Forwarded from GitHub
🐛 New issue BBS#25 重拳出击XHTTP!科福瑞的忠实用户应该如何应对?
by @RememberOurPromise
近期,不少科福瑞的忠实用户收到了亲切的邮件问候
例如这样:
https://github.com/XTLS/Xray-core/issues/5967
### Logs or other evidence of abuse: WebSocket tunneling abuse - Xray/V2Ray x_padding pattern with Go-http client
<img width="1902" height="1158" alt="Image" src="https://github.com/user-attachments/assets/dfa3f3d4-aa8e-426d-93ac-796957e3007d" />
---
不过呢,赛博大善人真滴太善了,答案居然写在试卷上!
1. 首先升级服务端和客户端 Xray-core 到最新版本
User-Agent问题就解决了
2. 改个配置
俄友在面对俄罗斯CDN时已经考虑了x_padding等特征,可以参考这个PR
https://github.com/XTLS/Xray-core/pull/5414#issuecomment-3770071786
服务端
客户端
### 让我们继续做科福瑞的忠实用户吧!
~不过这可以证明在世界顶级网络公司眼中~
~Xray 排在 V2Ray 前面~
~s***-b** 和 m***** 根本不入法眼~
~又赢了~
Reply to this message to post a comment on GitHub.
by @RememberOurPromise
近期,不少科福瑞的忠实用户收到了亲切的邮件问候
例如这样:
https://github.com/XTLS/Xray-core/issues/5967
### Logs or other evidence of abuse: WebSocket tunneling abuse - Xray/V2Ray x_padding pattern with Go-http client
<img width="1902" height="1158" alt="Image" src="https://github.com/user-attachments/assets/dfa3f3d4-aa8e-426d-93ac-796957e3007d" />
---
不过呢,赛博大善人真滴太善了,答案居然写在试卷上!
1. 首先升级服务端和客户端 Xray-core 到最新版本
User-Agent问题就解决了
2. 改个配置
俄友在面对俄罗斯CDN时已经考虑了x_padding等特征,可以参考这个PR
https://github.com/XTLS/Xray-core/pull/5414#issuecomment-3770071786
服务端
{
"xhttpSettings": {
"host": "example.com",
"path": "/path",
"mode": "auto",
"xPaddingObfsMode": true, //填 true
"xPaddingMethod": "tokenish", //填 tokenish
"xPaddingPlacement": "queryInHeader", //可选 queryInHeader, cookie, header, query
"xPaddingHeader": "X-Cache", //xPaddingPlacement 为 header 或 queryInHeader 时才保留此行,填写合理的字符串
"xPaddingKey": "_dc" //根据上面的选择,填写合理的字符串
}
}
客户端
{
"xhttpSettings": {
"host": "example.com",
"path": "/path",
"mode": "auto",
"extra": { //保持与服务端一致,放extra里
"xPaddingObfsMode": true,
"xPaddingMethod": "tokenish",
"xPaddingPlacement": "queryInHeader",
"xPaddingHeader": "X-Cache",
"xPaddingKey": "_dc"
}
}
}
### 让我们继续做科福瑞的忠实用户吧!
~不过这可以证明在世界顶级网络公司眼中~
~Xray 排在 V2Ray 前面~
~s***-b** 和 m***** 根本不入法眼~
~又赢了~
Reply to this message to post a comment on GitHub.
😁71❤6👍5
Project X
https://github.com/MetaCubeX/mihomo/commit/2337d70d86fa15efe7b69ee54bff6139ebfabcf6#diff-f545caafd993e4b1ab84b7b49d9671a282237f9a869f74456be42f2855820362R89
😁36⚡4👍2👀2
Forwarded from GitHub
💬 New comment on BBS#25 重拳出击XHTTP!科福瑞的忠实用户应该如何应对?
by @UjuiUjuMandan
第三方向 Cloudflare 发送了滥用举报,Cloudflare 只是转发了该举报。那么究竟是谁举报的?举报内容是什么?请澄清一下。
Reply to this message to post a comment on GitHub.
by @UjuiUjuMandan
第三方向 Cloudflare 发送了滥用举报,Cloudflare 只是转发了该举报。那么究竟是谁举报的?举报内容是什么?请澄清一下。
Reply to this message to post a comment on GitHub.
