Project X Channel
纯扯淡 现在就是拉不下脸了
同之前提过的“
正在开始写一篇文章简评一下,偏技术吧,又是被动写文章这一天天的
Telegram
Project X Channel
这几天很焦虑,原因是真的有太多内容想转发了,但是根本转发不完,不转发又难受,tg 频道又没有分组,所以只主要转发下自己的调侃吧
转发那么多还是不如真正做实事,搞完 XDRIVE 我就着手弄 Xray-core 的官方客户端,iOS 上更严的限制也会反哺 Xray-core 的整体性能优化
对客户端而言 UI 肯定是第一位的,功能上 Xray-core 也有 Surge 用户最喜欢吹的“内网穿透”和“透明代理”,主要是一问 Surge 有啥独有的特性就是 Ponte 和“网关模式”,似乎就只有这俩撑起了几十刀和订阅制,唉韭菜,至于…
转发那么多还是不如真正做实事,搞完 XDRIVE 我就着手弄 Xray-core 的官方客户端,iOS 上更严的限制也会反哺 Xray-core 的整体性能优化
对客户端而言 UI 肯定是第一位的,功能上 Xray-core 也有 Surge 用户最喜欢吹的“内网穿透”和“透明代理”,主要是一问 Surge 有啥独有的特性就是 Ponte 和“网关模式”,似乎就只有这俩撑起了几十刀和订阅制,唉韭菜,至于…
😁36👀7👍4❤2
Forwarded from GitHub
💬 New comment on Xray-core#5944 iOS high memory usage/memory leak
by @RPRX
> @Fangliding I ask you, please do not abandon poor iOS users. I really hope this information will help identify the cause of the leak specifically due to UDP
~~啥叫 poor iOS users??288 刀的 iOS 家人们必须是第一位的~~
Reply to this message to post a comment on GitHub.
by @RPRX
> @Fangliding I ask you, please do not abandon poor iOS users. I really hope this information will help identify the cause of the leak specifically due to UDP
~~啥叫 poor iOS users??288 刀的 iOS 家人们必须是第一位的~~
Reply to this message to post a comment on GitHub.
😁38⚡4🔥2❤1
Forwarded from GitHub
💬 New comment on BBS#24 关于机场以及DNS,最近的个人观察
by @RPRX
https://t.me/projectXtls/1996
> 相比于“封端”,机场最稳的选择其实是 XHTTP+CDN+ECH,就算被 GFW 拉到了订阅,不能封 IP 也不能 SNI 阻断,除非封了 ECH SNI
机场也确实正在涌入 XHTTP,要不要把 XHTTP/2+TLS 的默认模式改回 stream-up,~~给 CF 减点压力~~
Reply to this message to post a comment on GitHub.
by @RPRX
https://t.me/projectXtls/1996
> 相比于“封端”,机场最稳的选择其实是 XHTTP+CDN+ECH,就算被 GFW 拉到了订阅,不能封 IP 也不能 SNI 阻断,除非封了 ECH SNI
机场也确实正在涌入 XHTTP,要不要把 XHTTP/2+TLS 的默认模式改回 stream-up,~~给 CF 减点压力~~
Reply to this message to post a comment on GitHub.
😁36❤4🔥4
Forwarded from GitHub
💬 New comment on Xray-core#5920 Finalmask header-custom: add programmable handshake templates and runtime core
by @RPRX
这部分目前我用不到,也不太想烧脑细胞来确定怎么设计才是“最优”,所以我的态度类似对于 XHTTP 那些新参数,谁行谁上
具体而言,谁用谁设计,只要不影响到已有功能就行,我会合并,文档请自行 PR,未来若需要 breaking 也可以接受
算是实现了半个“完全可编程协议”的饼,也避免了用户自行搞出不够安全的加密,从这个角度来说这种方式更好
不过这只是 header-custom,还需要一个可编程 transport,或者也放 finalmask 里然后加个 [pre](https://github.com/XTLS/Xray-core/pull/5850#issuecomment-4154647029)(生效在 tls/reality 内部)
---
@patterniha 最近在整些新活导致 Project X 伊朗群 Project XHTTP 这两天涌入了上万人,那些花活想加的话也可以 PR
Reply to this message to post a comment on GitHub.
