Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Sign in / Register
Toggle navigation
G
gost
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Locked Files
Issues
0
Issues
0
List
Boards
Labels
Service Desk
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Security & Compliance
Security & Compliance
Dependency List
License Compliance
Packages
Packages
List
Container Registry
Analytics
Analytics
CI / CD
Code Review
Insights
Issues
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
nanahira
gost
Commits
f2de67f8
Commit
f2de67f8
authored
Sep 07, 2016
by
rui.zheng
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
pretty logs
parent
ec8cfa44
Changes
6
Show whitespace changes
Inline
Side-by-side
Showing
6 changed files
with
62 additions
and
27 deletions
+62
-27
README.md
README.md
+21
-7
conn.go
conn.go
+21
-11
forward.go
forward.go
+3
-0
socks.go
socks.go
+5
-1
ss.go
ss.go
+9
-5
ws.go
ws.go
+3
-3
No files found.
README.md
View file @
f2de67f8
...
...
@@ -44,20 +44,18 @@ protocol: 代理协议类型(http, socks5, shadowsocks), transport: 数据传输
> ss - 作为shadowsocks服务,ss://aes-256-cfb:123456@:8080
####
本地
端口转发
#### 端口转发
适用于-L参数
```
bash
scheme://[bind_address]:port/[host]:hostport
```
> scheme - 端口转发
类型: tcp,
udp
> scheme - 端口转发
模式, 本地端口转发: tcp, udp; 远程端口转发: rtcp, r
udp
> bind_address:port - 本地
监听
地址
> bind_address:port - 本地
/远程绑定
地址
> host:hostport - 远程地址
当在bind_address:port上收到连接信息,则会(通过转发链)与host:hostport建立连接,创建一条数据通道。
> host:hostport - 目标访问地址
#### 开启日志
...
...
@@ -123,7 +121,23 @@ gost -L=udp://:5353/192.168.1.1:53 -F=...
```
将本地UDP端口5353上的数据(通过转发链)转发到192.168.1.1:53上。
**注: 如果有转发链,则转发链的末端(最后一个-F参数)必须是gost socks5类型代理。**
**注: 转发UDP数据时,如果有转发链,则转发链的末端(最后一个-F参数)必须是gost socks5类型代理。**
#### 远程端口转发(TCP)
```
bash
gost
-L
=
rtcp://:2222/192.168.1.1:22
-F
=
...
-F
=
socks://172.24.10.1:1080
```
将172.24.10.1:2222上的数据(通过转发链)转发到192.168.1.1:22上。
#### 远程端口转发(UDP
```
bash
gost
-L
=
rudp://:5353/192.168.1.1:53
-F
=
...
-F
=
socks://172.24.10.1:1080
```
将172.24.10.1:5353上的数据(通过转发链)转发到192.168.1.1:53上。
**注: 若要使用远程端口转发功能,则至少要设置一个-F参数,且转发链的末端(最后一个-F参数)必须是gost socks5类型代理。**
加密机制
------
...
...
conn.go
View file @
f2de67f8
...
...
@@ -17,7 +17,7 @@ import (
"strconv"
"strings"
"sync"
"sync/atomic"
//
"sync/atomic"
"time"
)
...
...
@@ -76,6 +76,10 @@ func listenAndServe(arg Args) error {
glog
.
V
(
LWARNING
)
.
Infoln
(
err
)
continue
}
if
tc
,
ok
:=
conn
.
(
*
net
.
TCPConn
);
ok
{
tc
.
SetKeepAlive
(
true
)
tc
.
SetKeepAlivePeriod
(
time
.
Second
*
180
)
}
go
handleConn
(
conn
,
arg
)
}
}
...
...
@@ -175,6 +179,7 @@ func serveRUdpForward(arg Args) error {
}
func
handleConn
(
conn
net
.
Conn
,
arg
Args
)
{
/*
atomic.AddInt32(&connCounter, 1)
glog.V(LDEBUG).Infof("%s connected, connections: %d",
conn.RemoteAddr(), atomic.LoadInt32(&connCounter))
...
...
@@ -186,6 +191,7 @@ func handleConn(conn net.Conn, arg Args) {
}()
}
defer atomic.AddInt32(&connCounter, -1)
*/
defer
conn
.
Close
()
// socks5 server supported methods
...
...
