Compare commits

..

173 Commits

Author SHA1 Message Date
mercury 2622397542 mihomo: udp true 2025-04-18 23:40:33 +04:00
mercury 702123e39c vless: ip limit only notifies 2025-04-17 00:58:13 +04:00
mercury 01ef7707c4 fix first start 2025-04-14 11:36:26 +04:00
mercury 064d39d80b Excess image php 2025-04-09 18:12:18 +04:00
mercury 1b93d41421 cyclical rebooting panel adguardhome fix 2025-04-07 00:22:50 +04:00
mercury e41c8e30a4 fix warp 2025-04-06 23:57:46 +04:00
mercury 260f988360 Merge branch 'dev' of github.com:mercurykd/vpnbot into dev 2025-04-05 00:38:54 +04:00
mercury ca4905220d np/oc the domain is preserved when transferring 2025-04-05 00:36:08 +04:00
Konstantin 08c5ff136e Merge pull request #38 from legiz-ru/dev
new variable ~dnspath~
2025-03-04 15:45:18 +04:00
legiz-ru 8709531717 new variable ~dnspath~
new variable ~dnspath~ for client templates (required for future release sing-box 1.12)
2025-03-04 12:41:23 +03:00
Konstantin 71f53c3575 Merge pull request #37 from legiz-ru/dev
update singbox 1.11.4 windows x64
2025-03-04 12:16:19 +04:00
legiz-ru 2607f1f264 update singbox 1.11.4 windows x64 2025-03-04 10:46:56 +03:00
mercury a94cab7dc1 fix ip limit user off 2025-03-02 18:41:18 +04:00
mercury 694d446402 update version 2025-02-22 18:56:42 +04:00
mercury 6074d40643 update version 2025-02-22 18:52:17 +04:00
mercury 4b1df94325 Revert "add clash mode selector for sing-box clients"
This reverts commit fb22744fa7.
2025-02-22 18:51:49 +04:00
mercury 232c75d5bf Merge branch 'dev' of github.com:mercurykd/vpnbot into dev 2025-02-22 18:50:32 +04:00
mercury 5e860a4896 fix addruleset for block outbound 2025-02-22 18:47:36 +04:00
Konstantin 5b05486b98 Merge pull request #35 from legiz-ru/dev
add clash mode selector for sing-box clients
2025-02-13 10:13:38 +04:00
legiz-ru fb22744fa7 add clash mode selector for sing-box clients 2025-02-13 08:11:20 +03:00
mercury af812b7c93 vless: stats collect improve 2025-02-12 13:29:08 +04:00
mercury 3302ca8871 vless stats: fix delete user 2025-02-12 12:50:39 +04:00
mercury 2c5eff03d5 vless stats: fix reset user stats 2025-02-12 00:25:23 +04:00
mercury a8a203041f vless stats: fix reset user stats 2025-02-11 22:48:47 +04:00
mercury a21c9b5fe9 update version 2025-02-11 00:14:07 +04:00
mercury 696779450f ip limit: count ip 2025-02-11 00:12:21 +04:00
mercury 7c5b3dfa3a xray: fix stats user 2025-02-10 23:58:17 +04:00
mercury 74404559f9 xray: stats to separate file 2025-02-10 23:33:38 +04:00
mercury 11e8fb468b singbox: return mixed-in port 2025-02-10 10:03:27 +04:00
mercury ca92ca703f update version 2025-02-08 15:52:49 +04:00
mercury f527888db8 vless: singbox 1.11 migrate 2025-02-08 15:51:44 +04:00
mercury 0e47a771cc Reapply "update singbox 1.11 windows x64"
This reverts commit 414a67c10d.
2025-02-08 15:51:20 +04:00
mercury ff10cbefc8 vless: fix reset stats 2025-02-07 22:44:55 +04:00
mercury 3371ba4bae update version 2025-02-07 00:53:07 +04:00
mercury 621fb08467 vless stats fix 2025-02-07 00:47:52 +04:00
mercury 5153b2c94a vless stats fix 2025-02-07 00:36:49 +04:00
mercury 1e9461cc49 vless: global stats traffic 2025-02-06 17:34:25 +04:00
mercury 88f48a036c autoclean logs 2025-02-06 17:33:56 +04:00
mercury b40e052d3f vless: add user with uuid 2025-02-06 16:34:14 +04:00
mercury a43082ae27 vless: global stats traffic 2025-02-06 16:25:36 +04:00
mercury c2cd945991 hashbot migration with backup 2025-02-06 16:09:21 +04:00
mercury 0737327e4b vless ip limit: ability change window time 2025-02-05 21:34:01 +04:00
mercury f620bf12cd vless ip limit: improve message 2025-02-05 17:26:03 +04:00
mercury 8b3730c61f vless ip limit improve 2025-02-05 17:01:52 +04:00
mercury c6d9dcd47b vless: batch adding users 2025-02-05 16:13:55 +04:00
mercury d83ba51d81 vless ip limit 2025-02-05 16:00:32 +04:00
mercury 1a593100b7 update version 2025-02-02 14:24:05 +04:00
mercury 414a67c10d Revert "update singbox 1.11 windows x64"
This reverts commit 284b025881.
2025-02-02 13:29:51 +04:00
mercury f92b484011 Revert "fix singbox template"
This reverts commit 86261e6b76.
2025-02-02 11:52:02 +04:00
mercury 7af0276944 Revert "Migrate to sing-box 1.11"
This reverts commit 6d1ab0cb3a.
2025-02-02 01:56:15 +04:00
mercury 24aaa8756c update version 2025-02-02 00:05:02 +04:00
mercury 07e2beff9b xray stats improve 2025-01-31 18:15:48 +04:00
mercury 86261e6b76 fix singbox template 2025-01-31 12:30:45 +04:00
Konstantin d816582e6f Merge pull request #34 from legiz-ru/dev
Migrate to sing-box 1.11
2025-01-30 19:04:30 +04:00
legiz-ru 6d1ab0cb3a Migrate to sing-box 1.11 2025-01-30 17:55:27 +03:00
legiz-ru 284b025881 update singbox 1.11 windows x64 2025-01-30 17:51:19 +03:00
mercury 0ca93b56a3 vless: ~email~ tag in subscription 2025-01-29 18:18:28 +04:00
mercury 7bcd8de007 vless: reset stats user 2025-01-29 11:04:06 +04:00
mercury 34eb950852 ip-cidr route 2025-01-24 22:09:05 +04:00
mercury 46021855a5 improve wg client menu 2025-01-23 00:55:44 +04:00
mercury 29c18ceb9d update readme 2025-01-20 01:04:24 +04:00
mercury 49d0827b9e update version 2025-01-18 23:39:39 +04:00
mercury 07e04c384a Merge branch 'dev' of github.com:mercurykd/vpnbot into dev 2025-01-18 23:33:29 +04:00
mercury 579457b4f4 show xray stats 2025-01-18 23:33:00 +04:00
mercury 3dac9416ca fix download mihomo template 2025-01-18 23:32:31 +04:00
mercury 5b4d3b5627 reality degenerate pattern improve 2025-01-18 23:31:58 +04:00
mercury 658e125cd8 show group id 2025-01-18 23:31:01 +04:00
Konstantin 1840555573 Merge pull request #33 from legiz-ru/dev
update singbox 1.10.7 windows x64
2025-01-18 18:23:20 +04:00
legiz-ru ecdc028226 update singbox 1.10.7 windows x64 2025-01-18 16:57:39 +03:00
mercury d432bf82f2 force inclusion of xray statistics 2025-01-16 01:04:33 +04:00
mercury 211e2c079d collect xray metrics 2025-01-13 15:32:54 +04:00
Konstantin 1696c4da7b Merge pull request #32 from legiz-ru/dev
v2ray(xray) client templates update
2025-01-12 02:23:56 +04:00
legiz-ru b8d5700eba v2ray(xray) client update
return warp+block domain routes
replace rule for directing
2025-01-12 01:17:23 +03:00
mercury 7e20c14299 update version 2025-01-07 21:02:43 +04:00
mercury b9155cf674 fix show ports on start 2025-01-07 21:00:06 +04:00
mercury 159f775e12 port accounting for shadowsocks 2025-01-07 18:30:57 +04:00
mercury ae672439be return shadowsocks 2025-01-07 18:01:44 +04:00
mercury 6dafba5618 update version 2025-01-04 22:56:21 +04:00
mercury 7daf61a4f5 improve main menu 2025-01-04 21:52:26 +04:00
mercury f9266827c9 ability to install the desired version 2025-01-03 17:09:51 +04:00
mercury 9e22c64771 update readme 2025-01-03 16:22:10 +04:00
mercury a2026a4436 adaptation of the log analyzer 2025-01-03 13:55:49 +04:00
mercury 95c5b5b8fd update version 2024-12-26 18:29:55 +04:00
mercury efbe20485a ability to change subdomain for naiveproxy 2024-12-26 18:28:24 +04:00
mercury 475eea1f47 ability to change subdomain for openconnect 2024-12-26 18:12:42 +04:00
mercury 02d9cdcccc improve update script 2024-12-26 16:59:06 +04:00
mercury d633799f11 update version 2024-12-26 16:26:34 +04:00
Konstantin ead66c3951 Merge pull request #29 from legiz-ru/dev
sb1.10+tun-inbound + sb-win64-1.10.5
2024-12-26 09:46:35 +04:00
legiz-ru bd7742d8b2 update tun inbound (changes in sb 1.10+)
change inet4_address to address

https://sing-box.sagernet.org/migration/#tun-address-fields-are-merged
2024-12-24 16:32:07 +03:00
legiz-ru ac593629a8 update singbox 1.10.5 windows x64 2024-12-24 16:24:58 +03:00
mercury 9932ee1e00 update version 2024-12-22 18:48:13 +04:00
mercury 1a6e9f43e8 show branch 2024-12-22 18:25:54 +04:00
mercury 76373ffcf2 fix first start nginx 2024-12-22 16:57:27 +04:00
mercury 43c59a9ed6 cloak main 2024-12-22 16:24:42 +04:00
mercury 8b3c6ca547 cloak static 2024-12-22 15:32:27 +04:00
mercury 63654e7ad7 cloak donate 2024-12-22 15:23:58 +04:00
mercury dcb4f72f07 fix cloak DoT 2024-12-22 15:16:35 +04:00
mercury 90afbbedb0 cloak DoH 2024-12-22 15:04:19 +04:00
mercury 1964ed0079 fix adguard 2024-12-22 14:58:02 +04:00
mercury 2525181655 fix nginx 2024-12-22 14:39:58 +04:00
mercury ef690349fd fix change transport xray 2024-12-22 14:33:00 +04:00
mercury 2c1db5f233 cloak xray 2024-12-22 13:32:01 +04:00
mercury 554d7f3a25 fix cloak nginx 2024-12-21 20:39:17 +04:00
mercury f2a1ec1b71 cloak nginx 2024-12-21 20:12:21 +04:00
mercury 04f1bf564c cloak for np/oc subdomain 2024-12-21 01:09:17 +04:00
mercury 1116f8ec75 delete backup shadowsocks 2024-12-21 01:04:18 +04:00
mercury f8e5b54a98 fix tlgrm handle 2024-12-20 03:25:35 +04:00
mercury 3929032e7a fix add domain and ssl 2024-12-20 02:46:09 +04:00
mercury 057917a24a delete x-powered-by php 2024-12-20 01:12:21 +04:00
mercury 941fc05e21 fix tlgrm location 2024-12-20 00:57:21 +04:00
mercury 797088a328 improve nginx config 2024-12-20 00:52:49 +04:00
mercury 45614eaf3b delete shadowsocks 2024-12-20 00:21:55 +04:00
mercury 47113b4940 hide ports 2024-12-19 23:42:27 +04:00
