$row) { if (($row['until'] ?? 0) <= $now) unset($black[$k]); } if (isset($black[$ipKey]) && ($black[$ipKey]['until'] ?? 0) > $now) { header('HTTP/1.1 403 Forbidden'); header('Content-Type: text/html; charset=UTF-8'); echo "

403 Forbidden

Your IP is temporarily blacklisted.

"; exit; } // ========================= /** RATE LIMIT ADAPTIF */ // ========================= $rate = load_json($RATE_FILE); // cleanup entry kedaluwarsa untuk hemat memori foreach ($rate as $k => $info) { if (($info['last'] ?? 0) < ($now - max(RL_WINDOW_SECONDS, max(RL_BACKOFF_STEPS)))) { unset($rate[$k]); } } // init entry IP if (!isset($rate[$ipKey])) { $rate[$ipKey] = [ 'count' => 0, 'window' => $now, // awal jendela 'last' => $now, // waktu request terakhir 'violations' => 0, 'blocked_to' => 0, ]; } // jika sedang di-block karena backoff if (($rate[$ipKey]['blocked_to'] ?? 0) > $now) { $retryAfter = max(1, $rate[$ipKey]['blocked_to'] - $now); header('HTTP/1.1 429 Too Many Requests'); header("Retry-After: $retryAfter"); echo "

429 Too Many Requests

Backoff active. Try again in {$retryAfter}s.

"; exit; } // reset window jika sudah lewat if ($now - $rate[$ipKey]['window'] >= RL_WINDOW_SECONDS) { $rate[$ipKey]['window'] = $now; $rate[$ipKey]['count'] = 0; } // hitung request $rate[$ipKey]['count']++; $rate[$ipKey]['last'] = $now; if ($rate[$ipKey]['count'] > RL_MAX_REQUESTS) { // kena limit → tambah violations, hitung backoff $rate[$ipKey]['violations'] = min($rate[$ipKey]['violations'] + 1, 1000); $stepIndex = min($rate[$ipKey]['violations'] - 1, count(RL_BACKOFF_STEPS) - 1); $backoff = RL_BACKOFF_STEPS[$stepIndex]; $rate[$ipKey]['blocked_to'] = $now + $backoff; // blacklist jika violations kebanyakan if ($rate[$ipKey]['violations'] >= RL_MAX_VIOLATIONS) { $black[$ipKey] = ['until' => $now + BLACKLIST_DURATION, 'reason' => 'excessive_rate_limit']; save_json($BLACK_FILE, $black); } save_json($RATE_FILE, $rate); header('HTTP/1.1 429 Too Many Requests'); header("Retry-After: $backoff"); echo "

429 Too Many Requests

Slow down. Temporary block: {$backoff}s.

"; exit; } // simpan progres rate limit save_json($RATE_FILE, $rate); // ========================= // BOT GOODLIST (SEO safe) // ========================= $knownBots = [ 'Googlebot','Bingbot','Slurp','DuckDuckBot','YandexBot','Baiduspider' ]; foreach ($knownBots as $bot) { if (stripos($ua, $bot) !== false) { // lolos total (jaga SEO) return; } } // ========================= // HEADER HEURISTIK ringan // (jika header terlalu minimal → tantang JS terlebih dahulu) // ========================= $headers_sus = 0; if ($al === '') $headers_sus++; if (!isset($_SERVER['HTTP_SEC_CH_UA'])) $headers_sus++; if (!isset($_SERVER['HTTP_UPGRADE_INSECURE_REQUESTS'])) $headers_sus++; // ========================= // COOKIE ENCRYPTED + JS PROOF // ========================= $tomorrow = date('dmY', strtotime('+1 day')); $dataPlain = $domain . '/' . $tomorrow . '/' . $ua; $enc = openssl_encrypt($dataPlain, ENC_METHOD, ENC_KEY, 0, ENC_IV); $encB64 = base64_encode($enc); // Validasi cookie + JS proof $hasCookie = isset($_COOKIE[COOKIE_NAME]); $hasJS = isset($_COOKIE[COOKIE_JS_PROOF]) && strlen($_COOKIE[COOKIE_JS_PROOF]) >= 32; // Jika cookie ada, cek validitas if ($hasCookie) { $decBin = base64_decode($_COOKIE[COOKIE_NAME], true); if ($decBin !== false) { $dec = openssl_decrypt($decBin, ENC_METHOD, ENC_KEY, 0, ENC_IV); if ($dec) { $parts = explode('/', $dec, 3); if (count($parts) === 3) { [$decDomain, $decDate, $decUA] = $parts; $today = date('dmY'); $isValid = ($decDomain === $domain) && ($decUA === $ua) && ($decDate === $today || $decDate === $tomorrow); // butuh JS proof minimal sekali (lawan curl/wget) if ($isValid && $hasJS) { // lolos: lanjut ke aplikasi return; } } } } } // Kalau sampai sini, tampilkan halaman “Checking Browser” header("Cache-Control: no-store, no-cache, must-revalidate, max-age=0"); header("Pragma: no-cache"); ?> Checking Your Browser
Checking your browser before accessing .
This process is automatic. Your browser will redirect shortly.
Please allow up to 5 seconds…
DDoS protection by LC GOOGLE
Ray ID: