Python Requests触发Cloudflare拦截返回403,BurpSuite请求正常求助
Python请求返回403但BurpSuite可正常请求的解决方案
问题场景
以下代码使用requests库发送请求时返回403状态码,但通过BurpSuite使用相同IP、相同请求头发起请求却能正常响应:
import requests , json from collections import OrderedDict def Core(): response = requests.Session() headers = OrderedDict({'Authorization': 'bearer 0', 'BrandType': '1', 'AppBrand': '1', 'Accept-Language': 'en-US', 'X-Device-Source': '6', 'X-Device-Version': '9.99', 'Content-Type': 'application/json', 'User-Agent': 'Dalvik/2.1.0 (11)', 'Host': 'api.talabat.com', 'Connection': 'close'}) url = 'https://api.talabat.com/apiAndroid/v2/customer/verifyoption' response = requests.get(url, headers=headers) print(response.status_code) print(response.text) Core()
核心原因及解决方法
1. 请求头顺序被自动调整
requests库会自动调整部分请求头的顺序(比如Host头会被强制前置),而部分服务器会校验请求头的顺序,不符合要求就返回403。BurpSuite则严格按照你设置的顺序发送请求,所以能通过校验。
解决代码:手动构建PreparedRequest,确保请求头顺序完全一致:
import requests from collections import OrderedDict def Core(): session = requests.Session() # 按Burp中使用的顺序定义请求头 headers = OrderedDict([ ('Authorization', 'bearer 0'), ('BrandType', '1'), ('AppBrand', '1'), ('Accept-Language', 'en-US'), ('X-Device-Source', '6'), ('X-Device-Version', '9.99'), ('Content-Type', 'application/json'), ('User-Agent', 'Dalvik/2.1.0 (11)'), ('Host', 'api.talabat.com'), ('Connection', 'close') ]) url = 'https://api.talabat.com/apiAndroid/v2/customer/verifyoption' # 构建预请求,保留头顺序 req = requests.Request('GET', url, headers=headers) prepared = session.prepare_request(req) # 删除requests自动添加的干扰头(比如Accept-Encoding) for header in ['Accept-Encoding']: if header in prepared.headers: del prepared.headers[header] # 发送预构建的请求 response = session.send(prepared) print(response.status_code) print(response.text) Core()
2. TLS指纹被识别
requests默认的TLS指纹和真实客户端(或BurpSuite)差异较大,服务器通过TLS特征识别出是脚本请求,返回403。
解决代码:使用curl_cffi库模拟Android设备的TLS指纹:
from curl_cffi import requests def Core(): headers = { 'Authorization': 'bearer 0', 'BrandType': '1', 'AppBrand': '1', 'Accept-Language': 'en-US', 'X-Device-Source': '6', 'X-Device-Version': '9.99', 'Content-Type': 'application/json', 'User-Agent': 'Dalvik/2.1.0 (11)', 'Host': 'api.talabat.com', 'Connection': 'close' } url = 'https://api.talabat.com/apiAndroid/v2/customer/verifyoption' # 模拟Android设备的TLS指纹,匹配Burp的请求特征 response = requests.get(url, headers=headers, impersonate='android') print(response.status_code) print(response.text) Core()
说明
- 第一种方法通过强制保留请求头顺序、移除自动添加的冗余头,让请求和Burp发送的完全一致。
- 第二种方法通过模拟真实设备的TLS指纹,绕过服务器基于TLS特征的反爬检测,这是很多403问题的核心原因。
内容的提问来源于stack exchange,提问作者John Duo
相关产品推荐
相关产品推荐