mercury 3febfe1d3d Merge branch 'dev' into stealth 2024-12-19 20:38:41 +04:00
mercury 90084c37ff shadowsocks password generation 2024-12-19 01:13:31 +04:00
mercury b49f088256 fix default password for shadowsocks 2024-12-19 00:15:41 +04:00
mercury 09a0f77863 update version 2024-12-13 16:00:03 +04:00
mercury 8c65f8e538 update adguardhome version 2024-12-13 01:24:59 +04:00
mercury 32e49088c2 fix delete upstream 2024-12-12 23:21:17 +04:00
Konstantin f666762dfa Merge pull request #28 from legiz-ru:dev
Update readme.md
2024-12-12 14:31:41 +04:00
legiz-ru a1778e6be8 Update readme.md 2024-12-12 13:26:33 +03:00
Konstantin 4b61e38b6b Merge pull request #27 from legiz-ru:dev
fix behavior clash.json
2024-12-11 02:38:47 +04:00
legiz-ru 270968e4ac fix behavior clash.json 2024-12-11 00:32:11 +03:00
mercury 3349e3b306 mihomo: new rule-set generation scheme 2024-12-10 22:55:17 +04:00
mercury 3e53000065 update version 2024-12-10 17:16:05 +04:00
mercury 18ceb51f4e mihomo: rules -> rule-providers
update core's
2024-12-10 17:13:38 +04:00
mercury 99bce7a988 update version 2024-12-09 14:30:26 +04:00
mercury 446a5d7150 mihomo: rule-providers add format 2024-12-09 13:32:25 +04:00
mercury 855f516936 update version 2024-12-06 23:39:12 +04:00
mercury e1c13480d1 mihomo: fix empty rules 2024-12-06 23:36:43 +04:00
mercury bd5e10fa23 naming: clash -> mihomo 2024-12-06 23:12:22 +04:00
mercury 3627b389b4 mihomo: added yaml support 2024-12-06 22:26:00 +04:00
mercury f3f9cb5348 fix ruleset for mihomo 2024-12-06 22:11:12 +04:00
mercury 1527b9f856 added rule-set for clash 2024-12-04 00:08:32 +04:00
mercury f896b307ea removed check when adding a subnet to openconnect 2024-11-28 20:11:05 +04:00
mercury 8ba7ddedee update version 2024-11-28 20:04:53 +04:00
mercury 19ef567873 fix createruleset 2024-11-28 19:51:21 +04:00
mercury 4f4e36e1cb doh ip exclude for analyze ip 2024-11-28 15:17:42 +04:00
mercury 6267931475 fix bug createruleset for singbox 2024-11-28 12:59:06 +04:00
mercury 7e2d90e7da update prioritet clash rules 2024-11-28 10:36:10 +04:00
mercury 28906176f5 update clash links 2024-11-28 00:21:22 +04:00
mercury 968d72ce81 autoscan call fix 2024-11-28 00:12:12 +04:00
mercury 66e204e5ba import url for clash 2024-11-27 23:37:39 +04:00
mercury 36e8acd2aa xray: template for clash 2024-11-27 22:00:30 +04:00
mercury cdc20adccd consistent template logic 2024-11-27 16:52:30 +04:00
mercury 8ad00bc47a update version 2024-11-21 18:09:25 +04:00
mercury 4902eb53ce fix addruleset for direct 2024-11-21 16:04:09 +04:00
mercury 253cceb44c fix analyze ip autoban 2024-11-21 12:13:02 +04:00
mercury 9d53f2896c fix analyze memory 2024-11-21 11:49:29 +04:00
mercury 550a8ad3b7 fix ip/32 analyze 2024-11-21 01:37:22 +04:00
mercury e2f84b0ee7 update version 2024-11-21 00:39:07 +04:00
mercury b394e769c6 роутинг для openconnect 2024-11-21 00:24:50 +04:00
mercury 7d8dc1dd2d duplicating the list of subnets for openconnect 2024-11-20 20:59:25 +04:00
mercury 34b1de5132 import telegram, gcore, cloudflare ip 2024-11-20 20:58:17 +04:00
mercury 12b5d84afc IP analyzer takes into account subnets 2024-11-20 17:12:08 +04:00
mercury c3d90ada83 addruleset and additional tags 2024-11-20 15:55:10 +04:00
mercury dbe3f290ea commands reset and backup 2024-11-20 15:46:03 +04:00
mercury b56b48e080 override ignore 2024-11-20 15:45:02 +04:00
mercury 21b7a4816f fix bot dump when telegram logs are empty 2024-11-18 00:31:53 +04:00
mercury 51ecb815ba fix domain installation on first launch 2024-11-17 19:32:54 +04:00
mercury 66cee61d41 allow telegram ip 2024-11-17 15:08:01 +04:00
mercury 66225917fe fix ip menu 2024-11-16 16:45:36 +04:00
mercury be227f6a33 update version 2024-11-16 01:13:53 +04:00
mercury 37d392a240 update backup 2024-11-16 01:10:47 +04:00
mercury 565573cfc2 fix notify update 2024-11-16 00:51:09 +04:00
mercury 3813f43b92 update bot from notify 2024-11-16 00:45:30 +04:00
mercury f34427c13c fix notification about new version 2024-11-16 00:42:22 +04:00
mercury c2219e3657 ability to add your IPs to blocklist/whitelist 2024-11-16 00:34:22 +04:00
mercury 0d7426e785 improve analyze ip 2024-11-16 00:11:19 +04:00
mercury c56fe4ff78 blocklist improve
add https://github.com/legiz-ru/sb-rule-sets/raw/main/ru-bundle.lst button
2024-11-15 11:49:20 +04:00
mercury b3366edb6e Merge branch 'dev' into stealth 2024-11-14 02:36:55 +04:00
mercury 1edc9e8608 fix input timer autoscan 2024-11-14 02:32:03 +04:00
mercury 8a3d9c1007 server headers off 2024-11-14 01:44:31 +04:00
33 changed files with 2801 additions and 1628 deletions
+4 -1
View File
@@ -22,4 +22,7 @@ update/*
override.env
override.html
override.php
docker-compose.override.yml
docker-compose.override.yml
backup.json
app/webapp/override/
.rest
+13
View File
@@ -0,0 +1,13 @@
<?php
require __DIR__ . '/timezone.php';
require __DIR__ . '/bot.php';
require __DIR__ . '/config.php';
require __DIR__ . '/i18n.php';
if ($c['debug']) {
require __DIR__ . '/debug.php';
}
$bot = new Bot($c['key'], $i);
echo $bot->export();
+1621 -677
View File
File diff suppressed because it is too large Load Diff
+10 -6
View File
@@ -2,8 +2,8 @@
$i = [
'warp' => [
'en' => 'warp',
'ru' => 'warp',
'en' => 'Warp',
'ru' => 'Warp',
],
'wg_title' => [
'en' => 'Wireguard',
@@ -22,7 +22,7 @@ $i = [
'ru' => 'AdGuard',
],
'config' => [
'en' => 'config',
'en' => 'Settings',
'ru' => 'настройки',
],
'pac' => [
@@ -30,7 +30,7 @@ $i = [
'ru' => 'PAC',
],
'chat' => [
'en' => 'discussion group',
'en' => 'chat',
'ru' => 'чат поддержки',
],
'back' => [
@@ -262,8 +262,12 @@ $i = [
'ru' => 'очистить',
],
'xray' => [
'en' => 'Xray',
'ru' => 'Xray',
'en' => 'Vless',
'ru' => 'Vless',
],
'clash' => [
'en' => 'mihomo',
'ru' => 'mihomo',
],
'geodb' => [
'en' => 'GeoIp/GeoSite',
+131 -136
View File
@@ -1,128 +1,18 @@
<?php
require __DIR__ . '/timezone.php';
// bot
require __DIR__ . '/config.php';
if ('POST' == $_SERVER['REQUEST_METHOD'] && $_GET['k'] == $c['key']) {
if ($c['debug']) {
require __DIR__ . '/debug.php';
}
require __DIR__ . '/calc.php';
require __DIR__ . '/bot.php';
require __DIR__ . '/i18n.php';
if (file_exists(__DIR__ . '/override.php')) {
include __DIR__ . '/override.php';
}
$bot = new Bot($c['key'], $i);
$bot->input();
exit;
if ($c['debug']) {
require __DIR__ . '/debug.php';
}
// pac
if (!empty($t = unserialize(base64_decode(explode('/', $_SERVER['REQUEST_URI'])[2])))) { // fix sing-box import
$_GET = array_merge($_GET, $t);
}
$type = $_GET['t'] ?? 'pac';
$address = $_GET['a'] ?: '127.0.0.1';
$port = $_GET['p'] ?: '1080';
$hash = $_GET['h'];
if ($hash == substr(md5($c['key']), 0, 8)) {
require __DIR__ . '/bot.php';
require __DIR__ . '/i18n.php';
$bot = new Bot($c['key'], $i);
switch ($type) {
case 'mirror':
$bot->getMirror();
break;
case 's':
case 'si':
$bot->subscription();
exit;
case 'te':
if (!empty($_GET['te'])) {
$t = $bot->getPacConf()["{$_GET['ty']}templates"][$_GET['te']];
} else {
$t = json_decode(file_get_contents("/config/{$_GET['ty']}.json"), true);
}
if ($t) {
header('Content-Type: text/html');
$t = json_encode($t, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES);
$name = $_GET['te'] ?: 'origin';
$type = $_GET['ty'];
echo <<<HTML
<!DOCTYPE HTML>
<html lang="en" style="height:100%">
<head>
<!-- when using the mode "code", it's important to specify charset utf-8 -->
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link href="jsoneditor.min.css" rel="stylesheet" type="text/css">
<script src="jsoneditor.min.js"></script>
<script src="jquery-3.7.1.min.js"></script>
<script src="https://telegram.org/js/telegram-web-app.js"></script>
</head>
<body style="height:100%">
<div id="jsoneditor" style="height:100%"></div>
<script>
jQuery(function($) {
var tg = window.Telegram.WebApp;
// create the editor
const container = document.getElementById("jsoneditor")
const options = {}
const editor = new JSONEditor(container, options)
editor.set({$t})
tg.MainButton.show().setText('{$bot->i18n('save')}').onClick(function (e) {
var self = this;
$.ajax({
url: '/webapp/save?' + tg.initData,
method: 'POST',
data: {
name: '$name',
type: '$type',
json: editor.getText()
},
dataType: 'json'
}).done(function (r) {
if (r.status == true) {
tg.MainButton.setText('{$bot->i18n('success')}')
setTimeout(() => {
tg.close();
}, 500);
} else {
tg.MainButton.setText(r.message);
}
}).fail(function (r) {
tg.MainButton.setText('{$bot->i18n('error')}')
});
});
});
</script>
</body>
</html>
HTML;
exit;
}
default:
if (file_exists($file = __DIR__ . "/zapretlists/$type")) {
$pac = file_get_contents($file);
header('Content-Type: text/plain');
echo str_replace([
'~address~',
'~port~',
], [
$address,
$port,
], $pac);
exit;
}
break;
}
require __DIR__ . '/calc.php';
require __DIR__ . '/bot.php';
require __DIR__ . '/i18n.php';
if (file_exists(__DIR__ . '/override.php')) {
include __DIR__ . '/override.php';
}
$bot = new Bot($c['key'], $i);
$hash = $bot->getHashBot();
if (!empty($_GET['hash'])) {
$t = $_GET;
unset($t['hash']);
@@ -130,22 +20,127 @@ if (!empty($_GET['hash'])) {
foreach ($t as $k => $v) {
$s[] = "$k=$v";
}
$s = implode("\n", $s);
$sk = hash_hmac('sha256', $c['key'], "WebAppData", true);
if (hash_hmac('sha256', $s, $sk) == $_GET['hash']) {
require __DIR__ . '/bot.php';
require __DIR__ . '/i18n.php';
$bot = new Bot($c['key'], $i);
if (!empty($_POST['json'])) {
echo json_encode($bot->saveTemplate($_POST['name'], $_POST['type'], $_POST['json']));
die();
} else {
setcookie('c', substr(hash('sha256', $c['key']), 0, 8), 0, '/');
setcookie('a', $bot->adguardBasicAuth(), 0, '/');
}
die('ok');
}
$s = implode("\n", $s);
$sk = hash_hmac('sha256', $c['key'], "WebAppData", true);
$webapp = hash_hmac('sha256', $s, $sk) == $_GET['hash'];
}
header('500', true, 500);
exit;
switch (true) {
// tlgrm
case 'POST' == $_SERVER['REQUEST_METHOD'] && preg_match('~^/tlgrm~', $_SERVER['REQUEST_URI']) && $_GET['k'] == $c['key']:
$bot->input();
break;
// save template
case preg_match('~^' . preg_quote("/webapp$hash/save") . '~', $_SERVER['REQUEST_URI']) && $webapp && !empty($_POST['json']):
echo json_encode($bot->saveTemplate($_POST['name'], $_POST['type'], $_POST['json']));
break;
// adguard cookie
case preg_match('~^' . preg_quote("/webapp$hash/check") . '~', $_SERVER['REQUEST_URI']) && $webapp:
setcookie('c', $hash, 0, '/');
echo "/adguard$hash/";
break;
// subs & pac
case preg_match('~^' . preg_quote("/pac$hash") . '~', $_SERVER['REQUEST_URI']):
if (!empty($t = unserialize(base64_decode(explode('/', $_SERVER['REQUEST_URI'])[2])))) { // fix sing-box import
$_GET = array_merge($_GET, $t);
}
$type = $_GET['t'] ?? 'pac';
$address = $_GET['a'] ?: '127.0.0.1';
$port = $_GET['p'] ?: '1080';
switch ($type) {
case 's':
case 'si':
case 'cl':
$bot->subscription();
exit;
case 'te':
if (!empty($_GET['te'])) {
$t = $bot->getPacConf()["{$_GET['ty']}templates"][$_GET['te']];
} else {
$t = json_decode(file_get_contents("/config/{$_GET['ty']}.json"), true);
}
if ($t) {
header('Content-Type: text/html');
$t = json_encode($t, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES);
$name = $_GET['te'] ?: 'origin';
$type = $_GET['ty'];
echo <<<HTML
<!DOCTYPE HTML>
<html lang="en" style="height:100%">
<head>
<!-- when using the mode "code", it's important to specify charset utf-8 -->
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link href="/webapp$hash/jsoneditor.min.css" rel="stylesheet" type="text/css">
<script src="/webapp$hash/jsoneditor.min.js"></script>
<script src="/webapp$hash/jquery-3.7.1.min.js"></script>
<script src="https://telegram.org/js/telegram-web-app.js"></script>
</head>
<body style="height:100%">
<div id="jsoneditor" style="height:100%"></div>
<script>
jQuery(function($) {
var tg = window.Telegram.WebApp;
// create the editor
const container = document.getElementById("jsoneditor")
const options = {}
const editor = new JSONEditor(container, options)
editor.set({$t})
tg.MainButton.show().setText('{$bot->i18n('save')}').onClick(function (e) {
var self = this;
$.ajax({
url: '/webapp$hash/save?' + tg.initData,
method: 'POST',
data: {
name: '$name',
type: '$type',
json: editor.getText()
},
dataType: 'json'
}).done(function (r) {
if (r.status == true) {
tg.MainButton.setText('{$bot->i18n('success')}')
setTimeout(() => {
tg.close();
}, 500);
} else {
tg.MainButton.setText(r.message);
}
}).fail(function (r) {
tg.MainButton.setText('{$bot->i18n('error')}')
});
});
});
</script>
</body>
</html>
HTML;
exit;
}
default:
if (file_exists($file = __DIR__ . "/zapretlists/$type")) {
$pac = file_get_contents($file);
header('Content-Type: text/plain');
echo str_replace([
'~address~',
'~port~',
], [
$address,
$port,
], $pac);
exit;
}
break;
}
break;
default:
header('500', true, 500);
}
+10
View File
@@ -0,0 +1,10 @@
<?php
require __DIR__ . '/timezone.php';
// require __DIR__ . '/debug.php';
require __DIR__ . '/bot.php';
require __DIR__ . '/config.php';
require __DIR__ . '/i18n.php';
(new Bot($c['key'], $i))->analyzeXray();
+3 -1
View File
@@ -13,12 +13,14 @@ if ($c['debug']) {
$bot = new Bot($c['key'], $i);
$bot->selfUpdate();
$bot->ssPswdCheck();
$bot->restartTG();
if (!empty($bot->selfupdate)) {
$bot->offWarp();
}
$bot->dontshowcron = 1;
$bot->adguardSync();
$bot->sslip();
$bot->adguardSync();
$bot->cloakNginx();
$bot->syncDeny();
$bot->cleanDocker();
+1 -1
View File
@@ -14,7 +14,7 @@
$.ajax({
'url': 'check?' + tg.initData,
}).done(function (r) {
location.replace('/adguard/');
location.replace(r);
}).fail(function (r) {
location.replace('/');
});
-117
View File
@@ -1,117 +0,0 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Login</title>
<style>
/* Design based on Blue Login Field of Kevin Sleger https://codepen.io/MurmeltierS/pen/macKb */
body {
background: #44c4e7 url("https://photos-6.dropbox.com/t/2/AAC_bdqR8LMkjEe-HPIf4K1DhtseMLRHPklBSzJSuzglvA/12/5714737/jpeg/1024x768/3/1418346000/0/2/bkg-blur.jpg/CLHm3AIgASgBKAI/b7RrveA2022yJyfO9RyRvv7LjJQESukGHssHUxVThzw") no-repeat center center fixed;
background-size: cover;
font-family: "Roboto";
-webkit-font-smoothing: antialiased;
-moz-osx-font-smoothing: grayscale;
&::before {
z-index: -1;
content: '';
position: fixed;
top: 0;
left: 0;
background: #44c4e7;
/* IE Fallback */
background: rgba(68, 196, 231, 0.8);
width: 100%;
height: 100%;
}
}
.form {
position: absolute;
top: 50%;
left: 50%;
background: #fff;
width: 285px;
margin: -140px 0 0 -182px;
padding: 40px;
box-shadow: 0 0 3px rgba(0, 0, 0, 0.3);
h2 {
margin: 0 0 20px;
line-height: 1;
color: #44c4e7;
font-size: 18px;
font-weight: 400;
}
input {
outline: none;
display: block;
width: 100%;
margin: 0 0 20px;
padding: 10px 15px;
border: 1px solid #ccc;
color: #ccc;
font-family: "Roboto";
box-sizing: border-box;
font-size: 14px;
font-wieght: 400;
-webkit-font-smoothing: antialiased;
-moz-osx-font-smoothing: grayscale;
transition: 0.2s linear;
&input:focus {
color: #333;
border: 1px solid #44c4e7;
}
}
button {
cursor: pointer;
background: #44c4e7;
width: 100%;
padding: 10px 15px;
border: 0;
color: #fff;
font-family: "Roboto";
font-size: 14px;
font-weight: 400;
&:hover {
background: #369cb8;
}
}
}
.error,
.valid {
display: none;
}
</style>
<script src="jquery-3.7.1.min.js"></script>
</head>
<body>
<section class="form animated flipInX">
<h2>Login To Your Account</h2>
<p class="valid">Valid. Please wait a moment.</p>
<p class="error">Error. Please enter correct Username &amp; password.</p>
<form class="loginbox" autocomplete="off">
<input placeholder="Username" type="text" id="username"></input>
<input placeholder="Password" type="password" id="password"></input>
<button id="submit">Login</button>
</form>
</section>
<script>
$(document).ready(function() {
$('#submit').click(function () {
event.preventDefault(); // prevent PageReLoad
$('.error').css('display', 'block'); // show error msg
});
});
</script>
</body>
</html>
+150
View File
@@ -0,0 +1,150 @@
{
"mixed-port": 2080,
"allow-lan": true,
"tcp-concurrent": true,
"enable-process": true,
"find-process-mode": "strict",
"global-client-fingerprint": "chrome",
"mode": "rule",
"log-level": "info",
"ipv6": false,
"keep-alive-interval": 30,
"unified-delay": false,
"profile": {
"store-selected": true,
"store-fake-ip": true
},
"sniffer": {
"enable": true,
"sniff": {
"HTTP": {
"ports": [
80,
"8080-8880"
],
"override-destination": true
},
"TLS": {
"ports": [
443,
8443
]
},
"QUIC": {
"ports": [
443,
8443
]
}
}
},
"tun": {
"enable": true,
"stack": "mixed",
"dns-hijack": [
"any:53"
],
"auto-route": true,
"auto-detect-interface": true,
"strict-route": true
},
"dns": {
"enable": true,
"listen": ":1053",
"prefer-h3": false,
"ipv6": false,
"enhanced-mode": "fake-ip",
"fake-ip-filter": [
"~domain~",
"+.lan",
"+.local"
],
"nameserver": [
"~dns~"
]
},
"proxies": [
{
"name": "~outbound~",
"type": "vless",
"server": "~domain~",
"port": 443,
"uuid": "~uid~",
"network": "tcp",
"flow": "xtls-rprx-vision",
"udp": true,
"tls": true,
"reality-opts": {
"public-key": "~public_key~",
"short-id": "~short_id~"
},
"servername": "~server_name~",
"client-fingerprint": "chrome"
}
],
"proxy-groups": [
{
"name": "PROXY",
"type": "select",
"proxies": [
"~outbound~"
]
}
],
"add-rule-providers": true,
"rule-providers": {},
"rules": [
{
"type": "RULE-SET",
"list": "~block~",
"action": "REJECT",
"interval": 30,
"behavior": "domain",
"name": "block"
},
{
"type": "RULE-SET",
"list": "~process~",
"action": "PROXY",
"interval": 30,
"behavior": "classical",
"name": "process"
},
{
"type": "RULE-SET",
"list": "~package~",
"action": "PROXY",
"interval": 30,
"behavior": "classical",
"name": "package"
},
{
"type": "RULE-SET",
"list": "~warp~",
"action": "PROXY",
"interval": 30,
"behavior": "domain",
"name": "warp"
},
{
"type": "RULE-SET",
"list": "~pac~",
"action": "PROXY",
"interval": 30,
"behavior": "domain",
"name": "pac"
},
{
"type": "RULE-SET",
"list": "~subnet~",
"action": "PROXY",
"interval": 30,
"behavior": "ipcidr",
"name": "subnet"
},
{
"type": "MATCH",
