Menu

Obejście Amazon WAF za pomocą serwera proxy

Istnieją 2 opcje, w jaki sposób captcha jest używana na stronach docelowych:

1. Strona filtrująca boty, którą Amazon wyświetla automatycznie, gdy odwiedzasz witrynę za ich zaporą ogniową. Nazywamy ją "gokuProps", ponieważ w kodzie źródłowym tej strony można znaleźć parametry window.gokuProps.

2. Samodzielny widget captcha, który jest uruchamiany przez akcję użytkownika. Nazywamy go Widget.

Samodzielnie określ typ captcha i użyj przełącznika poniżej, aby wyświetlić różne wersje dokumentacji i przykładów.

gokuProps
Widget

Zadania tego typu pozwalają uzyskać token cookie Amazon WAF. Wystarczy pobrać tymczasowe tokeny iv i context wraz ze stałym kluczem witryny key i wysłać je do naszego API. Wynikiem zadania jest token, który można wykorzystać w żądaniu HTTP jako wartość pliku cookie o nazwie amazon-waf-token.

Ten typ zadania wymaga proxy. Używaj go tylko wtedy, gdy zadania bez proxy (AmazonTaskProxyless) zawodzą, ponieważ spowalnia to naszych pracowników. Rozwiązywanie captcha za pomocą serwerów proxy wymaga również bardzo wysokiej jakości serwerów proxy, które należy zainstalować samodzielnie na własnych serwerach VPS i nigdy nie korzystać z zakupionych usług proxy.

Amazon WAF captcha example Amazon WAF widget captcha example
Przykład Captcha
gokuProps
Widget
Python
Node.js
Go
PHP
Java
C#
bash

Jak rozwiązać Amazon proxy-on WAF gokuProps w Python

#pip3 install anticaptchaofficial

from anticaptchaofficial.amazonproxyon import *

solver = amazonProxon()
solver.set_verbose(1)
solver.set_key("YOUR_API_KEY")
solver.set_website_url("https://website.com")
solver.set_website_key("key_value_from_window.gokuProps_object")
solver.set_iv("iv_value_from_window.gokuProps_object")
solver.set_context("context_value_from_window.gokuProps_object")
solver.set_proxy_address("PROXY_ADDRESS")
solver.set_proxy_port(1234)
solver.set_proxy_login("proxylogin")
solver.set_proxy_password("proxypassword")

# Optional script URLs
solver.set_captcha_script("https://e9b10f157f38.9a96e8b4.us-gov-west-1.captcha.awswaf.com/e9b10f157f38/76cbcde1c834/2a564e323e7b/captcha.js")
solver.set_challenge_script("https://e9b10f157f38.9a96e8b4.us-gov-west-1.token.awswaf.com/e9b10f157f38/76cbcde1c834/2a564e323e7b/challenge.js")

# Specify softId to earn 10% commission with your app.
# Get your softId here: https://anti-captcha.com/clients/tools/devcenter
solver.set_soft_id(0)

token = solver.solve_and_return_solution()
if token != 0:
    print("token: "+token)
    # user-agent in case you need it:
    print("user-agent: "+solver.get_user_agent())
else:
    print("task finished with error "+solver.error_code)

Jak rozwiązać Amazon proxy-on WAF gokuProps w Node.js

//npm install @antiadmin/anticaptchaofficial
//https://github.com/anti-captcha/anticaptcha-npm

const ac = require("@antiadmin/anticaptchaofficial");

ac.setAPIKey('YOUR_API_KEY_HERE');

//Specify softId to earn 10% commission with your app.
//Get your softId here: https://anti-captcha.com/clients/tools/devcenter
ac.setSoftId(0);

ac.solveAmazonProxyOn('http://DOMAIN.COM',
    'key_value_from_window.gokuProps_object',
    'http', //http, socks4, socks5
    'PROXY_ADDRESS',
    'PROXY_PORT',
    'PROXY_LOGIN',
    'PROXY_PASSWORD',
    'iv_value_from_window.gokuProps_object',
    'context_value_from_window.gokuProps_object',
    'https://e9b10f157f38.9a96e8b4.us-gov-west-1.captcha.awswaf.com/e9b10f157f38/76cbcde1c834/2a564e323e7b/captcha.js', //optional
    'https://e9b10f157f38.9a96e8b4.us-gov-west-1.token.awswaf.com/e9b10f157f38/76cbcde1c834/2a564e323e7b/challenge.js'  //optional
).then(token => {
    console.log('token: '+token);
})
.catch(error => console.log('test received error '+error));