@@ -329,6 +335,10 @@ func forwardChain(chain ...Args) (conn net.Conn, end Args, err error) {
if
conn
,
err
=
net
.
DialTimeout
(
"tcp"
,
end
.
Addr
,
time
.
Second
*
90
);
err
!=
nil
{
return
}
tc
:=
conn
.
(
*
net
.
TCPConn
)
tc
.
SetKeepAlive
(
true
)
tc
.
SetKeepAlivePeriod
(
time
.
Second
*
180
)
// 3min
c
,
err
:=
forward
(
conn
,
end
)
if
err
!=
nil
{
return
...
...
forward.go
View file @
f2de67f8
...
...
@@ -246,6 +246,7 @@ func connectRUdpForward(conn net.Conn, arg Args) error {
glog
.
V
(
LWARNING
)
.
Infof
(
"[rudp] %s -> %s : %s"
,
bindAddr
,
arg
.
Remote
,
err
)
return
}
glog
.
V
(
LDEBUG
)
.
Infof
(
"[rudp] %s <<< %s length: %d"
,
arg
.
Remote
,
bindAddr
,
len
(
dgram
.
Data
))
relay
.
SetReadDeadline
(
time
.
Now
()
.
Add
(
time
.
Second
*
60
))
n
,
err
:=
relay
.
Read
(
b
)
...
...
@@ -255,6 +256,8 @@ func connectRUdpForward(conn net.Conn, arg Args) error {
}
relay
.
SetReadDeadline
(
time
.
Time
{})
glog
.
V
(
LDEBUG
)
.
Infof
(
"[rudp] %s >>> %s length: %d"
,
arg
.
Remote
,
bindAddr
,
n
)
conn
.
SetWriteDeadline
(
time
.
Now
()
.
Add
(
time
.
Second
*
90
))
if
err
:=
gosocks5
.
NewUDPDatagram
(
gosocks5
.
NewUDPHeader
(
uint16
(
n
),
0
,
dgram
.
Header
.
Addr
),
b
[
:
n
])
.
Write
(
conn
);
err
!=
nil
{
glog
.
V
(
LWARNING
)
.
Infof
(
"[rudp] %s <- %s : %s"
,
bindAddr
,
arg
.
Remote
,
err
)
...
...
socks.go
View file @
f2de67f8
...
...
@@ -341,9 +341,13 @@ func socks5TunnelUDP(req *gosocks5.Request, conn net.Conn) error {
}
defer
uconn
.
Close
()
if
err
:=
gosocks5
.
NewReply
(
gosocks5
.
Succeeded
,
ToSocksAddr
(
uconn
.
LocalAddr
()))
.
Write
(
conn
);
err
!=
nil
{
addr
:=
ToSocksAddr
(
uconn
.
LocalAddr
())
addr
.
Host
,
_
,
_
=
net
.
SplitHostPort
(
conn
.
LocalAddr
()
.
String
())
rep
:=
gosocks5
.
NewReply
(
gosocks5
.
Succeeded
,
addr
)
if
err
:=
rep
.
Write
(
conn
);
err
!=
nil
{
return
nil
}
glog
.
V
(
LDEBUG
)
.
Infof
(
"[socks5-udp] %s <- %s
\n
%s"
,
conn
.
RemoteAddr
(),
uconn
.
LocalAddr
(),
rep
)
glog
.
V
(
LINFO
)
.
Infof
(
"[socks5-udp] %s <-> %s"
,
conn
.
RemoteAddr
(),
uconn
.
LocalAddr
())
tunnelUDP
(
uconn
,
conn
,
false
)
...
...
ss.go
View file @
f2de67f8
...
...
@@ -11,12 +11,14 @@ import (
)
func
handleShadow
(
conn
net
.
Conn
,
arg
Args
)
{
glog
.
V
(
LINFO
)
.
Infof
(
"[ss] %s -> %s"
,
conn
.
RemoteAddr
(),
conn
.
LocalAddr
())
if
arg
.
User
!=
nil
{
method
:=
arg
.
User
.
Username
()
password
,
_
:=
arg
.
User
.
Password
()
cipher
,
err
:=
shadowsocks
.
NewCipher
(
method
,
password
)
if
err
!=
nil
{
glog
.
V
(
LWARNING
)
.