"action": "DIRECT"
}
]
}
+194 -176
View File
@@ -1,197 +1,215 @@
user nginx;
worker_processes auto;
user nginx;
worker_processes auto;
error_log /logs/nginx_error;
pid /var/run/nginx.pid;
error_log /logs/nginx_error;
pid /var/run/nginx.pid;
events {
worker_connections 1024;
worker_connections 1024;
}
http {
server_names_hash_bucket_size 64;
include include.conf;
include /etc/nginx/mime.types;
default_type application/octet-stream;
server_names_hash_bucket_size 64;
server_tokens off;
include include.conf;
include /etc/nginx/mime.types;
default_type application/octet-stream;
# Proxy Cache storage - so we can cache the DoH response from the upstream
proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m;
# Proxy Cache storage - so we can cache the DoH response from the upstream
proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m;
real_ip_header proxy_protocol;
real_ip_recursive on;
set_real_ip_from 10.10.0.10;
real_ip_header proxy_protocol;
real_ip_recursive on;
set_real_ip_from 10.10.0.10;
server {
listen 10.10.0.2:80 default_server;
listen 10.10.0.2:443 ssl http2 default_server proxy_protocol;
ssl_certificate /certs/self_public;
ssl_certificate_key /certs/self_private;
server {
listen 80 default_server;
access_log /logs/nginx_default_access;
location / {
root /app;
index override.html login.html;
try_files $uri $uri/ =404;
location / {
return 301 https://$host$request_uri;
}
location ~\.well-known {
access_log /logs/nginx_certbot_access;
root /certs/;
try_files $uri =404;
}
}
location /adguard/ {
access_log /logs/nginx_adguard_access;
proxy_pass http://ad:80/;
proxy_redirect / /adguard/;
proxy_cookie_path / /adguard/;
server {
listen 10.10.0.2:443 ssl http2 proxy_protocol default_server;
listen 10.10.1.2:443 ssl http2 default_server;
ssl_certificate /certs/self_public;
ssl_certificate_key /certs/self_private;
access_log /logs/nginx_ip_access;
location = / {
root /app;
try_files $uri /override.html @auth;
}
location / {
root /app;
auth_basic "Restricted Content";
auth_basic_user_file /app/.htpasswd;
try_files $uri =404;
}
location @auth {
root /app;
auth_basic "Restricted Content";
auth_basic_user_file /app/.htpasswd;
try_files $uri =404;
}
location /tlgrm {
access_log /logs/nginx_tlgrm_access;
proxy_pass http://php;
}
location @php {
proxy_pass http://php;
}
location /adguard/ {
}
location /webapp {
access_log /logs/nginx_webapp_access;
alias /app;
index index.html;
try_files $uri $uri/ @php;
}
location /pac {
access_log /logs/nginx_pac_access;
proxy_set_header Host $http_host;
proxy_pass http://php;
}
location /ws {
proxy_pass http://xr:443;
proxy_redirect off;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_read_timeout 5d;
}
location /v2ray {
access_log /logs/nginx_v2ray_access;
proxy_redirect off;
proxy_buffering off;
proxy_http_version 1.1;
proxy_pass http://ss:8388/;
proxy_set_header Host $http_host;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
location /dns-query {
access_log /logs/nginx_doh_access;
proxy_http_version 1.1;
proxy_set_header Connection "";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-Proto https;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Host $remote_addr;
proxy_cache doh_cache;
proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
proxy_pass https://ad/dns-query;
}
}
location /webapp {
access_log /logs/nginx_webapp_access;
alias /app;
index index.html;
try_files $uri $uri/ /pac?$query_string;
}
location /pac {
access_log /logs/nginx_pac_access;
proxy_set_header Host $http_host;
proxy_pass http://php;
}
location /tlgrm {
access_log /logs/nginx_tlgrm_access;
proxy_pass http://php;
}
location /v2ray {
access_log /logs/nginx_v2ray_access;
proxy_redirect off;
proxy_buffering off;
proxy_http_version 1.1;
proxy_pass http://ss:8388/;
proxy_set_header Host $http_host;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
location /ws {
proxy_pass http://xr:443;
proxy_redirect off;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_read_timeout 5d;
}
#-ssl
# # The DoH server block
# location /dns-query {
# access_log /logs/nginx_doh_access;
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
# proxy_http_version 1.1;
# proxy_set_header Connection "";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-Proto https;
# proxy_set_header X-Forwarded-For $remote_addr;
# proxy_set_header X-Forwarded-Host $remote_addr;
# # Enable Cache, and set the cache_key to include the request_body
# proxy_cache doh_cache;
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
#~
# # proxy pass to the dohloop upstream
# proxy_pass https://ad/dns-query;
# }
#-ssl
location ~\.well-known {
access_log /logs/nginx_certbot_access;
root /certs/;
try_files $uri =404;
}
}
#-domain
# server {
# server_name domain;
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
# listen 10.10.1.2:443 ssl http2;
# ssl_certificate /certs/cert_public;
# ssl_certificate_key /certs/cert_private;
#~
# access_log /logs/nginx_domain_access;
#-domain
# server {
# listen 10.10.0.2:80;
# server_name ;
#-domain
#-ssl
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
# listen 10.10.1.2:443 ssl http2;
# ssl_certificate /certs/cert_public;
# ssl_certificate_key /certs/cert_private;
#-ssl
# location = / {
# root /app;
# try_files $uri /override.html @auth;
# }
#-domain
# access_log /logs/nginx_domain_access;
# location / {
# root /app;
# auth_basic "Restricted Content";
# auth_basic_user_file /app/.htpasswd;
# try_files $uri =404;
# }
# location @auth {
# root /app;
# auth_basic "Restricted Content";
# auth_basic_user_file /app/.htpasswd;
# try_files $uri =404;
# }
# location / {
# root /app;
# index override.html login.html;
# try_files $uri $uri/ =404;
# }
# location /adguard/ {
# access_log /logs/nginx_adguard_access;
# proxy_pass http://ad:80/;
# proxy_redirect / /adguard/;
# proxy_cookie_path / /adguard/;
# }
# location /webapp {
# access_log /logs/nginx_webapp_access;
# alias /app;
# index index.html;
# try_files $uri $uri/ /pac?$query_string;
# }
# location /pac {
# access_log /logs/nginx_pac_access;
# proxy_set_header Host $http_host;
# proxy_pass http://php;
# }
# location ~\.well-known {
# access_log /logs/nginx_certbot_access;
# root /certs/;
# try_files $uri =404;
# }
# location /v2ray {
# access_log /logs/nginx_v2ray_access;
# proxy_redirect off;
# proxy_buffering off;
# proxy_http_version 1.1;
# proxy_pass http://ss:8388/;
# proxy_set_header Host $http_host;
# proxy_set_header Upgrade $http_upgrade;
# proxy_set_header Connection "upgrade";
# }
# location /ws {
# proxy_pass http://xr:443;
# proxy_redirect off;
# proxy_http_version 1.1;
# proxy_set_header Upgrade $http_upgrade;
# proxy_set_header Connection "upgrade";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
# proxy_read_timeout 5d;
# }
#-domain
#-ssl
# # The DoH server block
# location /dns-query {
# access_log /logs/nginx_doh_access;
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
# proxy_http_version 1.1;
# proxy_set_header Connection "";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-Proto https;
# proxy_set_header X-Forwarded-For $remote_addr;
# proxy_set_header X-Forwarded-Host $remote_addr;
# location @php {
# proxy_pass http://php;
# }
# # Enable Cache, and set the cache_key to include the request_body
# proxy_cache doh_cache;
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
# location /adguard/ {
# }
# # proxy pass to the dohloop upstream
# proxy_pass https://ad/dns-query;
# }
#-ssl
#-domain
# }
#-domain
# location /webapp {
# access_log /logs/nginx_webapp_access;
# alias /app;
# index index.html;
# try_files $uri $uri/ @php;
# }
# location /pac {
# access_log /logs/nginx_pac_access;
# proxy_set_header Host $http_host;
# proxy_pass http://php;
# }
# location /v2ray {
# access_log /logs/nginx_v2ray_access;
# proxy_redirect off;
# proxy_buffering off;
# proxy_http_version 1.1;
# proxy_pass http://ss:8388/;
# proxy_set_header Host $http_host;
# proxy_set_header Upgrade $http_upgrade;
# proxy_set_header Connection "upgrade";
# }
# location /ws {
# proxy_pass http://xr:443;
# proxy_redirect off;
# proxy_http_version 1.1;
# proxy_set_header Upgrade $http_upgrade;
# proxy_set_header Connection "upgrade";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
# proxy_read_timeout 5d;
# }
# location /dns-query {
# access_log /logs/nginx_doh_access;
# proxy_http_version 1.1;
# proxy_set_header Connection "";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-Proto https;
# proxy_set_header X-Forwarded-For $remote_addr;
# proxy_set_header X-Forwarded-Host $remote_addr;
# proxy_cache doh_cache;
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
# proxy_pass https://ad/dns-query;
# }
# }
#-domain
}
+194 -176
View File
@@ -1,197 +1,215 @@
user nginx;
worker_processes auto;
user nginx;
worker_processes auto;
error_log /logs/nginx_error;
pid /var/run/nginx.pid;
error_log /logs/nginx_error;
pid /var/run/nginx.pid;
events {
worker_connections 1024;
worker_connections 1024;
}
http {
server_names_hash_bucket_size 64;
include include.conf;
include /etc/nginx/mime.types;
default_type application/octet-stream;
server_names_hash_bucket_size 64;
server_tokens off;
include include.conf;
include /etc/nginx/mime.types;
default_type application/octet-stream;
# Proxy Cache storage - so we can cache the DoH response from the upstream
proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m;
# Proxy Cache storage - so we can cache the DoH response from the upstream
proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m;
real_ip_header proxy_protocol;
real_ip_recursive on;
set_real_ip_from 10.10.0.10;
real_ip_header proxy_protocol;
real_ip_recursive on;
set_real_ip_from 10.10.0.10;
server {
listen 10.10.0.2:80 default_server;
listen 10.10.0.2:443 ssl http2 default_server proxy_protocol;
ssl_certificate /certs/self_public;
ssl_certificate_key /certs/self_private;
server {
listen 80 default_server;
access_log /logs/nginx_default_access;
location / {
root /app;
index override.html login.html;
try_files $uri $uri/ =404;
location / {
return 301 https://$host$request_uri;
}
location ~\.well-known {
access_log /logs/nginx_certbot_access;
root /certs/;
try_files $uri =404;
}
}
location /adguard/ {
access_log /logs/nginx_adguard_access;
proxy_pass http://ad:80/;
proxy_redirect / /adguard/;
proxy_cookie_path / /adguard/;
server {
listen 10.10.0.2:443 ssl http2 proxy_protocol default_server;
listen 10.10.1.2:443 ssl http2 default_server;
ssl_certificate /certs/self_public;
ssl_certificate_key /certs/self_private;
access_log /logs/nginx_ip_access;
location = / {
root /app;
try_files $uri /override.html @auth;
}
location / {
root /app;
auth_basic "Restricted Content";
auth_basic_user_file /app/.htpasswd;
try_files $uri =404;
}
location @auth {
root /app;
auth_basic "Restricted Content";
auth_basic_user_file /app/.htpasswd;
try_files $uri =404;
}
location /tlgrm {
access_log /logs/nginx_tlgrm_access;
proxy_pass http://php;
}
location @php {
proxy_pass http://php;
}
location /adguard/ {
}
location /webapp {
access_log /logs/nginx_webapp_access;
alias /app;
index index.html;
try_files $uri $uri/ @php;
}
location /pac {
access_log /logs/nginx_pac_access;
proxy_set_header Host $http_host;
proxy_pass http://php;
}
location /ws {
proxy_pass http://xr:443;
proxy_redirect off;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_read_timeout 5d;
}
location /v2ray {
access_log /logs/nginx_v2ray_access;
proxy_redirect off;
proxy_buffering off;
proxy_http_version 1.1;
proxy_pass http://ss:8388/;
proxy_set_header Host $http_host;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
location /dns-query {
access_log /logs/nginx_doh_access;
proxy_http_version 1.1;
proxy_set_header Connection "";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-Proto https;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Host $remote_addr;
proxy_cache doh_cache;
proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
proxy_pass https://ad/dns-query;
}
}
location /webapp {
access_log /logs/nginx_webapp_access;
alias /app;
index index.html;
try_files $uri $uri/ /pac?$query_string;
}
location /pac {
access_log /logs/nginx_pac_access;
proxy_set_header Host $http_host;
proxy_pass http://php;
}
location /tlgrm {
access_log /logs/nginx_tlgrm_access;
proxy_pass http://php;
}
location /v2ray {
access_log /logs/nginx_v2ray_access;
proxy_redirect off;
proxy_buffering off;
proxy_http_version 1.1;
proxy_pass http://ss:8388/;
proxy_set_header Host $http_host;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
location /ws {
proxy_pass http://xr:443;
proxy_redirect off;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_read_timeout 5d;
}
#-ssl
# # The DoH server block
# location /dns-query {
# access_log /logs/nginx_doh_access;
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
# proxy_http_version 1.1;
# proxy_set_header Connection "";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-Proto https;
# proxy_set_header X-Forwarded-For $remote_addr;
# proxy_set_header X-Forwarded-Host $remote_addr;
# # Enable Cache, and set the cache_key to include the request_body
# proxy_cache doh_cache;
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
#~
# # proxy pass to the dohloop upstream
# proxy_pass https://ad/dns-query;
# }
#-ssl
location ~\.well-known {
access_log /logs/nginx_certbot_access;
root /certs/;
try_files $uri =404;
}
}
#-domain
# server {
# server_name domain;
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
# listen 10.10.1.2:443 ssl http2;
# ssl_certificate /certs/cert_public;
# ssl_certificate_key /certs/cert_private;
#~
# access_log /logs/nginx_domain_access;
#-domain
# server {
# listen 10.10.0.2:80;
# server_name ;
#-domain
#-ssl
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
# listen 10.10.1.2:443 ssl http2;
# ssl_certificate /certs/cert_public;
# ssl_certificate_key /certs/cert_private;
#-ssl
# location = / {
# root /app;
# try_files $uri /override.html @auth;
# }
#-domain
# access_log /logs/nginx_domain_access;
# location / {
# root /app;
# auth_basic "Restricted Content";
# auth_basic_user_file /app/.htpasswd;
# try_files $uri =404;
# }
# location @auth {
# root /app;
# auth_basic "Restricted Content";
# auth_basic_user_file /app/.htpasswd;
# try_files $uri =404;
# }
# location / {
# root /app;
# index override.html login.html;
# try_files $uri $uri/ =404;
# }
# location /adguard/ {
# access_log /logs/nginx_adguard_access;
# proxy_pass http://ad:80/;
# proxy_redirect / /adguard/;
# proxy_cookie_path / /adguard/;
# }
# location /webapp {
# access_log /logs/nginx_webapp_access;
# alias /app;
# index index.html;
# try_files $uri $uri/ /pac?$query_string;
# }
# location /pac {
# access_log /logs/nginx_pac_access;
# proxy_set_header Host $http_host;
# proxy_pass http://php;
# }
# location ~\.well-known {
# access_log /logs/nginx_certbot_access;
# root /certs/;
# try_files $uri =404;
# }
# location /v2ray {
# access_log /logs/nginx_v2ray_access;
# proxy_redirect off;
# proxy_buffering off;
# proxy_http_version 1.1;
# proxy_pass http://ss:8388/;
# proxy_set_header Host $http_host;
# proxy_set_header Upgrade $http_upgrade;
# proxy_set_header Connection "upgrade";
# }
# location /ws {
# proxy_pass http://xr:443;
# proxy_redirect off;
# proxy_http_version 1.1;
# proxy_set_header Upgrade $http_upgrade;
# proxy_set_header Connection "upgrade";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
# proxy_read_timeout 5d;
# }
#-domain
#-ssl
# # The DoH server block
# location /dns-query {
# access_log /logs/nginx_doh_access;
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
# proxy_http_version 1.1;
# proxy_set_header Connection "";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-Proto https;
# proxy_set_header X-Forwarded-For $remote_addr;
# proxy_set_header X-Forwarded-Host $remote_addr;
# location @php {
# proxy_pass http://php;
# }
# # Enable Cache, and set the cache_key to include the request_body
# proxy_cache doh_cache;
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
# location /adguard/ {
# }
# # proxy pass to the dohloop upstream
# proxy_pass https://ad/dns-query;
# }
#-ssl
#-domain
# }
#-domain
# location /webapp {
# access_log /logs/nginx_webapp_access;
# alias /app;
# index index.html;
# try_files $uri $uri/ @php;
# }
# location /pac {
# access_log /logs/nginx_pac_access;
# proxy_set_header Host $http_host;
# proxy_pass http://php;
# }
# location /v2ray {
# access_log /logs/nginx_v2ray_access;
# proxy_redirect off;
# proxy_buffering off;
# proxy_http_version 1.1;
# proxy_pass http://ss:8388/;
# proxy_set_header Host $http_host;
# proxy_set_header Upgrade $http_upgrade;
# proxy_set_header Connection "upgrade";
# }
# location /ws {
# proxy_pass http://xr:443;
# proxy_redirect off;
# proxy_http_version 1.1;
# proxy_set_header Upgrade $http_upgrade;
# proxy_set_header Connection "upgrade";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
# proxy_read_timeout 5d;
# }
# location /dns-query {
# access_log /logs/nginx_doh_access;
# proxy_http_version 1.1;
# proxy_set_header Connection "";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-Proto https;
# proxy_set_header X-Forwarded-For $remote_addr;
# proxy_set_header X-Forwarded-Host $remote_addr;
# proxy_cache doh_cache;
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
# proxy_pass https://ad/dns-query;
# }
# }
#-domain
}
+1 -1
View File
@@ -505,7 +505,7 @@ ipv4-netmask = 255.255.255.0
# Whether to tunnel all DNS queries via the VPN. This is the default
# when a default route is set.
#tunnel-all-dns = true
tunnel-all-dns = true
# The advertised DNS server. Use multiple lines for
# multiple servers.
+1 -3
View File
@@ -397,7 +397,7 @@ zend.exception_string_param_max_len = 0
; threat in any way, but it makes it possible to determine whether you use PHP
; on your server or not.