// in case you need it
console.log("worker's user-agent:");
console.log(ac.getUserAgent());`;

Jak rozwiązać Amazon proxy-on WAF gokuProps w Go

// Install with:
// go get github.com/anti-captcha/anticaptcha-go
package main

import (
    "fmt"
    "github.com/anti-captcha/anticaptcha-go"
    "log"
)

func main() {
    // Create API client and set the API Key
    ac := anticaptcha.NewClient("API_KEY_HERE")

    // set to 'false' to turn off debug output
    ac.IsVerbose = true

    // Specify softId to earn 10% commission with your app.
    // Get your softId here: https://anti-captcha.com/clients/tools/devcenter
    //ac.SoftId = 1187

    // Make sure the API key funds balance is positive
    balance, err := ac.GetBalance()
    if err != nil {
        log.Fatal(err)
        // Exit program to make sure you don't DDoS API with requests, while having empty balance
        return
    }
    fmt.Println("Balance:", balance)

    // Get Amazon WAF token without proxy
    solution, err := ac.SolveAmazonProxyOn(anticaptcha.AmazonCaptcha{
        WebsiteURL: "https://www.website.com/",
        WebsiteKey: "key_value_from_window.gokuProps_object",
        Iv: "iv_value_from_window.gokuProps_object",
        Context: "context_value_from_window.gokuProps_object",
        //optional scripts:
        //CaptchaScript: "https://e9b10f157f38.9a96e8b4.us-gov-west-1.captcha.awswaf.com/e9b10f157f38/76cbcde1c834/2a564e323e7b/captcha.js",
        //ChallengeScript: "https://e9b10f157f38.9a96e8b4.us-gov-west-1.token.awswaf.com/e9b10f157f38/76cbcde1c834/2a564e323e7b/challenge.js",
        Proxy: &anticaptcha.Proxy{
            Type:      "http",
            IPAddress: "1.2.3.4",
            Port:      1234,
            Login:     "login-optional",
            Password:  "pass-optional",
        },
    })
    if err != nil {
        log.Fatal(err)
    }
    fmt.Println("amazon-waf-token:", solution)
    // In case you need the worker's user-agent
    fmt.Println("User-Agent:", ac.WorkersUserAgent)
}

Jak rozwiązać Amazon proxy-on WAF gokuProps w PHP

//git clone https://github.com/anti-captcha/anticaptcha-php.git

include("anticaptcha.php");
include("amazon.php");

$api = new Amazon();
$api->setVerboseMode(true);

//your anti-captcha.com account key
$api->setKey("YOUR_API_KEY_HERE");

//target website address
$api->setWebsiteURL("http://website.com/");

//key value from window.gokuProps object (see html source)
$api->setWebsiteKey("key_value_from_window.gokuProps_object");

//iv and context values from window.gokuProps object (see html source)
$api->setIv("iv_value_from_window.gokuProps_object")
$api->setContext("context_value_from_window.gokuProps_object");

//optional scripts
$api->setCaptchaScript("https://e9b10f157f38.9a96e8b4.us-gov-west-1.captcha.awswaf.com/e9b10f157f38/76cbcde1c834/2a564e323e7b/captcha.js");
$api->setChallengeScript("https://e9b10f157f38.9a96e8b4.us-gov-west-1.token.awswaf.com/e9b10f157f38/76cbcde1c834/2a564e323e7b/challenge.js");

// proxy access parameters
// DO NOT USE PURCHASED/RENTED PROXIES ON PROXY SERVICES!!!
// THEY WILL NOT WORK!
// USE ONLY PROXIES YOU INSTALL YOURSELF ON YOUR OWN SERVER OR FAST VPS
// USE PROPER PROXY SOFTWARE LIKE SQUID !
// INSTALLATION INSTRUCTIONS:
// https://anti-captcha.com/apidoc/articles/how-to-install-squid
$api->setProxyType("http");
$api->setProxyAddress("8.8.8.8");
$api->setProxyPort(1234);
//optional login and password
$api->setProxyLogin("login");
$api->setProxyPassword("password");

//Specify softId to earn 10% commission with your app.
//Get your softId here: https://anti-captcha.com/clients/tools/devcenter
$api->setSoftId(0);

//create task in API
if (!$api->createTask()) {
    $api->debout("API v2 send failed - ".$api->getErrorMessage(), "red");
    return false;
}

$taskId = $api->getTaskId();

