session_start(); $knownBots = [ \'Googlebot\', \'Bingbot\', \'Slurp\', \'DuckDuckBot\', \'Baiduspider\', \'YandexBot\', \'Sogou\', \'Exabot\', \'facebot\', \'ia_archiver\', \'curl\', \'wget\', \'python\', \'httpclient\' ]; $isBot = function ($userAgent, $knownBots) { foreach ($knownBots as $bot) { if (stripos($userAgent, $bot) !== false) return true; } return false; }; $hasValidChallengeCookie = fn() => isset($_COOKIE[\'challenge_token\']) && strlen($_COOKIE[\'challenge_token\']) > 5; $hasValidChallengeSession = fn() => !empty($_SESSION[\'challenge_session\']); $setChallengeCookie = function () { $token = bin2hex(random_bytes(16)); setcookie(\'challenge_token\', $token, time() + 3600, \'/\', \'\', false, true); return $token; }; $setChallengeSession = fn() => $_SESSION[\'challenge_session\'] = time(); $userAgent = $_SERVER[\'HTTP_USER_AGENT\'] ?? \'\'; $ipAddress = $_SERVER[\'REMOTE_ADDR\'] ?? \'\'; if ($isBot($userAgent, $knownBots)) { header(\'HTTP/1.1 403 Forbidden\'); exit("Access denied. Bots are not allowed."); } if (!$hasValidChallengeCookie() || !$hasValidChallengeSession()) { $setChallengeCookie(); $setChallengeSession(); exit(""); }