ESC
开源 3 分钟阅读

turnstile-bypass:跨平台 Cloudflare Turnstile 破解工具(支持 macOS、Windows、Linux)

开源项目 turnstile-bypass 发布,支持 macOS、Windows 和 Linux。该工具通过驱动有界面 Chrome 破解 Cloudflare 的两层防护:Turnstile 验证组件与插页式等待页,可获取 token 和 cf_clearance cookie,实测约 9 秒即可通过 grok.com 的质询。但不支持绕过 IP 封禁、速率限制和 WAF 拦截。

来源:GitHub

turnstile-bypass

适用于 macOS、Windows 和 Linux 的自包含 Cloudflare 挑战辅助工具。

它驱动有界面(headed)的 Chrome 通过人们通常称之为“盾”的两层 CF 防护:

  1. 站点页面上的 Turnstile 组件(例如 aipaycards.com/login)→ JSON token
  2. 插页式等待室(请稍候… / Just a moment,例如 grok.com)→ cf_clearance 和真实源站

curl https://grok.com/ 返回 403 + cf-mitigated: challenge。运行 solve.py --url https://grok.com/ --fresh 后,同一个 Chrome 标签页就变成了带有 cf_clearance cookie 的 Grok 应用。

它无法通过 IP 封禁(1020)、速率限制(1015),也无法在此 Chrome 已被拒绝时通过 Bot Fight。

新 agent 应按照 Install(安装)然后 Use(使用)的步骤操作,无需其他任何东西。

安装

需要:Python 3.10+、Google Chrome 或 Chromium。

git clone https://github.com/Sophomoresty/turnstile-bypass.git
cd turnstile-bypass
python3 scripts/install.py

install.py 会在本仓库中创建 .venv,安装 requirements.txt(DrissionPage),打包 assets/turnstilePatch.zip,并运行 scripts/preflight.py。

你应该看到:

{ "ok": true, "methods": { "drissionpage": true } }
操作系统如果找不到 Chrome
macOS安装 Google Chrome,或 export CHROME_PATH="/Applications/Google Chrome.app/Contents/MacOS/Google Chrome"
Windowsset CHROME_PATH=C:\Path\to\chrome.exe
Linuxsudo apt-get install -y google-chrome-stable 或 chromium
Linux 无桌面sudo apt-get install -y xvfb,然后在命令前加 xvfb-run -a

手动安装(效果相同):

python3 -m venv .venv
.venv/bin/python -m pip install -r requirements.txt   # Windows: .venv\Scripts\python.exe
python3 scripts/pack_extension.py
python3 scripts/preflight.py

使用

python3 scripts/solve.py --url "https://aipaycards.com/login"
python3 scripts/solve.py --url "https://grok.com/" --fresh

标准输出为一个 JSON 对象。

  • 组件破解成功:"ok": true 且 token 长度超过 20 个字符。请立即使用(TTL 约 300 秒)。
  • 等待室破解成功(grok.com):"ok": true 且 kind 为 cf_clearance 或 cf_passed,clearanceLen > 20。该标签页即为真实站点。
  • 失败:"ok": false 且返回 error。不要凭空编造 token。

强制指定通道:

python3 scripts/solve.py --lane drission --url "https://example.com/login"
python3 scripts/solve.py --lane ab --url "https://example.com/login"

无 GUI 的 Linux:

xvfb-run -a python3 scripts/solve.py --url "https://example.com/login"

默认通道:运行 install.py 后为 DrissionPage + 打包的扩展。如果 agent-browser-cli 和 Node 已在 PATH 中,solve.py 会优先使用更快的通道(TURNSTILE_PREFER_AB=0 可强制使用 Drission)。

--lane ab 是可选的,且仅在 agent-browser-cli + Node 已安装并且该 Chrome 已装此扩展时才更快。Iframe 点击必须使用 Chrome CDP(默认端口 19221),绝不要用 shim 的 19222。

YesCaptcha(最后手段):设置 YESCAPTCHA_CLIENT_KEY 并运行

python3 scripts/solve.py --lane yescaptcha --url "https://example.com" --sitekey "0x..."

Chrome 扩展

事实来源:assets/turnstilePatch/(以未打包方式加载)。

打包副本:assets/turnstilePatch.zip(相同的两个文件)。使用 python3 scripts/pack_extension.py 重新构建。

该扩展为 Manifest V3,world: MAIN,all_frames,仅匹配 https://challenges.cloudflare.com/*。它修补了 MouseEvent.screenX/Y,因为 Chrome CDP 点击会将屏幕坐标设置为与客户端坐标相同(chromium 40280325),而 Turnstile 会将此视为机器人行为。

手动加载未打包扩展: chrome://extensions → 开发者模式 → 加载已解压的扩展程序 → 选择 assets/turnstilePatch/。

DrissionPage 会通过 add_extension 自动完成此操作。默认的 solve.py 路径不需要你手动点击该 UI。

它不是什么

范围内范围外
源站页面上的 Turnstile 组件Cloudflare 1020 / 1015 / WAF 拦截
插页式“请稍候…”/ Just a moment(JS 或托管质询)此 Chrome 已被封禁时的 Bot Fight
cf_clearance + 源站 HTMLhCaptcha、reCAPTCHA、无头 Chrome

已验证

macOS、Chrome 152、agent-browser、CDP 19221。

目标内容结果时间
https://demo.turnstile.workers.dev/虚拟 TurnstiletokenLen 213.46s
examples/interactive-dummy.html虚拟交互式tokenLen 217.46s
https://aipaycards.com/login生产环境 TurnstiletokenLen 816,3/38–11s
https://grok.com/插页(cf-mitigated: challenge)kind=cf_clearance,clearanceLen 533–597,源站标题为 Grok约 9s(--fresh)

不经过此 Chrome 直接 curl grok.com 会得到 403 + cf-mitigated: challenge。破解后,同一个标签页就是 Grok 应用。插页路径会将标签页置于前台(Page.bringToFront)并点击 CF iframe;如果 document.visibilityState 为 hidden,等待室 JS 通常会拒绝完成。

python3 scripts/solve.py --url "https://grok.com/" --fresh
python3 scripts/e2e.py

目录结构

AGENTS.md                 # 面向编码 agent 的简短运行手册
README.md                 # 本文件
LICENSE
requirements.txt          # DrissionPage
assets/turnstilePatch/    # 未打包的 MV3 扩展
assets/turnstilePatch.zip # 相同内容的 zip 包
examples/interactive-dummy.html
scripts/install.py            # venv + 依赖 + 打包 + 预检
scripts/e2e.py                # 实时双页面检查;仅在成功时退出码为 0
scripts/preflight.py
scripts/solve.py          # 入口
scripts/solve_turnstile.py
scripts/pack_extension.py
scripts/solve_agent_browser.py
scripts/camoufox_turnstile.py
scripts/solve_yescaptcha.py
scripts/proxy_auth_extension.py
scripts/runtime.py

限制

  • 仅支持有界面 Chrome。插页破解需要标签页可见(Page.bringToFront)。
  • 数据中心 IP 经常失败;用住宅代理重试一次,然后停止。
  • 不要跨会话缓存 token。
  • 不适用于 1020/1015/WAF 拦截,也不是指纹浏览器。

本项目的开发 agent 能力由 GenericAgent 提供。

🚩 友情链接

GenericAgent LinuxDo

许可证

MIT。详见 LICENSE。