by @RPRX
这部分目前我用不到,也不太想烧脑细胞来确定怎么设计才是“最优”,所以我的态度类似对于 XHTTP 那些新参数,谁行谁上
具体而言,谁用谁设计,只要不影响到已有功能就行,我会合并,文档请自行 PR,未来若需要 breaking 也可以接受
算是实现了半个“完全可编程协议”的饼,也避免了用户自行搞出不够安全的加密,从这个角度来说这种方式更好
不过这只是 header-custom,还需要一个可编程 transport,或者也放 finalmask 里然后加个 [pre](https://github.com/XTLS/Xray-core/pull/5850#issuecomment-4154647029)(生效在 tls/reality 内部)
---
@patterniha 最近在整些新活导致 Project X 伊朗群 Project XHTTP 这两天涌入了上万人,那些花活想加的话也可以 PR
Reply to this message to post a comment on GitHub.
👍20🔥4
Forwarded from GitHub
💬 New comment on Xray-core#5887 TUN inbound: Add `gateway`, `dns`, `autoSystemRoutingTable`, `autoOutboundsInterface` for Windows
by @RPRX
~~我觉得用 TUN 时建议加这个路由挺好的,万一以后加其它东西又整回环了,这算是个万能兜底,文档中确实得提醒下~~
Xray-core 的文档的话建议加 "/self" 吧,~~有的人可能就爱开俩进程然后整些进程 2 进一步处理进程 1 的流量的花活~~
Reply to this message to post a comment on GitHub.
by @RPRX
~~我觉得用 TUN 时建议加这个路由挺好的,万一以后加其它东西又整回环了,这算是个万能兜底,文档中确实得提醒下~~
Xray-core 的文档的话建议加 "/self" 吧,~~有的人可能就爱开俩进程然后整些进程 2 进一步处理进程 1 的流量的花活~~
Reply to this message to post a comment on GitHub.
👍17⚡3🔥2
Forwarded from GitHub
💬 New comment on BBS#13 ECH先遣服:搭建修改HTTPS记录的DoH服务,强制为Cloudflare CDN与Meta CDN开启ECH功能
by @RememberOurPromise
XChat是否会加入Cloudflare ECH套餐?
Reply to this message to post a comment on GitHub.
by @RememberOurPromise
XChat是否会加入Cloudflare ECH套餐?
https://chat.x.com/cdn-cgi/tracefl=
h=chat.x.com
ip=104.28.
ts=
visit_scheme=https
uag=
colo=
sliver=none
http=http/2
loc=
tls=TLSv1.3
sni=encrypted
warp=plus
gateway=off
rbi=off
kex=X25519MLKEM768
Reply to this message to post a comment on GitHub.
