diff --git a/test/autoXRAYselfTLS2.sh b/test/autoXRAYselfTLS2.sh new file mode 100644 index 0000000..1091445 --- /dev/null +++ b/test/autoXRAYselfTLS2.sh @@ -0,0 +1,669 @@ +#!/bin/bash + +DOMAIN=$1 + +if [ -z "$DOMAIN" ]; then + echo "❌ Ошибка: домен не задан." + exit 1 +fi + +echo "Обновление и установка необходимых пакетов..." +apt update && apt install -y jq dnsutils + + +LOCAL_IP=$(hostname -I | awk '{print $1}') +DNS_IP=$(dig +short "$DOMAIN" | grep '^[0-9]') + +if [ "$LOCAL_IP" != "$DNS_IP" ]; then + echo "❌ Внимание: IP-адрес ($LOCAL_IP) не совпадает с A-записью $DOMAIN ($DNS_IP)." + echo "Правильно укажите одну A-запись для вашего домена в ДНС - $LOCAL_IP" + + read -p "Продолжить на ваш страх и риск? (y/N): " choice + if [[ ! "$choice" =~ ^[Yy]$ ]]; then + echo "Выполнение скрипта прервано." + exit 1 + fi + echo "Продолжение выполнения скрипта..." +fi + + +apt install nginx -y + +systemctl enable --now nginx + +apt install certbot -y + +mkdir -p /var/lib/xray/cert/ + +### Проверить +cp /etc/letsencrypt/live/$DOMAIN/fullchain.pem /var/lib/xray/cert/fullchain.pem +cp /etc/letsencrypt/live/$DOMAIN/privkey.pem /var/lib/xray/cert/privkey.pem +chmod 744 /var/lib/xray/cert/privkey.pem +chmod 744 /var/lib/xray/cert/fullchain.pem + +certbot certonly --webroot -w /var/www/html -d $DOMAIN -m mail@$DOMAIN --agree-tos --non-interactive --deploy-hook "systemctl reload nginx; cp /etc/letsencrypt/live/$DOMAIN/fullchain.pem /var/lib/xray/cert/fullchain.pem; cp /etc/letsencrypt/live/$DOMAIN/privkey.pem /var/lib/xray/cert/privkey.pem; chmod 744 /var/lib/xray/cert/privkey.pem; chmod 744 /var/lib/xray/cert/fullchain.pem; systemctl restart xray" + +CONFIG_PATH="/etc/nginx/sites-available/default" + +path_xhttp=$(openssl rand -base64 15 | tr -dc 'a-z0-9' | head -c 6) + +echo "✅ Записываем конфигурацию в $CONFIG_PATH для домена $DOMAIN" + +bash -c "cat > $CONFIG_PATH" < "$WEB_PATH/index.html" < + + + + + $TITLE + + + + + +
+

