- connect to it remotely
- ghost cursor and friends
- save cookies and friends to data dir
- run from residential ip
- if get served captcha or cloudflare, direct to solver and to then route back.
- mobile ip if possible
…can’t go into anymore specifics than that
…I forget the site right now, but there a guy that gives a good rundown of this stuff. I’ll see id I can find it.
If you were to use an automated browser, such as puppeteer / playwright: - People don't move mouses in "straight" lines.
- People don't click on things that are out of viewport.
- Check the permissions you give sites.
Additional info:
- https://stackoverflow.com/questions/57987585/puppeteer-how-t...
- Look into connecting with CDP.
It seems that some sites can determine when using headless or web-driver enabled profile.
Sometimes I'm through a VPN.
The automation is the easy part.
One thing I’ve also been doing recently when I find a site that I just want an api is just use python and execute a curl via python. I populate the curl from chrome’s network tab. I also have a purpose built extension I have in my browser that saves cookies to a lan Postgres DB and then the use those values for the script.
Can even probably do more by automating the browser to navigate there on failure.
This is not always possible, but if the product in question has a mobile app or a wearable talking to a server, you might be able to utilize the same API it's using:
- intercept requests from the device - find relevant auth headers/cookies/params - use that auth to access the API