😁21👀4❤2
Forwarded from 我不是大HE神的正义大佬sukka
这色鸡到底是怎么做到让用户心甘情愿做猪仔被人卖了还帮人家数钱的
R主席得好好学习学习研究研究
R主席得好好学习学习研究研究
😁39👀3
Forwarded from Solidot
俄罗斯流行应用被发现会检测是否安装 VPN
2026-04-15 21:43 by 十二魔
RKS Global 的专家发现,30 款俄罗斯最流行 Android 应用有 22 款能检测 VPN,其中 19 款会将 VPN 状态发送至服务器。这些应用包括:Yandex Browser、Yandex Maps、VKontakte、My MTS、Sberbank Online、T-Bank、VK Video、Wildberries、 Kinopoisk、Ozon、Samokat、RuStore、VTB Online、Yandex Music、Avito、Alfa-Bank、2GIS、MegaMarket、Odnoklassniki、MAX、Rutube 和 VK Music。俄罗斯数字发展部已经要求大型企业从 4 月 15 日起限制那些在设备上启用了 VPN 的用户的访问。调查发现,Avito 应用会检测设备上是否安装了逾 200 种外国应用,其中包括银行、加密货币钱包和 IM 等。
https://files.rks.global/russian_apps_search_for_vpn_en.pdf
#审查
2026-04-15 21:43 by 十二魔
RKS Global 的专家发现,30 款俄罗斯最流行 Android 应用有 22 款能检测 VPN,其中 19 款会将 VPN 状态发送至服务器。这些应用包括:Yandex Browser、Yandex Maps、VKontakte、My MTS、Sberbank Online、T-Bank、VK Video、Wildberries、 Kinopoisk、Ozon、Samokat、RuStore、VTB Online、Yandex Music、Avito、Alfa-Bank、2GIS、MegaMarket、Odnoklassniki、MAX、Rutube 和 VK Music。俄罗斯数字发展部已经要求大型企业从 4 月 15 日起限制那些在设备上启用了 VPN 的用户的访问。调查发现,Avito 应用会检测设备上是否安装了逾 200 种外国应用,其中包括银行、加密货币钱包和 IM 等。
https://files.rks.global/russian_apps_search_for_vpn_en.pdf
#审查
⚡31😁24
Forwarded from Lucas Kate
R佬早就说了类似网传美团这种利用“网络beacon”的钓IP方式,几乎是可以通杀所有分流代理的无解方式(但是你不可能用外网登国内账号吧?),唯一比较好的应对方法是分应用
👍34❤5
Forwarded from ちおれい
伊朗政府现在白名单某些 Cloudflare 网站的 SNI 只要发送白名单 SNI 到 TTL 刚好到达 DPI 但在到达 Cloudflare 之前到期然后再以相同 TCP 序列发送正确的 SNI 给 Cloudflare 就能过去
👍46😁16
Forwarded from GitHub
💬 New comment on Xray-core#5892 xhttp h2c
by @RPRX
> IPIfNonMatch
~~这样的话确实能防一下,如果这里的解析遵从系统 hosts 的话~~
我的意思是 Xray-core 应该提供一个默认的防护,我感觉很多人根本没设置 block private 啊,比如 VLESS 入、freedom 出就可以认定是服务端了,默认在出站 block private,加个选项主要是给内网穿透的内网端用的,@Meo597 有兴趣实现不
Reply to this message to post a comment on GitHub.
by @RPRX
> IPIfNonMatch
~~这样的话确实能防一下,如果这里的解析遵从系统 hosts 的话~~
我的意思是 Xray-core 应该提供一个默认的防护,我感觉很多人根本没设置 block private 啊,比如 VLESS 入、freedom 出就可以认定是服务端了,默认在出站 block private,加个选项主要是给内网穿透的内网端用的,@Meo597 有兴趣实现不
Reply to this message to post a comment on GitHub.
👍15⚡5🔥4
Forwarded from RAJA ATAEV|DEUS EX MACHINA
plus it seems like the internal user-agent is now being taken into account as well
😁12👀4
Project X Channel
Photo
如果 CF 彻底封掉 WebSocket 的话那 XHTTP 还是赢了,毕竟后者只基于 GET、POST,且可以有很多变体根本封不完,比如年初 XHTTP 就新增了一堆参数,可以改掉 x_padding 等默认特征
GitHub
XHTTP transport: New options for bypassing CDN's potential detection by paqx · Pull Request #5414 · XTLS/Xray-core
Hi!
As you might know, there are currently white lists for mobile internet in many regions of Russia. It's hard set up an xray server to bypass the restriction because you need either a whi...
As you might know, there are currently white lists for mobile internet in many regions of Russia. It's hard set up an xray server to bypass the restriction because you need either a whi...
