使用CURL请求rumah.com返回403 Forbidden的问题排查求助
Hey there! Let's break down why you're hitting that 403 error with your cURL request to rumah.com—403 typically means the server is flagging your request as non-legitimate, so let's walk through the likely missing configurations and fixes:
1. Fix the Misconfigured Cookie Setting
You’ve set CURLOPT_COOKIE to 1, which is incorrect. This option is meant to pass a specific cookie string (like name=value), not enable cookie functionality. Since you’re already using CURLOPT_COOKIEJAR and CURLOPT_COOKIEFILE to handle cookie persistence, this line is interfering with normal cookie handling.
Remove this line entirely:
// curl_setopt($ch,CURLOPT_COOKIE,1); // Delete this line
2. Add Critical Request Headers
Most modern websites validate standard browser headers beyond just User-Agent and Referer. Missing these can trigger bot detection. Add these headers to mimic a real Safari request:
curl_setopt($ch, CURLOPT_HTTPHEADER, array( 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8', 'Accept-Language: en-US,en;q=0.5', 'Connection: keep-alive', 'Upgrade-Insecure-Requests: 1' ));
3. Validate Cookie File Permissions
Ensure the paths in $cookie and $cookieRead point to a directory your server can write to. If the cookie file can’t be saved or read, the server may reject your request for missing session context. Add a quick check:
$cookie = '/tmp/rumah_cookie.txt'; // Use a writable path $cookieRead = '/tmp/rumah_cookie.txt'; if (!is_writable(dirname($cookie))) { die('Error: Cookie directory is not writable'); }
4. Explicitly Set TLS Version
Some servers block outdated TLS versions. Force TLS 1.2 (a widely supported modern standard) to avoid handshake issues:
curl_setopt($ch, CURLOPT_SSLVERSION, CURL_SSLVERSION_TLSv1_2);
5. Test for Bot Detection
If the above fixes don’t work, rumah.com might have stricter anti-bot measures:
- Add a small random delay before your request (e.g.,
sleep(rand(1, 3));) to avoid rate limiting - Try rotating your
User-Agentwith a different real browser string occasionally - Ensure you’re not making too many requests in a short period
Full Modified Code
Here’s the updated code incorporating all the fixes above:
$cookie = '/tmp/rumah_cookie.txt'; $cookieRead = '/tmp/rumah_cookie.txt'; if (!is_writable(dirname($cookie))) { die('Error: Cookie directory is not writable'); } $ch = curl_init(); curl_setopt($ch,CURLOPT_URL,'https://rumah.com'); curl_setopt($ch,CURLOPT_RETURNTRANSFER,1); curl_setopt($ch,CURLOPT_FOLLOWLOCATION,1); curl_setopt($ch,CURLOPT_COOKIEJAR,$cookie); curl_setopt($ch,CURLOPT_COOKIEFILE,$cookieRead); curl_setopt($ch,CURLOPT_HEADER,true); curl_setopt($ch,CURLOPT_IPRESOLVE, CURL_IPRESOLVE_V4); curl_setopt($ch,CURLOPT_ENCODING,'gzip'); curl_setopt($ch,CURLOPT_USERAGENT,'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0 Safari/605.1.15'); curl_setopt($ch,CURLOPT_REFERER,'https://google.com'); curl_setopt($ch,CURLOPT_AUTOREFERER,true); curl_setopt($ch,CURLOPT_TIMEOUT,20); curl_setopt($ch, CURLOPT_HTTPHEADER, array( 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8', 'Accept-Language: en-US,en;q=0.5', 'Connection: keep-alive', 'Upgrade-Insecure-Requests: 1' )); curl_setopt($ch, CURLOPT_SSLVERSION, CURL_SSLVERSION_TLSv1_2); $data = curl_exec($ch); // Check for cURL errors to debug further if(curl_errno($ch)) { echo 'Curl Error: ' . curl_error($ch); } curl_close($ch);
Start by testing the cookie fix and added headers—those are the most likely culprits here. If you still get a 403, check for cURL errors with the debug line included above to get more context.
内容的提问来源于stack exchange,提问作者Raden Bagus

