跳到正文

CircuitSavage

cloudflare-turnstile-reversed

Cloudflare Turnstile challenge internals: the live request flow, the challenge bundle, and a capture toolkit.

README 已保存到本站,可直接阅读

Documentation snapshot

README 快照

这篇是英文原文

下面正文是项目自己的英文 README。想读全文就用浏览器自带的整页翻译: Chrome / Edge 点地址栏右侧的翻译图标,或用右键菜单里的「翻译成中文」; 手机浏览器一般在菜单里。

本页保存的是公开项目资料快照,阅读过程不需要连接 GitHub。

cloudflare-turnstile-reversed

A sourced teardown of how Cloudflare Turnstile fingerprints and scores browsers, plus a live capture tool. Every claim is cited or tagged [observed] / (inferred) — no filler, no memory guesses.

Need it solved, not studied? Peak solves Cloudflare Turnstile and the 5s challenge via API — pay per success, from $1/1K, free key, no card. (reCAPTCHA coming soon.)


Docs

  • docs/fingerprinting/ — the deep layer: 8 per-field teardowns (behavioral, automation-tells, canvas, WebGL, audio, device-coherence, TLS/HTTP2, IP/scoring/PoW), each cited and tagged confirmed/observed/inferred. Start at its index.
  • docs/03-fingerprinting.md — the one-page fingerprinting overview (surface map; the docs/fingerprinting/ set goes deeper per field).
  • docs/04-loader-internals.md — concrete code from the real bundle: the [native code] hook-detection function, the isTrusted interaction gate, stack/timing telemetry, the endpoint builder.
  • docs/01-challenge-flow.md — the live request flow (loader → versioned bundle → challenge-platform), captured.
  • docs/02-widget-params.md — the widget parameters the bundle reads (sitekey, cData, action, chlPageData).

Tool

tools/capture.py — pull the sitekey / cData / action off a page; --solve returns a token.

python tools/capture.py https://example.com/
PEAK_API_KEY=pk_your_key python tools/capture.py https://example.com/ --solve

Scope

Is: a sourced map of the fingerprinting surface (which signals, collected where) and capture tooling. Isn’t: a byte-level deobfuscation of the versioned bundle, the challenge-platform payload schema, or token construction — and not a token-forgery method, since tokens are single-use and validated server-side via siteverify.

Legitimate use

Research and automation on data you are allowed to access. Respect each site’s Terms of Service and robots.txt. No credential stuffing.

License

MIT.

Official distribution

获取与安装

暂未发现可确认的官方软件包地址

当前 README 快照没有出现 npm、PyPI、Crates.io、pub.dev 等官方包页链接。本站不会根据仓库名称猜测下载地址。

本站不托管项目文件;需要安装时,请以项目维护者发布的官方文档为准。

使用前核验

本站保存公开资料用于阅读,不代表安全审计或功能背书。安装前请核对许可证、依赖来源和发布签名,不要直接运行来源不明的二进制文件或高权限脚本。