😁74👀7❤3👍3
Forwarded from GitHub
💬 New comment on Xray-core#5947 Direct/Freedom outbound: Add `ipsBlocked` (supports IP, CIDR, "geoip:", "ext:") and apply a default safe policy
by @Meo597
> 重新在freedom做一套路由。。
最多算个 acl 吧
xray-enterprise 这不就来了吗
这波福利给到家人们,原价 $0
surge 存量用户凭订单只要 $288
Reply to this message to post a comment on GitHub.
by @Meo597
> 重新在freedom做一套路由。。
最多算个 acl 吧
xray-enterprise 这不就来了吗
这波福利给到家人们,原价 $0
surge 存量用户凭订单只要 $288
Reply to this message to post a comment on GitHub.
😁41🔥2
Forwarded from GitHub
💬 New comment on Xray-core#5947 Direct/Freedom outbound: Add `ipsBlocked` (supports IP, CIDR, "geoip:", "ext:") and apply a default safe policy
by @RPRX
总之这个 PR 所实现的 TCP 只看 dial 后的 remoteAddr,以及 UDP 逐包匹配确实封得更彻底,没有死角了
再做绝些就是把 UDP 回包也过滤一下,来自那些地址的话就 drop 掉,@Meo597 PR 一下吧
~~要论割韭菜那确实还得是 Surge,一个无关紧要的新功能让韭菜们续订一年,Xray 一个月都能更新它一年的量还多~~
Reply to this message to post a comment on GitHub.
by @RPRX
总之这个 PR 所实现的 TCP 只看 dial 后的 remoteAddr,以及 UDP 逐包匹配确实封得更彻底,没有死角了
再做绝些就是把 UDP 回包也过滤一下,来自那些地址的话就 drop 掉,@Meo597 PR 一下吧
~~要论割韭菜那确实还得是 Surge,一个无关紧要的新功能让韭菜们续订一年,Xray 一个月都能更新它一年的量还多~~
Reply to this message to post a comment on GitHub.
😁24❤1
Forwarded from GitHub
💬 New comment on Xray-core#5947 Direct/Freedom outbound: Add `ipsBlocked` (supports IP, CIDR, "geoip:", "ext:") and apply a default safe policy
by @RPRX
怎么说呢,从~~哲学~~的角度是彻底杜绝与这些 ipsBlocked 地址的 任何 有效数据传输,~~这下真变成哲学问题了~~
Reply to this message to post a comment on GitHub.
by @RPRX
怎么说呢,从~~哲学~~的角度是彻底杜绝与这些 ipsBlocked 地址的 任何 有效数据传输,~~这下真变成哲学问题了~~
Reply to this message to post a comment on GitHub.
🔥14😁6
Forwarded from GitHub
💬 New comment on Xray-core#5907 Proxy: Add AnyTLS protocol
by @RPRX
> 现在anytls是最稳的协议了,为什么不支持呢
~~忘说了,先是重新定义“最稳”~~
其次 AnyTLS 这类纯 padding TLV 无黑魔法协议,你让 Xray 的任何高频贡献者写都能一天给你写一个不同的,唉 end user
历史事实 https://github.com/XTLS/Xray-core/issues/5089#issuecomment-3258885791 与锐评 https://t.me/projectXtls/1164
~~不聊了这个月内 release XDRIVE,别等下 XDRIVE 也被偷家了,end user 太多不看 Xray roadmap 只认谁先 release,难绷~~
Reply to this message to post a comment on GitHub.
by @RPRX
> 现在anytls是最稳的协议了,为什么不支持呢
~~忘说了,先是重新定义“最稳”~~
其次 AnyTLS 这类纯 padding TLV 无黑魔法协议,你让 Xray 的任何高频贡献者写都能一天给你写一个不同的,唉 end user
历史事实 https://github.com/XTLS/Xray-core/issues/5089#issuecomment-3258885791 与锐评 https://t.me/projectXtls/1164
~~不聊了这个月内 release XDRIVE,别等下 XDRIVE 也被偷家了,end user 太多不看 Xray roadmap 只认谁先 release,难绷~~
Reply to this message to post a comment on GitHub.
❤25😁9👍2