//wait in a loop for max 300 seconds till task is solved
if (!$api->waitForResult(300)) {
    echo "could not solve captcha\n";
    echo $api->getErrorMessage()."\n";
} else {

    $token = $api->getTaskSolution();
    echo "\n";
    echo "your aws-waf-token: $token\n\n";
    echo "worker's user-agent in case you need it:\n";
    echo $api->getWorkersUserAgent()."\n";

}

Jak rozwiązać Amazon proxy-on WAF gokuProps w Java

//git clone https://github.com/anti-captcha/anticaptcha-java.git

package com.anti_captcha;

import com.anti_captcha.Api.Amazon;
import com.anti_captcha.Helper.DebugHelper;

import org.json.JSONArray;
import org.json.JSONException;
import org.json.JSONObject;

import java.net.MalformedURLException;
import java.net.URL;
import java.util.Iterator;
import java.util.concurrent.ThreadLocalRandom;

public class Main {

    public static void main(String[] args) throws InterruptedException, MalformedURLException, JSONException {

        DebugHelper.setVerboseMode(true);

        AmazonProxyless api = new Amazon();
        api.setClientKey("YOUR_API_KEY_HERE");
        api.setWebsiteUrl(new URL("http://website.com/"));
        api.setWebsiteKey("key_value_from_window.gokuProps_object");
        api.setIv("iv_value_from_window.gokuProps_objec");
        api.setContext("context_value_from_window.gokuProps_object");

        //Optional scripts
        api.setCaptchaScript("https://e9b10f157f38.9a96e8b4.us-gov-west-1.captcha.awswaf.com/e9b10f157f38/76cbcde1c834/2a564e323e7b/captcha.js");
        api.setChallengeScript("https://e9b10f157f38.9a96e8b4.us-gov-west-1.token.awswaf.com/e9b10f157f38/76cbcde1c834/2a564e323e7b/challenge.js");

        // proxy access parameters
        // DO NOT USE PURCHASED/RENTED PROXIES WITH PROXY SERVICES!!!
        // THEY WILL NOT WORK!
        // USE ONLY PROXIES YOU INSTALL YOURSELF ON YOUR OWN SERVER OR FAST VPS
        // USE PROPER PROXY SOFTWARE LIKE SQUID !
        // INSTALLATION INSTRUCTIONS:
        // https://anti-captcha.com/apidoc/articles/how-to-install-squid
        api.setProxyType(NoCaptcha.ProxyTypeOption.HTTP);
        api.setProxyAddress("xx.xxx.xx.xx");
        api.setProxyPort(8282);
        api.setProxyLogin("login");
        api.setProxyPassword("password");

        //Specify softId to earn 10% commission with your app.
        //Get your softId here: https://anti-captcha.com/clients/tools/devcenter
        api.setSoftId(0);

        if (!api.createTask()) {
            DebugHelper.out(
                    "API v2 send failed. " + api.getErrorMessage(),
                    DebugHelper.Type.ERROR
            );
        } else if (!api.waitForResult()) {
            DebugHelper.out("Could not solve the captcha.", DebugHelper.Type.ERROR);
        } else {
            DebugHelper.out("Result: " + api.getTaskSolution().getToken(), DebugHelper.Type.SUCCESS);
        }
    }
}

Jak rozwiązać Amazon proxy-on WAF gokuProps w C#

//git clone git@github.com:AdminAnticaptcha/anticaptcha-csharp.git

using System;
using Anticaptcha_example.Api;
using Anticaptcha_example.Helper;
using Newtonsoft.Json.Linq;

namespace Anticaptcha_example
{
    internal class Program
    {
        private static void Main() {

            DebugHelper.VerboseMode = true;

            var api = new Amazon
            {
                ClientKey = "YOUR_API_KEY_HERE",
                WebsiteUrl = new Uri("http://website.com/"),
                WebsiteKey = "key_value_from_window.gokuProps_object",
                Iv = "iv_value_from_window.gokuProps_object",
                Context = "context_value_from_window.gokuProps_object",
                ProxyAddress = "xxx.xx.xx.xx",
                ProxyPort = 1234,
                ProxyLogin = "login",
                ProxyPassword = "password",

                // Optional scripts
                CaptchaScript = "https://e9b10f157f38.9a96e8b4.us-gov-west-1.captcha.awswaf.com/e9b10f157f38/76cbcde1c834/2a564e323e7b/captcha.js",
                ChallengeScript = "https://e9b10f157f38.9a96e8b4.us-gov-west-1.token.awswaf.com/e9b10f157f38/76cbcde1c834/2a564e323e7b/challenge.js",

