socks5proxy

package module
v0.0.0-...-d4fcde0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 20, 2026 License: MIT Imports: 15 Imported by: 2

README

Socks5Proxy

GitHub license GitHub stars GitHub forks Language Go Report Card

用golang 实现了一个简单的socks5协议来实现代理转发,主要应用场景是給公司内部做VPN登陆,提供内网访问。(声明:由于采用的是原始的socks5协议,并没有对协议做改造加工,并不一定能防范GFW的主动探测,请勿用于非法用途)

项目同时支持两种运行模式:

  • proxy:HTTP/SOCKS5 TCP 应用代理,支持 HTTP 转发、HTTPS CONNECT 和 simple / random 流量混淆。
  • tunnel:Linux/macOS/Windows 全局 IPv4 TUN,以及 Android VpnService / iOS Packet Tunnel 原生客户端,默认使用 QUIC + TLS 1.3;可选 TCP + TLS 1.3(-transport tcp)或显式无加密 TCP(-transport tcp-plain),支持 none / simple / random 混淆。

客户端平台

平台 架构 使用入口
Linux amd64、arm64 CLI,TUN 模式需要 root / 网络管理权限
Windows amd64、arm64 CLI,以管理员身份运行;使用包含对应 Wintun DLL 的 ZIP
macOS Intel、Apple Silicon CLI,TUN 模式需要 sudo
Android 8.0+ arm64、armv7、x86_64 原生配置界面 + VpnService;构建 APK 后安装
iOS / iPadOS 15+ arm64;模拟器 arm64、x86_64 SwiftUI + NetworkExtension;真机需 Apple 签名

桌面发布物由 Release workflow 构建;移动源码、AAR/XCFramework 和应用构建入口见移动客户端文档。移动端目前提供全局 IPv4 隧道,尚无真机联网验收;IPv6 被阻断。应用签名和商店分发由使用者配置。

安全说明

  • 当前 simple / random 仅用于流量混淆,不是安全加密,也不提供现代意义上的机密性、完整性或重放防护。
  • 全局隧道默认 quic,以及可选的 tcp,使用 TLS 1.3;不会自动降级为明文。tcp-plain 不提供 IP 包机密性或完整性,即使使用 random 也是如此。
  • 两个 TCP 后端使用新鲜随机挑战和 HMAC 认证,线路上传输认证证明,不直接发送令牌或摘要。摘要本身等价于 TCP 认证凭据,应保密;明文模式仍可被监听、篡改或中继,应使用独立测试令牌。
  • 不要把 simple / random 当作 TLS、SSH、WireGuard 或 AEAD 安全通道的替代品。
  • proxy 密码最终只影响至多 256 张替换表,长密码不能提升其密码学强度。本地监听无用户认证,默认只绑定 127.0.0.1:8888;服务端没有目标地址 ACL,部署时应限制访问来源和出口。
  • TLS 隧道保护客户端至服务端这一段;服务端仍可看到解封装的流量。目标站点的数据保护依赖 HTTPS 等端到端协议。完整边界见安全与威胁模型。

文件结构

cryptogram.go       `流量混淆算法`
socks5.go           `socks5协议实现`
server.go           `服务端实现`
client.go           `客户端实现`
cmd/server/main.go  `服务端主启动程序`
cmd/client/main.go  `客户端主启动程`
internal/tunnel/    `全局加密隧道、TUN 和系统网络配置`
mobile/            `可嵌入的 Go 隧道核心,gomobile 绑定接口`
apps/android/      `Android 原生 VPN 应用`
apps/ios/          `iOS 原生应用与 Packet Tunnel 扩展`
使用说明

从 GitHub Releases 下载对应系统/架构的产物并校验 SHA256SUMS。Release 可能落后于源码;下面也提供从仓库根目录运行的方式(Go 版本见 go.mod)。

客户端和服务端可以在同一台机器运行,使用两个不同端口。分别在两个终端执行:

# 终端 1:服务端
go run ./cmd/server -mode proxy -local 127.0.0.1:18888 -type random -passwd demo-only
# 终端 2:客户端
go run ./cmd/client -mode proxy -local 127.0.0.1:8888 \
  -server 127.0.0.1:18888 -type random -passwd demo-only -recv http
curl --noproxy "" --proxy http://127.0.0.1:8888 https://example.com/