; https://php.net/expose-php
expose_php = On
expose_php = Off
;;;;;;;;;;;;;;;;;;;
; Resource Limits ;
@@ -1955,5 +1955,3 @@ opcache.enable=1
opcache.jit_buffer_size=128M
opcache.enable_cli=1
pcre.jit=1
+54 -33
View File
@@ -9,12 +9,12 @@
"tag": "tun-in",
"domain_strategy": "prefer_ipv4",
"interface_name": "sing-tun",
"inet4_address": "172.19.0.1\/30",
"address": [
"172.19.0.1\/30"
],
"mtu": 1400,
"gso": true,
"auto_route": true,
"strict_route": true,
"sniff": true,
"endpoint_independent_nat": false,
"stack": "mixed",
"platform": {
@@ -27,14 +27,9 @@
},
{
"type": "mixed",
"tag": "mixed-in",
"domain_strategy": "prefer_ipv4",
"tag": "in",
"listen": "127.0.0.1",
"listen_port": 2080,
"tcp_fast_open": true,
"sniff": true,
"sniff_override_destination": false,
"users": []
"listen_port": 2080
}
],
"dns": {
@@ -92,14 +87,6 @@
{
"type": "direct",
"tag": "direct"
},
{
"type": "block",
"tag": "block"
},
{
"type": "dns",
"tag": "dns-out"
}
],
"route": {
@@ -107,14 +94,32 @@
"override_android_vpn": true,
"rules": [
{
"protocol": "dns",
"outbound": "dns-out"
"action": "sniff"
},
{
"protocol": "dns",
"action": "hijack-dns"
},
{
"inbound": "in",
"action": "resolve",
"strategy": "prefer_ipv4"
},
{
"inbound": "in",
"action": "sniff",
"timeout": "1s"
},
{
"addruleset": true,
"outbound": "direct"
},
{
"addruleset": true,
"createruleset": [
{
"name": "pac",
"interval": "15s",
"interval": "30s",
"rules": [
{
"domain_suffix": "~pac~"
@@ -122,13 +127,29 @@
]
}
],
"outbound": "~domains_outbound~"
"outbound": "~outbound~"
},
{
"addruleset": true,
"createruleset": [
{
"name": "subnet",
"interval": "30s",
"rules": [
{
"ip_cidr": "~subnet~"
}
]
}
],
"outbound": "~outbound~"
},
{
"addruleset": true,
"createruleset": [
{
"name": "package",
"interval": "15s",
"interval": "30s",
"rules": [
{
"package_name": "~package~"
@@ -136,13 +157,14 @@
]
}
],
"outbound": "~app_outbound~"
"outbound": "~outbound~"
},
{
"addruleset": true,
"createruleset": [
{
"name": "process",
"interval": "15s",
"interval": "30s",
"rules": [
{
"process_name": "~process~"
@@ -150,13 +172,14 @@
]
}
],
"outbound": "~process_outbound~"
"outbound": "~outbound~"
},
{
"addruleset": true,
"createruleset": [
{
"name": "block",
"interval": "15s",
"interval": "30s",
"rules": [
{
"domain_suffix": "~block~"
@@ -164,13 +187,14 @@
]
}
],
"outbound": "block"
"action": "reject"
},
{
"addruleset": true,
"createruleset": [
{
"name": "warp",
"interval": "15s",
"interval": "30s",
"rules": [
{
"domain_suffix": "~warp~"
@@ -179,11 +203,8 @@
}
],
"outbound": "~outbound~"
},
{
"outbound": "direct"
}
],
"final": "~final_outbound~"
"final": "direct"
}
}
+1 -1
View File
@@ -3,7 +3,7 @@
"server_port": 8388,
"local_address": "0.0.0.0",
"local_port": 1080,
"password": "test",
"password": "",
"timeout": 120,
"method": "chacha20-ietf-poly1305",
"no_delay": true,
+1 -1
View File
@@ -1,7 +1,7 @@
{
"server": "0.0.0.0",
"server_port": 8388,
"password": "test",
"password": "",
"timeout": 120,
"method": "chacha20-ietf-poly1305",
"no_delay": true,
+1 -1
View File
@@ -35,7 +35,7 @@ stream {
map_hash_bucket_size 128;
map $ssl_preread_server_name $sni_name {
#domain
telegram.org reality;
t reality;
#domain
#ocserv
+111 -81
View File
@@ -4,92 +4,122 @@
"error": "",
"loglevel": "warning"
},
"inbounds": [{
"tag": "socks",
"port": 10808,
"listen": "127.0.0.1",
"protocol": "socks",
"sniffing": {
"enabled": true,
"destOverride": ["http", "tls"],
"routeOnly": false
},
"settings": {
"auth": "noauth",
"udp": true,
"allowTransparent": false
}
}, {
"tag": "http",
"port": 10809,
"listen": "127.0.0.1",
"protocol": "http",
"sniffing": {
"enabled": true,
"destOverride": ["http", "tls"],
"routeOnly": false
},
"settings": {
"auth": "noauth",
"udp": true,
"allowTransparent": false
}
}],
"outbounds": [{
"tag": "~outbound~",
"protocol": "vless",
"settings": {
"vnext": [{
"address": "~domain~",
"port": 443,
"users": [{
"id": "~uid~",
"alterId": 0,
"email": "t@t.tt",
"security": "auto",
"encryption": "none",
"flow": "xtls-rprx-vision"
}]
}]
},
"streamSettings": {
"network": "tcp",
"security": "reality",
"realitySettings": {
"serverName": "~server_name~",
"fingerprint": "chrome",
"show": false,
"publicKey": "~public_key~",
"shortId": "~short_id~",
"spiderX": ""
"inbounds": [
{
"tag": "socks",
"port": 10808,
"listen": "127.0.0.1",
"protocol": "socks",
"sniffing": {
"enabled": true,
"destOverride": [
"http",
"tls"
],
"routeOnly": false
},
"settings": {
"auth": "noauth",
"udp": true,
"allowTransparent": false
}
},
"mux": {
"enabled": false,
"concurrency": -1
}
}, {
"tag": "direct",
"protocol": "freedom"
}, {
"tag": "block",
"protocol": "blackhole",
"settings": {
"response": {
"type": "http"
{
"tag": "http",
"port": 10809,
"listen": "127.0.0.1",
"protocol": "http",
"sniffing": {
"enabled": true,
"destOverride": [
"http",
"tls"
],
"routeOnly": false
},
"settings": {
"auth": "noauth",
"udp": true,
"allowTransparent": false
}
}
}],
],
"outbounds": [
{
"tag": "direct",
"protocol": "freedom"
},
{
"tag": "~outbound~",
"protocol": "vless",
"settings": {
"vnext": [
{
"address": "~domain~",
"port": 443,
"users": [
{
"id": "~uid~",
"alterId": 0,
"email": "t@t.tt",
"security": "auto",
"encryption": "none",
"flow": "xtls-rprx-vision"
}
]
}
]
},
"streamSettings": {
"network": "tcp",
"security": "reality",
"realitySettings": {
"serverName": "~server_name~",
"fingerprint": "chrome",
"show": false,
"publicKey": "~public_key~",
"shortId": "~short_id~",
"spiderX": ""
}
},
"mux": {
"enabled": false,
"concurrency": -1
}
},
{
"tag": "block",
"protocol": "blackhole",
"settings": {
"response": {
"type": "http"
}
}
}
],
"routing": {
"domainStrategy": "AsIs",
"rules": [{
"type": "field",
"outboundTag": "~outbound~",
"domain": "~pac~"
}, {
"type": "field",
"port": "0-65535",
"outboundTag": "direct"
}]
"rules": [
{
"type": "field",
"outboundTag": "block",
"domain": "~block~"
},
{
"type": "field",
"outboundTag": "~outbound~",
"domain": "~pac~"
},
{
"type": "field",
"outboundTag": "~outbound~",
"ip": "~subnet~"
},
{
"type": "field",
"outboundTag": "~outbound~",
"domain": "~warp~"
}
]
}
}
+44 -23
View File
@@ -16,29 +16,21 @@
"enabled": true
},
"streamSettings": {
"network": "tcp",
"realitySettings": {
"dest": "telegram.org:443",
"maxClientVer": "",
"maxTimeDiff": 0,
"minClientVer": "",
"privateKey": "",
"serverNames": [
"telegram.org"
],
"shortIds": [],
"show": false,
"xver": 0
},
"tcpSettings": {
"acceptProxyProtocol": true
},
"sockopt": {
"acceptProxyProtocol": true
},
"security": "reality"
"network": "ws",
"wsSettings": {
"path": "/ws"
}
},
"tag": "vless_tls"
},
{
"listen": "127.0.0.1",
"port": 8080,
"protocol": "dokodemo-door",
"settings": {
"address": "127.0.0.1"
},
"tag": "api"
}
],
"log": {
@@ -57,6 +49,35 @@
],
"routing": {
"domainStrategy": "AsIs",
"rules": []
"rules": [
{
"inboundTag": [
"api"
],
"outboundTag": "api",
"type": "field"
}
]
},
"stats": {},
"api": {
"services": [
"StatsService"
],
"tag": "api"
},
"policy": {
"levels": {
"0": {
"statsUserUplink": true,
"statsUserDownlink": true
}
},
"system": {
"statsInboundUplink": true,
"statsInboundDownlink": true,
"statsOutboundUplink": true,
"statsOutboundDownlink": true
}
}
}
}
+69 -77
View File
@@ -96,7 +96,7 @@ services:
ipv4_address: 10.10.1.2
logging: *default-logging
php:
image: mercurykd/vpnbot-php:1.6
image: mercurykd/vpnbot-php:1.7
build:
dockerfile: dockerfile/php.dockerfile
args:
@@ -147,7 +147,7 @@ services:
timeout: 5s
retries: 5
service:
image: mercurykd/vpnbot-php:1.6
image: mercurykd/vpnbot-php:1.7
build:
dockerfile: dockerfile/php.dockerfile
args:
@@ -160,8 +160,11 @@ services:
- ./ssh:/ssh
- ./app:/app
- ./logs/:/logs/
- ./version:/version
- ./update:/update
- ./.git:/.git
- ./scripts/start_service.sh:/start_service.sh
- ./docker-compose.override.yml:/docker/compose
- /var/run/docker.sock:/var/run/docker.sock:ro
environment:
IP: ${IP}
@@ -185,45 +188,15 @@ services:
- up
- ng
- php
- proxy
- wg
- wg1
- ad
- ss
- tg
- xr
- oc
- np
proxy:
image: mercurykd/vpnbot-ss:1.2
build:
dockerfile: dockerfile/shadowsocks.dockerfile
args:
image: ${IMAGE}
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/sslocal.json:/config.json
- ./ssh:/ssh
- ./config/sshd_config:/etc/ssh/sshd_config
- ./scripts/start_proxy.sh:/start_proxy.sh
hostname: proxy
container_name: proxy-${VER}
depends_on:
php:
condition: service_healthy
networks:
default:
ipv4_address: 10.10.0.3
environment:
TZ: ${TZ}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_proxy.sh"]
logging: *default-logging
- proxy
- ss
wg:
image: mercurykd/vpnbot-wg:1.1
build:
@@ -245,8 +218,6 @@ services:
depends_on:
php:
condition: service_healthy
ports:
- ${WGPORT}:${WGPORT}/udp
env_file:
- path: ./.env
required: true # default
@@ -285,8 +256,6 @@ services:
depends_on:
php:
condition: service_healthy
ports:
- ${WG1PORT}:${WG1PORT}/udp
env_file:
- path: ./.env
required: true # default
@@ -305,13 +274,11 @@ services:
ipv4_address: 10.10.0.14
logging: *default-logging
ad:
image: mercurykd/vpnbot-ad:1.2
image: mercurykd/vpnbot-ad:1.3
build:
dockerfile: dockerfile/adguard.dockerfile
args:
image: ${IMAGE}
ports:
- 853:853
volumes:
- ./config/.profile:/root/.ashrc:ro
- type: volume
@@ -341,37 +308,6 @@ services:
- NET_ADMIN
entrypoint: ["/bin/sh", "/start_ad.sh"]
logging: *default-logging
ss:
image: mercurykd/vpnbot-ss:1.2
build:
dockerfile: dockerfile/shadowsocks.dockerfile
args:
image: ${IMAGE}
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/ssserver.json:/config.json
- ./ssh:/ssh
- ./config/sshd_config:/etc/ssh/sshd_config
- ./scripts/start_ss.sh:/start_ss.sh
hostname: shadowsocks
container_name: shadowsocks-${VER}
depends_on:
php:
condition: service_healthy
ports:
- ${SSPORT}:${SSPORT}/tcp
- ${SSPORT}:${SSPORT}/udp
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_ss.sh"]
networks:
default:
ipv4_address: 10.10.0.6
logging: *default-logging
tg:
image: mercurykd/vpnbot-tg:1.1
build:
@@ -387,8 +323,6 @@ services:
depends_on:
php:
condition: service_healthy
ports:
- ${TGPORT}:${TGPORT}
environment:
IP: ${IP}
env_file:
@@ -403,7 +337,7 @@ services:
ipv4_address: 10.10.0.8
logging: *default-logging
xr:
image: mercurykd/vpnbot-xr:1.3
image: mercurykd/vpnbot-xr:1.4
build:
dockerfile: dockerfile/xray.dockerfile
args:
@@ -498,7 +432,7 @@ services:
ipv4_address: 10.10.0.12
logging: *default-logging
wp:
image: mercurykd/vpnbot-wp:1.2
image: mercurykd/vpnbot-wp:1.3
build:
dockerfile: dockerfile/warp.dockerfile
args:
@@ -508,7 +442,7 @@ services:
devices:
- /dev/net/tun:/dev/net/tun
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/.profile:/root/.bashrc:ro
- ./ssh:/ssh
- ./config/sshd_config:/etc/ssh/sshd_config
- ./config:/config
@@ -531,3 +465,61 @@ services:
default:
ipv4_address: 10.10.0.13
logging: *default-logging
proxy:
image: mercurykd/vpnbot-ss:1.2
build:
dockerfile: dockerfile/shadowsocks.dockerfile
args:
image: ${IMAGE}
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/sslocal.json:/config.json
- ./ssh:/ssh
- ./config/sshd_config:/etc/ssh/sshd_config
- ./scripts/start_proxy.sh:/start_proxy.sh
hostname: proxy
container_name: proxy-${VER}
depends_on:
php:
condition: service_healthy
networks:
default:
ipv4_address: 10.10.0.3
environment:
TZ: ${TZ}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_proxy.sh"]
logging: *default-logging
ss:
image: mercurykd/vpnbot-ss:1.2
build:
dockerfile: dockerfile/shadowsocks.dockerfile
args:
image: ${IMAGE}
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/ssserver.json:/config.json
- ./ssh:/ssh
- ./config/sshd_config:/etc/ssh/sshd_config
- ./scripts/start_ss.sh:/start_ss.sh
hostname: shadowsocks
container_name: shadowsocks-${VER}
depends_on:
php:
condition: service_healthy
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_ss.sh"]
networks:
default:
ipv4_address: 10.10.0.6
logging: *default-logging
+12 -11
View File
@@ -22,16 +22,17 @@ RUN apk add --no-cache --update php81 \
curl \
git \
py3-qt5 \
&& wget https://github.com/ameshkov/dnslookup/releases/download/v1.9.1/dnslookup-linux-amd64-v1.9.1.tar.gz \
&& tar -xf dnslookup-linux-amd64-v1.9.1.tar.gz \
&& mkdir /root/.ssh \
&& wget https://github.com/ameshkov/dnslookup/releases/download/v1.11.1/dnslookup-linux-amd64-v1.11.1.tar.gz \
&& tar -xf dnslookup-linux-amd64-v1.11.1.tar.gz \
&& mv linux-amd64/dnslookup /usr/bin \
&& rm dnslookup-linux-amd64-v1.9.1.tar.gz \
&& rm dnslookup-linux-amd64-v1.11.1.tar.gz \
&& rm -rf /linux-amd64 \
&& wget https://github.com/SagerNet/sing-box/releases/download/v1.8.11/sing-box-1.8.11-linux-amd64.tar.gz \
&& tar -xf sing-box-1.8.11-linux-amd64.tar.gz \
&& mv sing-box-1.8.11-linux-amd64/sing-box /usr/bin \
&& rm sing-box-1.8.11-linux-amd64.tar.gz \
&& rm -rf /sing-box-1.8.11-linux-amd64
RUN apk add openssh \
&& mkdir /root/.ssh
ENV ENV="/root/.ashrc"
&& wget https://github.com/SagerNet/sing-box/releases/download/v1.10.3/sing-box-1.10.3-linux-amd64.tar.gz \
&& tar -xf sing-box-1.10.3-linux-amd64.tar.gz \
&& mv sing-box-1.10.3-linux-amd64/sing-box /usr/bin \
&& rm sing-box-1.10.3-linux-amd64.tar.gz \
&& rm -rf /sing-box-1.10.3-linux-amd64 \
&& wget https://github.com/MetaCubeX/mihomo/releases/download/v1.18.10/mihomo-linux-amd64-v1.18.10.gz \
&& gunzip mihomo-linux-amd64-v1.18.10.gz \
&& mv mihomo-linux-amd64-v1.18.10 /usr/bin/mihomo
+3 -13
View File
@@ -1,16 +1,6 @@
FROM ubuntu:22.04 AS build
RUN apt update && apt install -y curl gpg lsb-release \
FROM ubuntu:22.04
RUN apt update && apt install -y curl gpg socat jq lsb-release openssh-server \
&& curl -fsSL https://pkg.cloudflareclient.com/pubkey.gpg | gpg --yes --dearmor --output /usr/share/keyrings/cloudflare-warp-archive-keyring.gpg \
&& echo "deb [signed-by=/usr/share/keyrings/cloudflare-warp-archive-keyring.gpg] https://pkg.cloudflareclient.com/ $(lsb_release -cs) main" | tee /etc/apt/sources.list.d/cloudflare-client.list \
&& apt update && apt install -y cloudflare-warp
FROM alpine:3.17
ARG GLIBC_VERSION=2.34-r0
COPY --from=build /usr/bin/warp-cli /usr/bin/warp-svc /usr/local/bin/
RUN apk add --no-cache dbus-libs wget socat openssh-server jq curl \
&& mkdir /tmp/glibc-pkgs \
&& for PKG in glibc-$GLIBC_VERSION.apk glibc-bin-$GLIBC_VERSION.apk; do wget -q --directory-prefix /tmp/glibc-pkgs https://github.com/sgerrand/alpine-pkg-glibc/releases/download/$GLIBC_VERSION/$PKG; done \
&& apk add --no-cache --allow-untrusted --force-overwrite /tmp/glibc-pkgs/* \
&& rm -rf /tmp/glibc-pkgs \
&& /usr/glibc-compat/sbin/ldconfig /lib /usr/glibc-compat/lib \
&& apt update && apt install -y cloudflare-warp \
&& mkdir /root/.ssh
+12 -2
View File
@@ -32,7 +32,7 @@ up: # консоль сервиса
ad: # консоль сервиса
docker compose exec ad /bin/sh
wp: # консоль сервиса
docker compose exec wp /bin/sh
docker compose exec wp bash
proxy: # консоль сервиса
docker compose exec proxy /bin/sh
tg: # консоль сервиса
@@ -41,6 +41,8 @@ xr: # консоль сервиса
docker compose exec xr /bin/sh
oc: # консоль сервиса
docker compose exec oc /bin/sh
service: # консоль сервиса
docker compose exec service /bin/sh
clean:
docker image prune
docker builder prune
@@ -59,4 +61,12 @@ c:
git checkout .
git reset
webhook:
docker compose exec php php checkwebhook.php
docker compose exec php php checkwebhook.php
reset:
make d
git reset --hard
git clean -fd
docker volume rm vpnbot_adguard vpnbot_warp
make u
backup:
docker compose exec php php backup.php > backup.json
+19 -72
View File
@@ -1,82 +1,29 @@
telegram bot to manage servers (inside the bot)
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/d5a81237-5215-41db-87e5-20734120cc9c" width="200">
### XTLS-Reality
- change secret
- qr/config
- change fake domain
- multiple users
- subscriptions with routing
- routing templates per user
- steal from yourself
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/39bdf4e0-96a6-4257-b61e-30a14122e236" width="200">
### NaiveProxy
- change login
- change password
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/2127a4af-0436-452c-bfe2-c750dd5dbc06" width="200">
### OpenConnect
- change secret
- change password
- change dns
- add user
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/a4ffc04f-965a-439b-862b-210b98e1f87d" width="200">
### Wireguard / Amnezia
- create
- delete
- rename
- timer
- torrent blocking
- qr/config
- statistics
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/51a79c93-8083-40ba-a14b-a6ef19f00531" width="200">
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/fd6ffd9f-bd75-479c-8dca-ea6c0b938b6c" width="200">
### Shadowsocks + v2ray
- change password
- on/off v2ray
- qr
- short link
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/fbe39617-63ae-4536-8ab0-e4269ed8784a" width="200">
### AdguardHome
- change password
- change upstream dns
- check dns
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/a7d4ba52-494b-429f-a3e2-08c68c8353c4" width="200">
### PAC
- the ability to create your own PAC available by url with the ability to substitute the final ip and port
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/5343e009-1b21-450f-918d-b811b98a0549" width="200">
### MTProto
- change secret
- qr/config
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/411696d8-172a-4dac-b6b7-4a6da3adfab2" width="200">
### Settings
- add/change admin
- change language (en/ru)
- import/export all settings
- domain binding
- obtain ssl for domain
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/431ec09d-9c14-4c74-b8f6-e49c142132e8" width="200">
- VLESS (Reality OR Websocket)
- NaiveProxy
- OpenConnect
- Wireguard
- Amnezia
- AdguardHome
- MTProto
- PAC
- automatic ssl
---
environment: ubuntu 18.04/20.04/22.04, debian 11/12
environment: ubuntu 22.04/24.04, debian 11/12
### Install:
## Install:
```shell
wget -O- https://raw.githubusercontent.com/mercurykd/vpnbot/master/scripts/init.sh | sh -s YOUR_TELEGRAM_BOT_KEY
wget -O- https://raw.githubusercontent.com/mercurykd/vpnbot/master/scripts/init.sh | sh -s YOUR_TELEGRAM_BOT_KEY master
```
### Install as service (autoload on start):
#### Restart:
```shell
cd /root/vpnbot
bash scripts/install_as_service.sh
make r
```
#### autoload:
```shell
crontab -e
```
add `@reboot cd /root/vpnbot && make r` and save
-5
View File
@@ -1,5 +0,0 @@
make d
rm /etc/systemd/resolved.conf.d/adguardhome.conf
mv /etc/resolv.conf.backup /etc/resolv.conf
systemctl reload-or-restart systemd-resolved
make u
-8
View File
@@ -1,8 +0,0 @@
mkdir /etc/systemd/resolved.conf.d
echo "[Resolve]
DNS=127.0.0.1
DNSStubListener=no" > /etc/systemd/resolved.conf.d/adguardhome.conf
mv /etc/resolv.conf /etc/resolv.conf.backup
ln -s /run/systemd/resolve/resolv.conf /etc/resolv.conf
systemctl reload-or-restart systemd-resolved
make d u
+2
View File
@@ -1,3 +1,4 @@
TAG="${2:-master}"
apt update
apt install -y \
ca-certificates \
@@ -13,6 +14,7 @@ apt install -y \
curl -fsSL https://get.docker.com -o get-docker.sh && sh get-docker.sh
git clone https://github.com/mercurykd/vpnbot.git
cd ./vpnbot
git checkout $TAG
echo "<?php
\$c = ['key' => '$1'];" > ./app/config.php
+1
View File
@@ -2,4 +2,5 @@ cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
php service.php
php iplimit.php &
php cron.php
+4 -3
View File
@@ -1,9 +1,10 @@
cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
echo 'HostKeyAlgorithms +ssh-rsa' >> /etc/ssh/sshd_config
echo 'PubkeyAcceptedKeyTypes +ssh-rsa' >> /etc/ssh/sshd_config
service ssh start
off=$(cat /config/pac.json | jq -r .warpoff)
key=$(cat /config/pac.json | jq -r .warp)
if [ "$off" == 'null' ]
if [ "$off" = 'null' ]
then
warp-svc > /dev/null &
sleep 3
Binary file not shown.
+11 -2
View File
@@ -1,5 +1,14 @@
#!/bin/bash
pwd=`pwd`
process_name="$pwd/update/update.sh"
current_pid=$$
pids=$(pgrep -f $process_name)
for pid in $pids; do
if [ $pid -ne $current_pid ]; then
kill -9 $pid
fi
done
> $pwd/update/pipe
echo "$$" > $pwd/update/update_pid
@@ -27,10 +36,10 @@ do
git pull > ./update/message
fi
curl -H "Content-Type: application/json" -X POST https://api.telegram.org/bot$key/editMessageText -d "$(cat $pwd/update/curl | sed 's/"text":"~t~"/"text": "launching the bot"/')"
IP=$(curl ipinfo.io/ip) VER=$(git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
bash $pwd/update/update.sh &
> $pwd/update/key
> $pwd/update/curl
IP=$(curl -s -t 1 2ip.io || curl -s -t 1 ipinfo.io/ip || curl -s -t 1 ifconfig.me) VER=$(git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
bash $pwd/update/update.sh &
exit 0
fi
sleep 1
+123
View File
@@ -1,3 +1,126 @@
18.04.2025 v2.18
- фикс отсутствия ssl при первом старте
- iplimit уведомляет без отключения пользователя
- включение udp в mihomo-шаблоне
- удаление лишнего образа пхп
07.04.2025 v2.17
- фикс циклической перезагрузки панели adguardHome
07.04.2025 v2.16
- фикс warp
07.04.2025 v2.15
- миграция поддоменов np/oc вместе в с бэкапом
02.03.2025 v2.14
- vless ip limit: фикс выключения юзера
22.02.2025 v2.13
- vless: улучшение сбора статы
- vless: фикс добавления правил srs для block outbound
11.02.2025 v2.12
- vless: хранение статы в отдельном файле
- vless ip limit: возможность указать кол-во айпи
08.02.2025 v2.11
- vless: singbox 1.11
07.02.2025 v2.10
- vless: ip limit
- vless: общая стата
- vless: пакетное добавление профилей
- vless: при добавлении можно указывать свой uuid (name:uuid, name:uuid, ...)
- автоудаление логов
- хэш бота сохраняется в настройках и восстанавливается с бэкапом. можно накатывать бэкап на нового бота
02.02.2025 v2.9
- откат sing-box 1.11
02.02.2025 v2.8
- vless: корректировка статы юзера
- sing-box 1.11
29.01.2025 v2.7
- vless: сброс статистики юзера
24.01.2025 v2.6
- правки меню
- vless:добавлена возможность маршрутизировать список ip-сетей
18.01.2025 v2.5
- фикс скачивания шаблона михомо
- обновлен singbox.exe
- вывод статистики vless пользователей
- смягчил паттерн поиска reality degenerate в логах
07.01.2025 v2.4
- вернул shadowsocks (спасибо за донат)
04.01.2025
- возможность установить нужную версию с нуля
- корректировка автосканера под новую версию
- улучшение основного меню
26.12.2024 v2.2
- возможность менять поддомен для naive/openconnect
26.12.2024 v2.1
- обновление версии singbox и конфига под него
22.12.2024 v2.0
!!! версия не совместима с предыдущими, возможно прийдется накатывать руками. старые конфиги (кроме вг) не будут работать! перед обновлением:
- включить все порты или удалить docker-compose.override.yml
- переключить vless на вебсокет
- запустить обновление, если бот запуститься:
- перевыпустить сертификаты
- все ссылки на конфиги будут новыми (старые не будут работать)
- переключить vless на нужный режим (передернуть тумблер)
- включить нужные вам порты (по умолчанию включено только 80 и 443)
что нового:
- по умолчанию включены только 80, 443 порты
- у каждого инстанса бота теперь индивидуальные ссылки и поддомены
- отключены заголовки в ответах по которым можно было идентифицировать бота
- стандартная заглушка на главной заменена на basic auth. если есть override.html - то покажет его
- любая ссылка 'не по адресам бота' выдает непроходимый basic auth
- поддомены np и oc теперь у каждого индивидуальные
- выпилен shadowsocks (10.10.0.3 прокси теперь нет)
- добавлен direct rule в origin-singbox шаблон
- заменены значки для silence mode анализатора логов
- переработано главное меню аля дашбоард
- куча отрефакторенного кода - возможны баги
19.12.2024 v1.115
- генерация устойчивого пароля shadowsocks, если он равен test или пуст
19.12.2024 v1.114
- убран дефолтный пароль у shadowsocks
13.12.2024 v1.113
- обновлен adguardHome
- фикс краша adg при удалении dns-upstream из бота
10.12.2024 v1.112
- mihomo: встроенные списки теперь отдаются через rule-providers(т.е подгружаются ядром без обновления конфига)
- обновлены ядра
09.12.2024 v1.111
- mihomo: фикс rule-providers format
06.12.2024 v1.110
- ruleset для mihomo
28.11.2024 v1.109
- фикс автоскана
- добавление clash-шаблонов
21.11.2024 v1.108
- xray: addruleset для direct
- openconnect:ограничение формата при добавлении подсети
- новый механизм сверки ip для анализатора айпи
- мелкие фиксы меню и текста
21.11.2024 v1.107
- xray: добавлены теги ~cdndomain~, ~directdomain~
- xray: возможность менять имя главного аутбаунда(тот аутбаунд который заполняет бот, в шаблонах идет как ~outbound~) для клиентских конфигов
- xray: в шаблонах теперь надо явно указывать ключ addruleset в route -> rules, чтобы бот заполнил их правилами из списка ruleset (см origin шаблон)
- openconnect: добавлена маршрутизация (список подсетей общий с wireguard)
- ip ban: фикс обработки подсетей в белом/черном списках
- ip ban: в белый список можно импортировать адреса от telegram, gcore, cloudflare
- добавлена в игнор папка app/webapp/override. она не будет перезатираться после обновления, туда можно положить ваши ресурсы к override.html
- <code>make backup</code> - сохранит в корень backup.json
- <code>make reset</code> - обнуляет все настройки
18.11.2024 v1.106
- фикс отвала бота при пустых логах телеги
17.11.2024 v1.105
- фикс установки домена при первом запуске
16.11.2024 v1.104
- единая механика закрепления бэкапа
- фикс текста уведомления о новой версии
16.11.2024 v1.103
- фикс уведомления о новой версии
16.11.2024 v1.102
- переделан раздел списка ip под управление кнопками
- возможность добавить свои айпи в blocklist/whitelist
15.11.2024 v1.101
- кнопка добавления https://github.com/legiz-ru/sb-rule-sets/raw/main/ru-bundle.lst
- переделан раздел списка ip для читаемости
15.11.2024 v1.100
- несколько режимов silence для сканера
- анализ сканера скидывает файл всех найденных айпи