Skip to content

Problems with CAPTCHA and anti-bot systems #1016

Description

@mrsaeedmiri

Thank you for your efforts, here are some of the problems we are facing:

1- Excessive slowness in many cases and 502 - 504 errors
2- You can't log in at all with all the sites that have anti-robot and reCAPTCHA systems because they don't verify you in any way and the anti-robot steps are not completed
3- I wish you would do something so that at least Telegram would work on mobile, it doesn't work at all on any port and address that is mentioned, but it works with difficulty on Windows.

Thank you for your efforts

Activity

  1. therealaleph commented on May 10, 2026

    @therealaleph
    Owner

    Reviewed via Anthropic Claude.

    @mrsaeedmiri — three separate issues, three separate paths:

    1. Slowness + 502/504: This is the Apps Script edge throttle pattern (#895/#910/#900/#990/#1000). Workarounds: add 2-3 script_ids from different Google accounts, set fetch_ips_from_api: true (default), wait 1-2 hours for transient throttle to lift. If your ISP is TCI/مخابرات specifically, the recent script.googleusercontent.com block is also relevant — see #1000.

    2. CAPTCHA / reCAPTCHA failures: This is JA3/JA4 fingerprinting. Apps Script's UrlFetchApp has a fixed TLS fingerprint that all anti-bot systems recognize as non-browser. The cf_clearance / reCAPTCHA token gets bound to (IP + UA + JA3) — when the next request comes from a different Apps Script egress IP, the token is invalid and the challenge re-fires.

    The architectural fix is PR #963 (utls Chrome ClientHello via BoringSSL, opt-in --features utls build) — currently in community testing. Once merged, mhrv-rs's outbound TLS will fingerprint as Chrome, bypassing JA3-based detection.

    Workaround today: route CAPTCHA-protected sites through an exit-node (Deno Deploy / Replit / VPS). The exit-node uses normal browser-like fetch with rotating egress IPs. Setup at assets/exit_node/README.md.

    3. Telegram on mobile: Telegram Android speaks MTProto over raw TCP, NOT HTTP/SOCKS5. The proxy port settings don't apply because Telegram bypasses HTTP/SOCKS5 stacks. Solutions:

    • Web Telegram (web.telegram.org) on Chrome via mhrv-rs HTTP proxy: works.
    • Telegram Android with MTProxy: Telegram's built-in setting (Settings → Data and Storage → Proxy → MTProto). Needs a hosted MTProxy server somewhere outside Iran (free options exist on Telegram channels).
    • xray on Android with mtproto inbound: chains Telegram → xray → mhrv-rs SOCKS5. Strips MTProto envelope so the inner TCP can tunnel. Complex setup.

    The Windows experience working is because Windows has multiple proxy paths and Telegram Desktop happens to honor SOCKS5 in some configurations the mobile app doesn't.

    Closing — three separate canonical answers for three distinct problems. Reopen with specific symptoms if any of these don't resolve your case.

  2. mrsaeedmiri commented on May 10, 2026

    @mrsaeedmiri
    Author

    سلام وقت بخیر
    نمیدونم باقی کاربران این مشکلات رو دارن یا خیر؟
    1- کندی بیش از حد در بسیاری مواقع و کدهای خطای 502 و 504
    2- با تمام سایت هایی که سیستم چک کپچا دارن از گوگل گرفته تا کلود فلر، اصلا نمیتونن تایید کنن و نمیزارن وارد بشیم.|
    3- ای کاش میشد روی نسخه موبایل حداقل بشه تلگرام رو باز کرد با پورت 8085 و ادرس 127.0.0.1، در ویندوز به راحتی متصل میشه با اینکه قطعی وصلی داره.

    در آخر هم خیلی ازتون ممنونم بابت زحماتتون و این کار عالی و پرقدرت

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions