Project X Channel
29.4K subscribers
200 photos
2 videos
6 files
1.02K links
Download Telegram
Forwarded from Ridar
转发给切图仔让他上报给GFW
😁371
Forwarded from GitHub
💬 New comment on Xray-core#5944 iOS high memory usage/memory leak
by @RPRX

> @Fangliding I ask you, please do not abandon poor iOS users. I really hope this information will help identify the cause of the leak specifically due to UDP

~~啥叫 poor iOS users??288 刀的 iOS 家人们必须是第一位的~~

Reply to this message to post a comment on GitHub.
😁384🔥21
Forwarded from GitHub
💬 New comment on BBS#24 关于机场以及DNS,最近的个人观察
by @RPRX

https://t.me/projectXtls/1996

> 相比于“封端”,机场最稳的选择其实是 XHTTP+CDN+ECH,就算被 GFW 拉到了订阅,不能封 IP 也不能 SNI 阻断,除非封了 ECH SNI

机场也确实正在涌入 XHTTP,要不要把 XHTTP/2+TLS 的默认模式改回 stream-up,~~给 CF 减点压力~~

Reply to this message to post a comment on GitHub.
😁364🔥4
Forwarded from GitHub
💬 New comment on Xray-core#5920 Finalmask header-custom: add programmable handshake templates and runtime core
by @RPRX

这部分目前我用不到,也不太想烧脑细胞来确定怎么设计才是“最优”,所以我的态度类似对于 XHTTP 那些新参数,谁行谁上

具体而言,谁用谁设计,只要不影响到已有功能就行,我会合并,文档请自行 PR,未来若需要 breaking 也可以接受

算是实现了半个“完全可编程协议”的饼,也避免了用户自行搞出不够安全的加密,从这个角度来说这种方式更好

不过这只是 header-custom,还需要一个可编程 transport,或者也放 finalmask 里然后加个 [pre](https://github.com/XTLS/Xray-core/pull/5850#issuecomment-4154647029)(生效在 tls/reality 内部)

---

@patterniha 最近在整些新活导致 Project X 伊朗群 Project XHTTP 这两天涌入了上万人,那些花活想加的话也可以 PR

Reply to this message to post a comment on GitHub.
👍20🔥4
Forwarded from GitHub
💬 New comment on Xray-core#5887 TUN inbound: Add `gateway`, `dns`, `autoSystemRoutingTable`, `autoOutboundsInterface` for Windows
by @RPRX

~~我觉得用 TUN 时建议加这个路由挺好的,万一以后加其它东西又整回环了,这算是个万能兜底,文档中确实得提醒下~~

Xray-core 的文档的话建议加 "/self" 吧,~~有的人可能就爱开俩进程然后整些进程 2 进一步处理进程 1 的流量的花活~~

Reply to this message to post a comment on GitHub.
👍173🔥2
Forwarded from GitHub
💬 New comment on BBS#13 ECH先遣服:搭建修改HTTPS记录的DoH服务,强制为Cloudflare CDN与Meta CDN开启ECH功能
by @RememberOurPromise

XChat是否会加入Cloudflare ECH套餐?

https://chat.x.com/cdn-cgi/trace

fl=
h=chat.x.com
ip=104.28.
ts=
visit_scheme=https
uag=
colo=
sliver=none
http=http/2
loc=
tls=TLSv1.3
sni=encrypted
warp=plus
gateway=off
rbi=off
kex=X25519MLKEM768


Reply to this message to post a comment on GitHub.
😁21👀42
Forwarded from 我不是大HE神的正义大佬sukka
这色鸡到底是怎么做到让用户心甘情愿做猪仔被人卖了还帮人家数钱的

R主席得好好学习学习研究研究
😁39👀3
Forwarded from Solidot
俄罗斯流行应用被发现会检测是否安装 VPN

2026-04-15 21:43 by 十二魔

RKS Global 的专家发现,30 款俄罗斯最流行 Android 应用有 22 款能检测 VPN,其中 19 款会将 VPN 状态发送至服务器。这些应用包括:Yandex Browser、Yandex Maps、VKontakte、My MTS、Sberbank Online、T-Bank、VK Video、Wildberries、 Kinopoisk、Ozon、Samokat、RuStore、VTB Online、Yandex Music、Avito、Alfa-Bank、2GIS、MegaMarket、Odnoklassniki、MAX、Rutube 和 VK Music。俄罗斯数字发展部已经要求大型企业从 4 月 15 日起限制那些在设备上启用了 VPN 的用户的访问。调查发现,Avito 应用会检测设备上是否安装了逾 200 种外国应用,其中包括银行、加密货币钱包和 IM 等。

https://files.rks.global/russian_apps_search_for_vpn_en.pdf

#审查
31😁24
Forwarded from Lucas Kate
R佬早就说了类似网传美团这种利用“网络beacon”的钓IP方式,几乎是可以通杀所有分流代理的无解方式(但是你不可能用外网登国内账号吧?),唯一比较好的应对方法是分应用
👍345
Forwarded from ちおれい
伊朗政府现在白名单某些 Cloudflare 网站的 SNI 只要发送白名单 SNI 到 TTL 刚好到达 DPI 但在到达 Cloudflare 之前到期然后再以相同 TCP 序列发送正确的 SNI 给 Cloudflare 就能过去
👍46😁16
Forwarded from GitHub
💬 New comment on Xray-core#5892 xhttp h2c
by @RPRX

> IPIfNonMatch

~~这样的话确实能防一下,如果这里的解析遵从系统 hosts 的话~~

我的意思是 Xray-core 应该提供一个默认的防护,我感觉很多人根本没设置 block private 啊,比如 VLESS 入、freedom 出就可以认定是服务端了,默认在出站 block private,加个选项主要是给内网穿透的内网端用的,@Meo597 有兴趣实现不

Reply to this message to post a comment on GitHub.
👍155🔥4
Forwarded from RAJA ATAEV|DEUS EX MACHINA
Well… it seems Cloudflare has started working and detecting based on 'VERY NON-SUSPICIOUS' indicators that 'definitely' don't belong exclusively to xray core
😁24👀5👍2
Forwarded from RAJA ATAEV|DEUS EX MACHINA
plus it seems like the internal user-agent is now being taken into account as well
😁12👀4
Forwarded from 
😁45🎉4
Project X Channel
Photo
Cloudflare 一天天的恨不得吃掉互联网上所有流量,感觉现在是为了配合 GFW 打击翻墙才开始搞这些,毕竟 XHTTP+ECH 确实挺让 GFW 难办的,Xray-core 上个月还把 WSS+ECH 改成了默认非 ALPN http/1.1,User-Agent 等 HTTP headers 默认也不再是 Go-http-client 了而是一套标准的 Chrome HTTP headers

如果 CF 彻底封掉 WebSocket 的话那 XHTTP 还是赢了,毕竟后者只基于 GET、POST,且可以有很多变体根本封不完,比如年初 XHTTP 就新增了一堆参数,可以改掉 x_padding 等默认特征
😁74👀73👍3
Forwarded from GitHub
💬 New comment on Xray-core#5947 Direct/Freedom outbound: Add `ipsBlocked` (supports IP, CIDR, "geoip:", "ext:") and apply a default safe policy
by @Meo597

> 重新在freedom做一套路由。。

最多算个 acl 吧

xray-enterprise 这不就来了吗
这波福利给到家人们,原价 $0
surge 存量用户凭订单只要 $288

Reply to this message to post a comment on GitHub.
😁41🔥2
Forwarded from GitHub
💬 New comment on Xray-core#5947 Direct/Freedom outbound: Add `ipsBlocked` (supports IP, CIDR, "geoip:", "ext:") and apply a default safe policy
by @RPRX

总之这个 PR 所实现的 TCP 只看 dial 后的 remoteAddr,以及 UDP 逐包匹配确实封得更彻底,没有死角了

再做绝些就是把 UDP 回包也过滤一下,来自那些地址的话就 drop 掉,@Meo597 PR 一下吧

~~要论割韭菜那确实还得是 Surge,一个无关紧要的新功能让韭菜们续订一年,Xray 一个月都能更新它一年的量还多~~

Reply to this message to post a comment on GitHub.
😁241
Forwarded from GitHub
💬 New comment on Xray-core#5947 Direct/Freedom outbound: Add `ipsBlocked` (supports IP, CIDR, "geoip:", "ext:") and apply a default safe policy
by @RPRX

怎么说呢,从~~哲学~~的角度是彻底杜绝与这些 ipsBlocked 地址的 任何 有效数据传输,~~这下真变成哲学问题了~~

Reply to this message to post a comment on GitHub.
🔥14😁6
Forwarded from GitHub
💬 New comment on Xray-core#5907 Proxy: Add AnyTLS protocol
by @RPRX

> 现在anytls是最稳的协议了,为什么不支持呢

~~忘说了,先是重新定义“最稳”~~

其次 AnyTLS 这类纯 padding TLV 无黑魔法协议,你让 Xray 的任何高频贡献者写都能一天给你写一个不同的,唉 end user

历史事实 https://github.com/XTLS/Xray-core/issues/5089#issuecomment-3258885791 与锐评 https://t.me/projectXtls/1164

~~不聊了这个月内 release XDRIVE,别等下 XDRIVE 也被偷家了,end user 太多不看 Xray roadmap 只认谁先 release,难绷~~

Reply to this message to post a comment on GitHub.
25😁9👍2