使用CURL请求rumah.com返回403 Forbidden问题求助
Hey there! Let's break down why you might be hitting that 403 Forbidden error despite setting up those cURL parameters. I’ve spotted a few key issues and fixes based on your code:
1. Fix the Invalid CURLOPT_COOKIE Setting
Your line curl_setopt($ch,CURLOPT_COOKIE,1); is incorrect. The CURLOPT_COOKIE option expects a string of cookie key-value pairs (e.g., "session_id=abc123"), not a boolean 1. Since you’re already using CURLOPT_COOKIEJAR and CURLOPT_COOKIEFILE to handle cookie persistence, this line is redundant and could be causing unexpected behavior. Remove it entirely.
2. Add Missing Standard Request Headers
Many modern websites block requests that don’t include common browser headers like Accept and Accept-Language. Adding these will help your request mimic a real browser session:
curl_setopt($ch, CURLOPT_HTTPHEADER, [ 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8', 'Accept-Language: en-US,en;q=0.9' ]);
3. Verify Cookie File Permissions
Double-check that $cookie and $cookieRead point to writable file paths on your server. If cURL can’t write to the cookie jar or read from the cookie file, it may fail to maintain session state—this is a common trigger for 403 errors.
4. Test SSL Certificate Verification (Temporary Fix)
In some cases, SSL certificate validation issues can lead to 403 errors. For testing purposes, you can temporarily disable verification (never do this in production):
curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, false);
If this resolves the issue, you’ll need to configure cURL to use a valid CA certificate bundle for production environments.
Modified Working Code Example
Here’s your code with all the fixes applied:
$cookie = '/path/to/writable/cookie.jar'; $cookieRead = '/path/to/writable/cookie.jar'; // You can use the same file for both $ch = curl_init(); curl_setopt($ch,CURLOPT_URL,'https://rumah.com'); curl_setopt($ch,CURLOPT_RETURNTRANSFER,1); curl_setopt($ch,CURLOPT_FOLLOWLOCATION,1); curl_setopt($ch,CURLOPT_COOKIEJAR,$cookie); curl_setopt($ch,CURLOPT_COOKIEFILE,$cookieRead); curl_setopt($ch,CURLOPT_HEADER,true); curl_setopt($ch,CURLOPT_IPRESOLVE, CURL_IPRESOLVE_V4); curl_setopt($ch,CURLOPT_ENCODING,'gzip'); curl_setopt($ch,CURLOPT_USERAGENT,'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0 Safari/605.1.15'); curl_setopt($ch,CURLOPT_REFERER,'https://google.com'); curl_setopt($ch,CURLOPT_AUTOREFERER,true); curl_setopt($ch,CURLOPT_TIMEOUT,20); // Add missing browser headers curl_setopt($ch, CURLOPT_HTTPHEADER, [ 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8', 'Accept-Language: en-US,en;q=0.9' ]); $data = curl_exec($ch); // Check for cURL errors to debug further if(curl_errno($ch)){ echo 'CURL Error: ' . curl_error($ch); } curl_close($ch);
Additional Notes
- If the above fixes don’t work, the site might use advanced anti-bot measures (like JavaScript fingerprinting) that basic cURL can’t bypass. In that case, you’d need to use a headless browser tool (like Puppeteer) to fully mimic a browser session.
- Always use
curl_errno()andcurl_error()to get specific error details—this will help you narrow down issues faster.
内容的提问来源于stack exchange,提问作者Raden Bagus

