urlyze docs

Real gates and copies of them

Anti-bot interstitials are effective at stopping automated analysis, which is exactly why kits copy them. A copied gate costs an attacker nothing and buys the same silence as a real one — the scan stops, and whatever sits behind the copy is never examined.

Why this is not a cosmetic problem

In the families we see most often, the copied interstitial is not a doorway to the payload — it is the payload's staging screen. "Verify you are human" is the pretext under which the visitor is asked to press something, and pressing it is what puts a command on their clipboard. Treating the copy as a gate to be respected means declining to look at the attack itself.

How we tell them apart

We decide from what the capture recorded — what the page actually fetched, and from whom — rather than from what the page says about itself. The words on the screen, the branding, and even markup referencing a well-known provider are all things a kit can copy in an afternoon; what a page cannot fake for free is the traffic its own visit produced.

When the evidence says a provider genuinely served the challenge, we treat it as infrastructure and stop. When it says the page is wearing a costume, analysis continues — and the interaction path described in ClickFix and the clipboard becomes available on a page that would otherwise have been reported as inconclusive.

What we do not do

We do not solve, bypass, or automate our way through a genuine anti-bot challenge. Real challenges belong to the site operator and are out of scope by policy. If the evidence about a challenge cannot be read for any reason, we treat it as genuine and stay away — the check fails towards restraint, not towards pressing.

What you get on the scan

A page that only claims to be protected no longer ends the scan. The result states what was observed, and if the page then hijacks the clipboard, the verdict says so — with the command and its destination, not merely a note that a challenge was present. A page genuinely behind a provider's challenge is still reported as AntiBotChallenged: we are telling you the content was not assessed, rather than implying it was clean.

Limits worth knowing