Info
ln
(
"shadowsocks:"
,
err
)
glog
.
V
(
LWARNING
)
.
Info
f
(
"[ss] %s - %s : %s"
,
conn
.
RemoteAddr
(),
conn
.
LocalAddr
()
,
err
)
return
}
conn
=
shadowsocks
.
NewConn
(
conn
,
cipher
)
...
...
@@ -24,26 +26,28 @@ func handleShadow(conn net.Conn, arg Args) {
addr
,
extra
,
err
:=
getShadowRequest
(
conn
)
if
err
!=
nil
{
glog
.
V
(
LWARNING
)
.
Info
ln
(
"shadowsocks:"
,
err
)
glog
.
V
(
LWARNING
)
.
Info
f
(
"[ss] %s - %s : %s"
,
conn
.
RemoteAddr
(),
conn
.
LocalAddr
()
,
err
)
return
}
glog
.
V
(
LINFO
)
.
Info
ln
(
"shadowsocks connect:"
,
addr
.
String
())
glog
.
V
(
LINFO
)
.
Info
f
(
"[ss] %s -> %s"
,
conn
.
RemoteAddr
()
,
addr
.
String
())
sconn
,
err
:=
Connect
(
addr
.
String
())
if
err
!=
nil
{
glog
.
V
(
LWARNING
)
.
Info
ln
(
"shadowsocks:"
,
err
)
glog
.
V
(
LWARNING
)
.
Info
f
(
"[ss] %s -> %s : %s"
,
conn
.
RemoteAddr
(),
addr
.
String
()
,
err
)
return
}
defer
sconn
.
Close
()
if
extra
!=
nil
{
if
_
,
err
:=
sconn
.
Write
(
extra
);
err
!=
nil
{
glog
.
V
(
LWARNING
)
.
Info
ln
(
"shadowsocks:"
,
err
)
glog
.
V
(
LWARNING
)
.
Info
f
(
"[ss] %s - %s : %s"
,
conn
.
RemoteAddr
(),
addr
.
String
()
,
err
)
return
}
}
glog
.
V
(
LINFO
)
.
Infof
(
"[ss] %s <-> %s"
,
conn
.
RemoteAddr
(),
addr
.
String
())
Transport
(
conn
,
sconn
)
glog
.
V
(
LINFO
)
.
Infof
(
"[ss] %s >-< %s"
,
conn
.
RemoteAddr
(),
addr
.
String
())
}
func
getShadowRequest
(
conn
net
.
Conn
)
(
addr
*
gosocks5
.
Addr
,
extra
[]
byte
,
err
error
)
{
...
...
ws.go
View file @
f2de67f8
...
...
@@ -112,13 +112,13 @@ func NewWs(arg Args) *ws {
}
func
(
s
*
ws
)
handle
(
w
http
.
ResponseWriter
,
r
*
http
.
Request
)
{
glog
.
V
(
LINFO
)
.
Info
ln
(
"[ws] %s - %s"
,
r
.
RemoteAddr
,
s
.
arg
.
Addr
)
glog
.
V
(
LINFO
)
.
Info
f
(
"[ws] %s - %s"
,
r
.
RemoteAddr
,
s
.
arg
.
Addr
)
if
glog
.
V
(
LDEBUG
)
{
dump
,
err
:=
httputil
.
DumpRequest
(
r
,
false
)
if
err
!=
nil
{
glog
.
V
(
LWARNING
)
.
Info
ln
(
"[ws] %s - %s : %s"
,
r
.
RemoteAddr
,
s
.
arg
.
Addr
,
err
)
glog
.
V
(
LWARNING
)
.
Info
f
(
"[ws] %s - %s : %s"
,
r
.
RemoteAddr
,
s
.
arg
.
Addr
,
err
)
}
else
{
glog
.
V
(
LDEBUG
)
.
Info
ln
(
"[ws] %s - %s
\n
%s"
,
r
.
RemoteAddr
,
s
.
arg
.
Addr
,
string
(
dump
))
glog
.
V
(
LDEBUG
)
.
Info
f
(
"[ws] %s - %s
\n
%s"
,
r
.
RemoteAddr
,
s
.
arg
.
Addr
,
string
(
dump
))
}
}
conn
,
err
:=
s
.
upgrader
.
Upgrade
(
w
,
r
,
nil
)
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment