key) {
35
+ const cache = loadCache();
36
+ const entry = cache[key];
37
+ if (entry && Date.now() - entry.timestamp < CACHE_TTL) {
38
+ return entry.value;
39
+ }
40
+ return null;
41
+ }
42
+
43
+ function writeCache(key, value) {
44
+ const cache = loadCache();
45
+ cache[key] = { timestamp: Date.now(), value };
46
+ saveCache(cache);
47
+ }
48
+
49
+ app.use(express.json());
50
+ app.use(express.urlencoded({ extended: true }));
51
+
52
+ app.get("/", (req, res) => {
53
+ res.json({
54
+ message: "Server is running!",
55
+ domain: domain,
56
+ endpoints: {
57
+ cloudflare: `${domain}/cloudflare`,
58
+ antibot: `${domain}/antibot`
59
+ },
60
+ status: {
61
+ browserLimit: global.browserLimit,
62
+ timeOut: global.timeOut,
63
+ authRequired: authToken !== null
64
+ }
65
+ });
66
+ });
67
+
68
+ if (process.env.NODE_ENV !== 'development') {
69
+ let server = app.listen(port, () => {
70
+ console.log(`Server running on port ${port}`);
71
+ console.log(`Domain: ${domain}`);
72
+ console.log(`Auth required: ${authToken !== null}`);
73
+ });
74
+ try {
75
+ server.timeout = global.timeOut;
76
+ } catch {}
77
+ }
78
+
79
+ async function createBrowser(proxyServer = null) {
80
+ const connectOptions = {
81
+ headless: false,
82
+ turnstile: true,
83
+ connectOption: { defaultViewport: null },
84
+ disableXvfb: false,
85
+ };
86
+ if (proxyServer) connectOptions.args = [`--proxy-server=${proxyServer}`];
87
+
88
+ const { browser } = await connect(connectOptions);
89
+ const [page] = await browser.pages();
90
+
91
+ await page.goto('about:blank');
92
+ await page.setRequestInterception(true);
93
+ page.on('request', (req) => {
94
+ const type = req.resourceType();
95
+ if (["image", "stylesheet", "font", "media"].includes(type)) req.abort();
96
+ else req.continue();
97
+ });
98
+
99
+ return { browser, page };
100
+ }
101
+
102
+ const turnstile = require('./endpoints/turnstile');
103
+ const cloudflare = require('./endpoints/cloudflare');
104
+ const antibot = require('./endpoints/antibot');
105
+
106
+ app.post('/cloudflare', async (req, res) => {
107
+ const data = req.body;
108
+ if (!data || typeof data.mode !== 'string')
109
+ return res.status(400).json({ message: 'Bad Request: missing or invalid mode' });
110
+
111
+ if (global.browserLimit <= 0)
112
+ return res.status(429).json({ message: 'Too Many Requests' });
113
+
114
+ let cacheKey, cached;
115
+ if (data.mode === "iuam") {
116
+ cacheKey = JSON.stringify(data);
117
+ cached = readCache(cacheKey);
118
+ if (cached) return res.status(200).json({ ...cached, cached: true });
119
+ }
120
+
121
+ global.browserLimit--;
122
+ let result, browser;
123
+
124
+ try {
125
+ const proxyServer = data.proxy ? `${data.proxy.hostname}:${data.proxy.port}` : null;
126
+ const ctx = await createBrowser(proxyServer);
127
+ browser = ctx.browser;
128
+ const page = ctx.page;
129
+
130
+ await page.goto('about:blank');
131
+
132
+ switch (data.mode) {
133
+ case "turnstile":
134
+ result = await turnstile(data, page).then(t => ({ token: t }));
135
+ break;
136
+
137
+ case "iuam":
138
+ result = await cloudflare(data, page).then(r => ({ ...r }));
139
+ writeCache(cacheKey, result);
140
+ break;
141
+
142
+ case "antibot":
143
+ result = await antibot();
144
+ break;
145
+
146
+ default:
147
+ result = { code: 400, message: 'Invalid mode' };
148
+ }
149
+ } catch (err) {
150
+ result = { code: 500, message: err.message };
151
+ } finally {
152
+ if (browser) try { await browser.close(); } catch {}
153
+ global.browserLimit++;
154
+ }
155
+
156
+ res.status(result.code ?? 200).json(result);
157
+ });
158
+
159
+ app.use((req, res) => {
160
+ res.status(404).json({ message: 'Not Found' });
161
+ });
162
+
163
+ if (process.env.NODE_ENV === 'development') {
164
+ module.exports = app;
165
+ }
package.json ADDED
@@ -0,0 +1,18 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ {
2
+ "name": "cf-bypass",
3
+ "version": "1.0",
4
+ "description": "get the cf_clearance cookie from any website",
5
+ "scripts": {
6
+ "start": "node index.js",
7
+ "dev": "nodemon index.js"
8
+ },
9
+ "dependencies": {
10
+ "express": "^5.1.0",
11
+ "puppeteer-real-browser": "^1.4.0",
12
+ "tesseract.js": "^5.0.3",
13
+ "jimp": "^0.22.10"
14
+ },
15
+ "devDependencies": {
16
+ "nodemon": "^3.1.10"
17
+ }
18
+ }