👍4
Forwarded from 世界突然安静了
surge不支持vless??能提建议加vless功能么。我这边机场改用vless协议了
😁23👍2
Forwarded from GitHub
💬 New comment on BBS#25 重拳出击XHTTP!科福瑞的忠实用户应该如何应对?
by @jon460243
@UjuiUjuMandan 可能是邮件模板吧,或者内部审查机器人发起
续上图的完整邮件,另外我还有io域名com域名目前正常work,这个是xyz,难道xyz被认为低价值?
<img width="939" height="672" alt="Image" src="https://github.com/user-attachments/assets/2189a35d-19dd-42fa-9134-7e007c83d445" />
Reply to this message to post a comment on GitHub.
by @jon460243
@UjuiUjuMandan 可能是邮件模板吧,或者内部审查机器人发起
续上图的完整邮件,另外我还有io域名com域名目前正常work,这个是xyz,难道xyz被认为低价值?
<img width="939" height="672" alt="Image" src="https://github.com/user-attachments/assets/2189a35d-19dd-42fa-9134-7e007c83d445" />
Reply to this message to post a comment on GitHub.
❤5
Forwarded from GitHub
💬 New comment on BBS#25 重拳出击XHTTP!科福瑞的忠实用户应该如何应对?
by @RememberOurPromise
看来举报信件是有域名的,那么你开启了ECH吗?
Reply to this message to post a comment on GitHub.
by @RememberOurPromise
看来举报信件是有域名的,那么你开启了ECH吗?
Reply to this message to post a comment on GitHub.
Forwarded from GitHub
💬 New comment on BBS#25 重拳出击XHTTP!科福瑞的忠实用户应该如何应对?
by @jon460243
> 看来举报信件是有域名的,那么你开启了ECH吗?
没有
Reply to this message to post a comment on GitHub.
by @jon460243
> 看来举报信件是有域名的,那么你开启了ECH吗?
没有
Reply to this message to post a comment on GitHub.
Forwarded from GitHub
💬 New comment on BBS#25 重拳出击XHTTP!科福瑞的忠实用户应该如何应对?
by @RememberOurPromise
emmm 这么说也不能完全排除GFW在批量举报的可能..
Reply to this message to post a comment on GitHub.
by @RememberOurPromise
emmm 这么说也不能完全排除GFW在批量举报的可能..
Reply to this message to post a comment on GitHub.
Forwarded from GitHub
💬 New comment on BBS#25 重拳出击XHTTP!科福瑞的忠实用户应该如何应对?
by @RememberOurPromise
如果这是GFW批量举报,填个狗屁不通的通用理由就比较扯了,这次只是正好中枪
先不管谁开枪的,把靶子移走就行了,开启ECH,改一下padding就好
~虚假的滥用:跑个XHTTP~
~真正的滥用:批量发送Abuse Report~
Reply to this message to post a comment on GitHub.
by @RememberOurPromise
如果这是GFW批量举报,填个狗屁不通的通用理由就比较扯了,这次只是正好中枪
先不管谁开枪的,把靶子移走就行了,开启ECH,改一下padding就好
~虚假的滥用:跑个XHTTP~
~真正的滥用:批量发送Abuse Report~
Reply to this message to post a comment on GitHub.
😁4
Forwarded from acdd1e
Project X Channel
另外有点奇怪的是,Cloudflare 把 Abuse Report API 的文档删除了。
Abuse Report API 被 Abuse 了🤣
😁17⚡4
Forwarded from GitHub
💬 New comment on BBS#25 重拳出击XHTTP!科福瑞的忠实用户应该如何应对?
by @RememberOurPromise
群友发现API文档中[Abuse Reports](https://developers.cloudflare.com/api/resources/abuse_reports/)被下架了
GFW现在完全没招只能当举报狗了?
XDRIVE 还没吃上 api.cloudflare.com,怎么GFW就先给滥用完了,太坏了😠
Reply to this message to post a comment on GitHub.
by @RememberOurPromise
群友发现API文档中[Abuse Reports](https://developers.cloudflare.com/api/resources/abuse_reports/)被下架了
GFW现在完全没招只能当举报狗了?
XDRIVE 还没吃上 api.cloudflare.com,怎么GFW就先给滥用完了,太坏了😠
Reply to this message to post a comment on GitHub.
⚡14❤1
Forwarded from GitHub
💬 New comment on BBS#25 重拳出击XHTTP!科福瑞的忠实用户应该如何应对?
by @RPRX
~~“举报狗”,咋这么喜感哈哈哈~~
Reply to this message to post a comment on GitHub.
by @RPRX
~~“举报狗”,咋这么喜感哈哈哈~~
Reply to this message to post a comment on GitHub.