You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Python Requests触发Cloudflare拦截返回403,BurpSuite请求正常求助

Python请求返回403但BurpSuite可正常请求的解决方案

问题场景

以下代码使用requests库发送请求时返回403状态码,但通过BurpSuite使用相同IP、相同请求头发起请求却能正常响应:

import requests , json
from collections import OrderedDict
def Core(): 
            response = requests.Session()
            headers = OrderedDict({'Authorization': 'bearer 0',    
                    'BrandType': '1',                            
                    'AppBrand': '1',
                    'Accept-Language': 'en-US',                    
                    'X-Device-Source': '6',
                    'X-Device-Version': '9.99',                     
                    'Content-Type': 'application/json',    
                    'User-Agent': 'Dalvik/2.1.0 (11)',
                    'Host': 'api.talabat.com',                   
                    'Connection': 'close'})
            url = 'https://api.talabat.com/apiAndroid/v2/customer/verifyoption'
            response = requests.get(url, headers=headers)
            print(response.status_code)
            print(response.text)                 

Core()

核心原因及解决方法

1. 请求头顺序被自动调整

requests库会自动调整部分请求头的顺序(比如Host头会被强制前置),而部分服务器会校验请求头的顺序,不符合要求就返回403。BurpSuite则严格按照你设置的顺序发送请求,所以能通过校验。

解决代码:手动构建PreparedRequest,确保请求头顺序完全一致:

import requests
from collections import OrderedDict

def Core():
    session = requests.Session()
    # 按Burp中使用的顺序定义请求头
    headers = OrderedDict([
        ('Authorization', 'bearer 0'),
        ('BrandType', '1'),
        ('AppBrand', '1'),
        ('Accept-Language', 'en-US'),
        ('X-Device-Source', '6'),
        ('X-Device-Version', '9.99'),
        ('Content-Type', 'application/json'),
        ('User-Agent', 'Dalvik/2.1.0 (11)'),
        ('Host', 'api.talabat.com'),
        ('Connection', 'close')
    ])
    url = 'https://api.talabat.com/apiAndroid/v2/customer/verifyoption'
    
    # 构建预请求,保留头顺序
    req = requests.Request('GET', url, headers=headers)
    prepared = session.prepare_request(req)
    
    # 删除requests自动添加的干扰头(比如Accept-Encoding)
    for header in ['Accept-Encoding']:
        if header in prepared.headers:
            del prepared.headers[header]
    
    # 发送预构建的请求
    response = session.send(prepared)
    print(response.status_code)
    print(response.text)

Core()

2. TLS指纹被识别

requests默认的TLS指纹和真实客户端(或BurpSuite)差异较大,服务器通过TLS特征识别出是脚本请求,返回403。

解决代码:使用curl_cffi库模拟Android设备的TLS指纹:

from curl_cffi import requests

def Core():
    headers = {
        'Authorization': 'bearer 0',
        'BrandType': '1',
        'AppBrand': '1',
        'Accept-Language': 'en-US',
        'X-Device-Source': '6',
        'X-Device-Version': '9.99',
        'Content-Type': 'application/json',
        'User-Agent': 'Dalvik/2.1.0 (11)',
        'Host': 'api.talabat.com',
        'Connection': 'close'
    }
    url = 'https://api.talabat.com/apiAndroid/v2/customer/verifyoption'
    
    # 模拟Android设备的TLS指纹,匹配Burp的请求特征
    response = requests.get(url, headers=headers, impersonate='android')
    print(response.status_code)
    print(response.text)

Core()

说明

  • 第一种方法通过强制保留请求头顺序、移除自动添加的冗余头,让请求和Burp发送的完全一致。
  • 第二种方法通过模拟真实设备的TLS指纹,绕过服务器基于TLS特征的反爬检测,这是很多403问题的核心原因。

内容的提问来源于stack exchange,提问作者John Duo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 03:41:09