$HEADER

+
+
+ + +
+
+ + +
+ +
+
+ + +EOF + + + +# Установка Xray +bash -c "$(curl -L https://github.com/XTLS/Xray-install/raw/main/install-release.sh)" @ install + + +# Определяем директорию скрипта +#SCRIPT_DIR=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" &> /dev/null && pwd) +SCRIPT_DIR=/usr/local/etc/xray + +# Генерируем переменные +xray_uuid_vrv=$(xray uuid) + +key_output=$(xray x25519) +xray_privateKey_vrv=$(echo "$key_output" | awk -F': ' '/PrivateKey/ {print $2}') +xray_publicKey_vrv=$(echo "$key_output" | awk -F': ' '/Password/ {print $2}') + +key_mldsa65=$(xray mldsa65) +seed_mldsa65=$(echo "$key_mldsa65" | awk -F': ' '/Seed/ {print $2}') +verify_mldsa65=$(echo "$key_mldsa65" | awk -F': ' '/Verify/ {print $2}') + +xray_shortIds_vrv=$(openssl rand -hex 8) + +# xray_sspasw_vrv=$(openssl rand -base64 15 | tr -dc 'A-Za-z0-9' | head -c 20) +xray_sspasw_vrv=$(openssl rand -base64 32) + +path_subpage=$(openssl rand -base64 15 | tr -dc 'A-Za-z0-9' | head -c 20) + +socksUser=$(openssl rand -base64 20 | tr -dc 'A-Za-z0-9' | head -c 5) +socksPasw=$(openssl rand -base64 20 | tr -dc 'A-Za-z0-9' | head -c 10) + +# ipserv=$(hostname -I | awk '{print $1}') + + + +# Экспортируем переменные для envsubst +export xray_uuid_vrv xray_privateKey_vrv xray_publicKey_vrv xray_shortIds_vrv xray_sspasw_vrv DOMAIN path_subpage path_xhttp WEB_PATH socksUser socksPasw + +# Создаем JSON конфигурацию сервера +cat << 'EOF' | envsubst > "$SCRIPT_DIR/config.json" +{ + "log": { + "dnsLog": false, + "access": "/var/log/xray/access.log", + "error": "/var/log/xray/error.log", + "loglevel": "warning" + }, + "dns": { + "servers": [ + "https+local://8.8.4.4/dns-query", + "https+local://8.8.8.8/dns-query", + "https+local://1.1.1.1/dns-query", + "localhost" + ], + "queryStrategy": "UseIPv4" + }, + "inbounds": [ + { + "tag": "vsTCPxtls", + "port": 443, + "listen": "0.0.0.0", + "protocol": "vless", + "settings": { + "clients": [ + { + "flow": "xtls-rprx-vision", + "id": "${xray_uuid_vrv}" + } + ], + "decryption": "none", + "fallbacks": [ + { + "path": "/${path_xhttp}22", + "dest": "@vless-ws", + "xver": 2 + }, + { + "path": "/${path_xhttp}33", + "dest": "@vless-tcp", + "xver": 2 + }, + { + "dest": "/dev/shm/nginx.sock", + "xver": 2 + } + ] + }, + "streamSettings": { + "network": "raw", + "security": "tls", + "tlsSettings": { + "certificates": [ + { + "certificateFile": "/var/lib/xray/cert/fullchain.pem", + "keyFile": "/var/lib/xray/cert/privkey.pem" + } + ] + } + }, + "sniffing": { + "enabled": true, + "destOverride": [ + "http", + "tls", + "quic" + ] + } + }, + { + "tag": "vsXHTTPtls", + "port": 8400, + "listen": "127.0.0.1", + "protocol": "vless", + "settings": { + "clients": [ + { + "id": "${xray_uuid_vrv}" + } + ], + "decryption": "none" + }, + "streamSettings": { + "network": "xhttp", + "xhttpSettings": { + "mode": "auto", + "path": "/${path_xhttp}" + }, + "security": "none", + "sockopt": { + "acceptProxyProtocol": false + } + }, + "sniffing": { + "enabled": true, + "destOverride": [ + "http", + "tls", + "quic" + ] + } + }, + { + "tag": "vsGRPCtls", + "port": 8411, + "listen": "127.0.0.1", + "protocol": "vless", + "settings": { + "clients": [ + { + "id": "${xray_uuid_vrv}" + } + ], + "decryption": "none" + }, + "streamSettings": { + "network": "grpc", + "grpcSettings": { + "serviceName": "${path_xhttp}11" + }, + "security": "none" + }, + "sniffing": { + "enabled": true, + "destOverride": [ + "http", + "tls", + "quic" + ] + } + }, + { + "listen": "@vless-ws", + "protocol": "vless", + "settings": { + "clients": [ + { + "id": "${xray_uuid_vrv}" + } + ], + "decryption": "none" + }, + "streamSettings": { + "network": "ws", + "wsSettings": { + "acceptProxyProtocol": true, + "path": "/${path_xhttp}22" + }, + "security": "none" + }, + "sniffing": { + "enabled": true, + "destOverride": [ + "http", + "tls", + "quic" + ] + } + }, + { + "listen": "@vless-tcp", + "protocol": "vless", + "settings": { + "clients": [ + { + "id": "${xray_uuid_vrv}" + } + ], + "decryption": "none" + }, + "streamSettings": { + "network": "raw", + "security": "none", + "rawSettings": { + "acceptProxyProtocol": true, + "header": { + "type": "http", + "request": { + "path": [ + "/${path_xhttp}33" + ] + } + } + } + }, + "sniffing": { + "enabled": true, + "destOverride": [ + "http", + "tls", + "quic" + ] + } + }, + { + "tag": "ShadowSocks2022", + "port": 4443, + "listen": "0.0.0.0", + "protocol": "shadowsocks", + "settings": { + "method": "2022-blake3-aes-256-gcm", + "password": "${xray_sspasw_vrv}", + "network": "tcp,udp" + }, + "sniffing": { + "enabled": true, + "destOverride": [ + "http", + "tls", + "quic" + ] + } + }, + { + "tag": "socks5", + "port": 10443, + "listen": "0.0.0.0", + "protocol": "mixed", + "settings": { + "ip": "0.0.0.0", + "udp": true, + "auth": "password", + "accounts": [ + { + "user": "${socksUser}", + "pass": "${socksPasw}" + } + ] + } + } + ], + "outbounds": [ + { + "tag": "direct", + "protocol": "freedom", + "settings": { + "domainStrategy": "ForceIPv4" + } + }, + { + "tag": "block", + "protocol": "blackhole" + } + ], + "routing": { + "rules": [ + { + "ip": [ + "geoip:private" + ], + "outboundTag": "block" + }, + { + "protocol": [ + "bittorrent" + ], + "outboundTag": "block" + }, + { + "domain": [ + "geosite:category-ads", + "geosite:win-spy", + "geosite:private" + ], + "outboundTag": "block" + } + ], + "domainStrategy": "IPIfNonMatch" + } +} + +EOF + +# Создаем JSON конфигурацию клиента +print_config() { + local PROXY_OUTBOUND="$1" + local REMARK="$2" + + cat << TPL + { + "log": { + "loglevel": "warning" + }, + "dns": { + "servers": [ + "https://8.8.4.4/dns-query", + "https://8.8.8.8/dns-query", + "https://1.1.1.1/dns-query" + ], + "queryStrategy": "UseIPv4" + }, + "routing": { + "domainStrategy": "IPIfNonMatch", + "rules": [ + { "domain": ["geosite:category-ads", "geosite:win-spy"], "outboundTag": "block" }, + { "protocol": ["bittorrent"], "outboundTag": "direct" }, + { "domain": ["geosite:private", "geosite:apple", "geosite:google-play", "geosite:yandex", "geosite:vk", "geosite:category-ru"], "outboundTag": "direct" }, + { "ip": ["geoip:private"], "outboundTag": "direct" }, + { "type": "field", "ip": ["geoip:!ru"], "outboundTag": "proxy" }, + { "domain": ["geosite:discord", "geosite:youtube", "geosite:tiktok", "geosite:signal"], "outboundTag": "proxy" } + ] + }, + "inbounds": [ + { "tag": "socks-in", "protocol": "socks", "listen": "127.0.0.1", "port": 10808, "settings": { "udp": true } }, + { "tag": "socks-sb", "protocol": "socks", "listen": "127.0.0.1", "port": 2080, "settings": { "udp": true } }, + { "tag": "http-in", "protocol": "http", "listen": "127.0.0.1", "port": 10809 } + ], + "outbounds": [ + $PROXY_OUTBOUND, + { + "tag": "direct", + "protocol": "freedom" + }, + { + "tag": "block", + "protocol": "blackhole" + } + ], + "remarks": "$REMARK" + } +TPL +} + +# --- Config 1: VLESS TCP Reality --- +OUT_TCP_REALITY='{ + "mux": { "concurrency": -1, "enabled": false }, + "tag": "proxy", + "protocol": "vless", + "settings": { + "vnext": [{ + "address": "$DOMAIN", + "port": 443, + "users": [{ "id": "${xray_uuid_vrv}", "flow": "xtls-rprx-vision", "encryption": "none" }] + }] + }, + "streamSettings": { + "network": "raw", + "security": "reality", + "realitySettings": { + "show": false, "fingerprint": "chrome", "serverName": "$DOMAIN", + "password": "${xray_publicKey_vrv}", "shortId": "${xray_shortIds_vrv}", "spiderX": "/" + } + } +}' + +# --- Config 2: VLESS XHTTP Reality --- +OUT_XHTTP_REALITY='{ + "mux": { "concurrency": -1, "enabled": false }, + "tag": "proxy", + "protocol": "vless", + "settings": { + "vnext": [{ + "address": "$DOMAIN", + "port": 443, + "users": [{ "id": "${xray_uuid_vrv}", "encryption": "none" }] + }] + }, + "streamSettings": { + "network": "xhttp", + "xhttpSettings": { "mode": "auto", "path": "/${path_xhttp}" }, + "security": "reality", + "realitySettings": { + "show": false, "fingerprint": "chrome", "serverName": "$DOMAIN", + "password": "${xray_publicKey_vrv}", "shortId": "${xray_shortIds_vrv}", "spiderX": "/" + } + } +}' + +# --- Config 3: ShadowSocks 2022 --- +OUT_SHADOWSOCKS='{ + "mux": { "concurrency": -1, "enabled": false }, + "tag": "proxy", + "protocol": "shadowsocks", + "settings": { + "servers": [{ + "port": 4443, + "method": "2022-blake3-aes-256-gcm", + "address": "$DOMAIN", + "password": "${xray_sspasw_vrv}" + }] + } +}' + + +# 3. Собираем всё вместе и прогоняем через envsubst +( + echo "[" + print_config "$OUT_TCP_REALITY" "🇪🇺 VlessRAWrealityXTLS - autoXRAY" + echo "," + print_config "$OUT_XHTTP_REALITY" "🇪🇺 vlessXHTTPreality - autoXRAY" + echo "," + print_config "$OUT_SHADOWSOCKS" "🇪🇺 ShadowS2022blake3 - autoXRAY" + echo "]" +) | envsubst > "$WEB_PATH/$path_subpage.json" + + +# Перезапуск Xray +echo "Перезапуск Xray..." +systemctl restart xray +echo -e "Готово!\n" + +# Формирование ссылок +subPageLink="https://$DOMAIN/$path_subpage.json" + +# Формирование ссылок +link01="vless://${xray_uuid_vrv}@$DOMAIN:443?security=tls&type=tcp&headerType=&path=&host=&flow=xtls-rprx-vision&sni=$DOMAIN&fp=chrome&pbk=${xray_publicKey_vrv}&sid=${xray_shortIds_vrv}&spx=%2F#vlessTCPxtlsVision-autoXRAY" + +link012="vless://${xray_uuid_vrv}@$DOMAIN:443?security=tls&type=tcp&headerType=http&path=%2F${path_xhttp}33&host=&sni=$DOMAIN&fp=chrome&pbk=${xray_publicKey_vrv}&sid=${xray_shortIds_vrv}&spx=%2F#vlessTCPtls-autoXRAY" + +link02="vless://${xray_uuid_vrv}@$DOMAIN:443?security=tls&type=xhttp&headerType=&path=%2F${path_xhttp}&host=&mode=auto&extra=%7B%22xmux%22%3A%7B%22cMaxReuseTimes%22%3A%221000-3000%22%2C%22maxConcurrency%22%3A%223-5%22%2C%22maxConnections%22%3A0%2C%22hKeepAlivePeriod%22%3A0%2C%22hMaxRequestTimes%22%3A%22400-700%22%2C%22hMaxReusableSecs%22%3A%221200-1800%22%7D%2C%22headers%22%3A%7B%7D%2C%22noGRPCHeader%22%3Afalse%2C%22xPaddingBytes%22%3A%22400-800%22%2C%22scMaxEachPostBytes%22%3A1500000%2C%22scMinPostsIntervalMs%22%3A20%2C%22scStreamUpServerSecs%22%3A%2260-240%22%7D&sni=$DOMAIN&fp=chrome&pbk=${xray_publicKey_vrv}&sid=${xray_shortIds_vrv}&spx=%2F#vlessXHTTPtls-autoXRAY" + +link03="vless://${xray_uuid_vrv}@$DOMAIN:443?security=tls&type=ws&headerType=&path=%2F${path_xhttp}22&host=&sni=$DOMAIN&fp=chrome&pbk=${xray_publicKey_vrv}&sid=${xray_shortIds_vrv}&spx=%2F#vlessWStls-autoXRAY" + +link04="vless://${xray_uuid_vrv}@$DOMAIN:443?security=tls&type=grpc&headerType=&serviceName=${path_xhttp}11&host=&sni=$DOMAIN&fp=chrome&pbk=${xray_publicKey_vrv}&sid=${xray_shortIds_vrv}&spx=%2F#vlessGRPCtls-autoXRAY" + + +ENCODED_STRING=$(echo -n "2022-blake3-aes-256-gcm:${xray_sspasw_vrv}" | base64) +linkSS="ss://$ENCODED_STRING@${DOMAIN}:4443#Shadowsocks2022-autoXRAY" + +configListLink="https://$DOMAIN/$path_subpage.html" + +# Создаем html файл с конфигами +cat > "$WEB_PATH/$path_subpage.html" <AutoXRAY configs + +

➡️ vless TCP xtls-Vision

$link01
+

➡️ vless TCP tls

$link012
+

➡️ vless XHTTP tls

$link02
+

➡️ vless WS tls

$link03
+

➡️ vless GRPC tls

$link04
+

➡️ Shadowsocks2022blake3 - новый и быстрый

$linkSS

+📂 Ссылка на подписку (готовый конфиг клиента с роутингом)

$subPageLink

📱 Приложение HAPP (Windows/Android/iOS/MAC/Linux)

+

Маршрутизацию нужно выключить, она тут встроенная. По умолчанию она выключена - включатся, если вы пользовались сторонними сервисами.

+EOF + +echo -e " + +Ваша json страничка подписки: +\033[32m$subPageLink\033[0m + +Ссылка на сохраненные конфиги: +\033[32m$configListLink\033[0m + +Скопируйте подписку в специализированное приложение: +- iOS: Happ или v2RayTun или v2rayN +- Android: Happ или v2RayTun или v2rayNG +- Windows: конфиги Happ или winLoadXRAY или v2rayN + для vless v2RayTun или Throne + +Открыт локальный socks5 на порту 10808, 2080 и http на 10809. + +Поддержать автора: https://github.com/xVRVx/autoXRAY +"