浏览器设置 HTTP/HTTPS 代理为 127.0.0.1:8888。若客户端改为 -recv socks5,浏览器也必须选择 SOCKS5,curl 使用 --proxy socks5h://127.0.0.1:8888。代理目标不能指回这两个监听端口。跨机器部署时,客户端的 -server 改为服务端地址;完整说明见应用代理部署。

-passwd 没有默认值,必须显式设置;-type 默认 random,两端必须相同。客户端 -recv 默认 http。应用代理只处理主动配置代理的应用;全局 IPv4 流量请使用隧道模式。

两端 proxy 模式均支持以下资源参数:

参数 默认值 含义
-max-connections 256 每个进程的最大活动会话数,额外连接留在系统监听队列
-dial-timeout 10s 上游/目标连接及 DNS 的超时
-handshake-timeout 10s 从接收连接到完成协议协商的总预算
-idle-timeout 5m 双向均无流量时回收连接

握手总预算包含连接时间;这些参数为 0 时使用默认值,负数无效。每会话约占用两个 FD,低 ulimit -n 环境应下调并发上限,详见资源排障。Ctrl+C 会关闭监听及活动会话并等待退出。

TODO

  • 明确 simple / random 仅用于流量混淆,不作为安全加密承诺(#23)
  • 迁移 CI 到 GitHub Actions,并补齐格式化 / 测试 / vet / staticcheck(#25)
  • 将发布物迁移到 GitHub Releases,并提供 SHA256SUMS(#28)
  • 补充 README 的安全声明与威胁模型说明(#29)
  • 说明客户端与服务端同机部署的使用方式(#2)
  • 排查并缓解 socket: too many open files 问题(#3)
  • 更新下载与使用说明,覆盖最新发布方式与问题排查入口(#4)

实现细节、复现与验证结果见 README TODO 验证记录。

Documentation

Index

Constants

View Source
const (
	RANDOM_A = 13
	RANDOM_B = 7
	RANDOM_M = 256
)
View Source
const (
	SOCKS_VERSION = 0x05
	METHOD_CODE   = 0x00
)

Variables

This section is empty.

Functions

func Client

func Client(local, remote, obfs, password, mode string) error

Client retains the original blocking API using default resource limits.

func ClientContext

func ClientContext(ctx context.Context, local, remote, obfs, password, mode string, options ProxyOptions) error

ClientContext serves an HTTP or SOCKS5 application proxy until cancellation.

func CreateAuth

func CreateAuth(encrytype string, passwd string) (socks5Auth, error)

创建流量混淆器。当前实现不是安全通道。

func SecureCopy

func SecureCopy(src io.ReadWriteCloser, dst io.ReadWriteCloser, secure func(b []byte) error) (written int64, err error)

SecureCopy 对有效负载做流量混淆后再转发。

func Server

func Server(local, obfs, password string) error

Server retains the original blocking API using default resource limits.

func ServerContext

func ServerContext(ctx context.Context, local, obfs, password string, options ProxyOptions) error

ServerContext serves the obfuscated SOCKS proxy until cancellation.

Types

type DefaultAuth

type DefaultAuth struct {
	Encode *[256]byte //编码表
	Decode *[256]byte //解码表
}

func CreateRandomCipher

func CreateRandomCipher(passwd string) (*DefaultAuth, error)

func CreateSimpleCipher

func CreateSimpleCipher(passwd string) (*DefaultAuth, error)

func (*DefaultAuth) DecodeRead

func (s *DefaultAuth) DecodeRead(c io.ReadWriter, b []byte) (int, error)

func (*DefaultAuth) Decrypt

func (s *DefaultAuth) Decrypt(b []byte) error

func (*DefaultAuth) EncodeWrite

func (s *DefaultAuth) EncodeWrite(c io.ReadWriter, b []byte) (int, error)

func (*DefaultAuth) Encrypt

func (s *DefaultAuth) Encrypt(b []byte) error

type Protocol

type Protocol interface {
	HandleHandshake(b []byte) ([]byte, error)
	SentHandshake(conn net.Conn) error
}

type ProtocolVersion

type ProtocolVersion struct {
	VER      uint8
	NMETHODS uint8
	METHODS  []uint8
}