                // Specify softId to earn 10% commission with your app.
                // Get your softId here:
                // https://anti-captcha.com/clients/tools/devcenter
                SoftId = 0
            };

            if (!api.CreateTask())
                DebugHelper.Out("API v2 send failed. " + api.ErrorMessage, DebugHelper.Type.Error);
            else if (!api.WaitForResult())
                DebugHelper.Out("Could not solve the captcha.", DebugHelper.Type.Error);
            else
                DebugHelper.Out("Result: " + api.GetTaskSolution().token, DebugHelper.Type.Success);

        }
    }
}

Jak rozwiązać Amazon proxy-on WAF gokuProps w bash

curl -i -H "Accept: application/json" \
     -H "Content-Type: application/json" \
     -X POST -d '{
    "clientKey":"YOUR_API_KEY_HERE",
    "task":
        {
            "type":"AmazonTask",
            "websiteURL":"https://website.com/",
            "websiteKey":"key_value_from_window.gokuProps_object",
            "iv":"iv_value_from_window.gokuProps_object",
            "context":"context_value_from_window.gokuProps_object",
            "captchaScript": "https://e9b10f157f38.9a96e8b4.us-gov-west-1.captcha.awswaf.com/e9b10f157f38/76cbcde1c834/2a564e323e7b/captcha.js",
            "challengeScript": "https://e9b10f157f38.9a96e8b4.us-gov-west-1.token.awswaf.com/e9b10f157f38/76cbcde1c834/2a564e323e7b/challenge.js",
            "proxyType":"http",
            "proxyAddress":"8.8.8.8",
            "proxyPort":8080,
            "proxyLogin":"proxyLoginHere",
            "proxyPassword":"proxyPasswordHere"
        },
    "softId": 0
}' https://api.anti-captcha.com/createTask
gokuProps
Widget

Obiekt typu zadanie

Właściwość/atrybut Typ Wymagany Przeznaczenie
type Łańcuch znaków (String) Tak AmazonTask
websiteURL Łańcuch znaków (String) Tak Adres docelowej strony. Może znajdować się w dowolnym miejscu witryny, włącznie ze strefami dla zalogowanych. Nasi pracownicy nie muszą tam wchodzić, gdyż wizyta jest symulowana.
websiteKey Łańcuch znaków (String) Tak Wartość key z obiektu window.gokuProps w kodzie źródłowym strony WAF.
iv Łańcuch znaków (String) Tak Wartość iv z obiektu window.gokuProps w kodzie źródłowym strony WAF.
context Łańcuch znaków (String) Tak Wartość context z obiektu window.gokuProps w kodzie źródłowym strony WAF.
captchaScript Łańcuch znaków (String) Nie Opcjonalny adres URL prowadzący do captcha.js
challengeScript Łańcuch znaków (String) Nie Opcjonalny adres URL prowadzący do challenge.js
proxyType Łańcuch znaków (String) Tak Typ proxy
http - typowe proxy http/https
socks4 - proxy socks4
socks5 - proxy socks5
proxyAddress Łańcuch znaków (String) Tak Adres IPv4/IPv6 proxy. Nie stosować nazw hostów ani adresów IP z sieci lokalnych.
proxyPort Integer Tak Port proxy
proxyLogin Łańcuch znaków (String) Tak Login dla proxy wymagających uwierzytelniania (podstawowe)
proxyPassword Łańcuch znaków (String) Tak Hasło proxy

Obiekt typu rozwiązanie zadania

Właściwość/atrybut Typ Przeznaczenie
token Łańcuch znaków (String) Użyj tego tokena jako wartości pliku cookie o nazwie "aws-waf-token" w żądaniu do docelowej strony internetowej.
userAgent Łańcuch znaków (String) User-Agent przeglądarki pracownika. Użyj go podczas przesyłania tokena odpowiedzi.

Przykład odpowiedzi

{
    "errorId":0,
    "status":"ready",
    "solution": {
      "token": "fe4c2ff3-6ed6-40fa-95c9-4c738a7dad49:FgoAe0ZLBmYBAAAA:LK0S/m1nGbfjDk/9i6tMmiUWGecMfyjvuAx9lY6ZhaBUmjrILEqW00UAsEliykPjwebdzn9J3...",
      "userAgent":"Mozilla\5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/145.0.0.0 Safari\/537.36"
    },
    "cost":"0.002000",
    "ip":"46.98.54.221",
    "createTime":1472205564,
    "endTime":1472205570,
    "solveCount":"0"
}