*

The localConn connects to the dstServer, and sends a ver
identifier/method selection message:
            +----+----------+----------+
            |VER | NMETHODS | METHODS  |
            +----+----------+----------+
            | 1  |    1     | 1 to 255 |
            +----+----------+----------+
The VER field is set to X'05' for this ver of the protocol.  The
NMETHODS field contains the number of method identifier octets that
appear in the METHODS field.
METHODS常见的几种方式如下:
1>.数字“0”:表示不需要用户名或者密码验证;
2>.数字“1”:GSSAPI是SSH支持的一种验证方式;
3>.数字“2”:表示需要用户名和密码进行验证;
4>.数字“3”至“7F”:表示用于IANA 分配(IANA ASSIGNED)
5>.数字“80”至“FE”表示私人方法保留(RESERVED FOR PRIVATE METHODS)
4>.数字“FF”:不支持所有的验证方式,无法进行连接

*

func (*ProtocolVersion) HandleHandshake

func (s *ProtocolVersion) HandleHandshake(b []byte) ([]byte, error)

func (*ProtocolVersion) SentHandshake

func (s *ProtocolVersion) SentHandshake(conn net.Conn) error

type ProxyOptions

type ProxyOptions struct {
	MaxConnections   int
	DialTimeout      time.Duration
	HandshakeTimeout time.Duration
	IdleTimeout      time.Duration
}

ProxyOptions bounds resource use in application proxy mode. Zero selects the default; negative values are rejected. IdleTimeout measures either direction.

type Socks5AuthUPasswd

type Socks5AuthUPasswd struct {
	VER    uint8
	ULEN   uint8
	UNAME  string
	PLEN   uint8
	PASSWD string
}

func (*Socks5AuthUPasswd) HandleAuth

func (s *Socks5AuthUPasswd) HandleAuth(b []byte) ([]byte, error)

type Socks5Resolution

type Socks5Resolution struct {
	VER       uint8
	CMD       uint8
	RSV       uint8
	ATYP      uint8
	DSTADDR   []byte
	DSTPORT   uint16
	DSTDOMAIN string
	RAWADDR   *net.TCPAddr
}

*

结构:
+----+-----+-------+------+----------+----------+
|VER | CMD |  RSV  | ATYP | DST.ADDR | DST.PORT |
+----+-----+-------+------+----------+----------+
| 1  |  1  | X'00' |  1   | Variable |    2     |
+----+-----+-------+------+----------+----------+
cmd代表客户端请求的类型,值长度也是1个字节,有三种类型:
    1>.数字“1”:表示客户端需要你帮忙代理连接,即CONNECT ;
    2>.数字“2”:表示让你代理服务器,帮他建立端口,即BIND ;
    3>.数字“3”:表示UDP连接请求用来建立一个在UDP延迟过程中操作UDP数据报的连接,即UDP ASSOCIATE;
ATYP代表请求的远程服务器地址类型,它是一个可变参数,但是它值的长度1个字节,
有三种类型:
    1>.数字“1”:表示是一个IPV4地址(IP V4 address);
    2>.数字“3”:表示是一个域名(DOMAINNAME);
    3>.数字“4”:表示是一个IPV6地址(IP V6 address);

*

func (*Socks5Resolution) LSTRequest

func (s *Socks5Resolution) LSTRequest(b []byte) ([]byte, error)

Directories

Path Synopsis
cmd
client command
server command
internal
tunnel/session
Package session provides authentication shared by desktop and mobile clients.
Package session provides authentication shared by desktop and mobile clients.
tunnel/testutil
Package testutil supplies local-only TLS fixtures for tunnel tests.
Package testutil supplies local-only TLS fixtures for tunnel tests.
Package mobile is the gomobile-compatible IPv4 tunnel client.
Package mobile is the gomobile-compatible IPv4 tunnel client.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL