forked from mohsen918/MTProxy1
-
Notifications
You must be signed in to change notification settings - Fork 0
/
MTProxy.sh
586 lines (546 loc) · 18.2 KB
/
MTProxy.sh
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
#!/bin/bash
Red="\033[31m" # 红色
Green="\033[32m" # 绿色
Yellow="\033[33m" # 黄色
Blue="\033[34m" # 蓝色
Nc="\033[0m" # 重置颜色
Red_globa="\033[41;37m" # 红底白字
Green_globa="\033[42;37m" # 绿底白字
Yellow_globa="\033[43;37m" # 黄底白字
Blue_globa="\033[44;37m" # 蓝底白字
Info="${Green}[信息]${Nc}"
Error="${Red}[错误]${Nc}"
Tip="${Yellow}[提示]${Nc}"
mtproxy_dir="/usr/local/MTProxy"
mtproxy_file="${mtproxy_dir}/mtproxy"
mtproxy_conf="${mtproxy_dir}/config.toml"
mtproxy_log="${mtproxy_dir}/mtproxy.log"
Old_ver_file="${mtproxy_dir}/ver.txt"
# 检查是否为root用户
check_root(){
if [[ $(whoami) != "root" ]]; then
echo -e "${Error} 当前非ROOT账号(或没有ROOT权限),无法继续操作,请更换ROOT账号或使用 ${Green_globa}sudo -i${Nc} 命令获取临时ROOT权限(执行后可能会提示输入当前账号的密码)。"
exit 1
fi
}
# 安装依赖
install_base(){
if ! command -v wget &>/dev/null || ! command -v ip &>/dev/null || ! command -v tar &>/dev/null || ! command -v ntpdate &>/dev/null; then
echo -e "${Info} 开始安装依赖软件!"
OS=$(cat /etc/os-release | grep -o -E "Debian|Ubuntu|CentOS" | head -n 1)
if [[ "$OS" == "Debian" || "$OS" == "Ubuntu" ]]; then
apt update -y
apt install -y wget tar ntpdate iproute2
systemctl unmask systemd-timesyncd.service >/dev/null 2>&1
ntpdate time.google.com
elif [[ "$OS" == "CentOS" ]]; then
yum update -y
yum install -y wget tar ntpdate iproute
systemctl unmask systemd-timesyncd.service >/dev/null 2>&1
ntpdate time.google.com
else
echo -e "${Error}很抱歉,你的系统不受支持!"
exit 1
fi
fi
}
# 检查架构
check_Arch(){
arch=$(uname -m)
if [[ ${arch} == "x86_64" ]]; then
Arch="amd64"
elif [[ ${arch} == "i386" || ${arch} == "i686" ]]; then
Arch="386"
elif [[ ${arch} == "arm64" || ${arch} == "armv6" || ${arch} == "armv7" ]]; then
Arch="arm64"
else
echo -e "${Error}很抱歉,你的架构不受支持!"
exit 1
fi
}
check_pid(){
PID=$(ps -ef | grep "./mtproxy " | grep -v "grep" | grep -v "service" | awk '{print $2}')
}
# 检查是否安装MTProxy
check_installed_status(){
if [[ ! -e "${mtproxy_file}" ]]; then
echo -e "${Error} MTProxy 没有安装,请检查 !"
exit 1
fi
}
# 检查MTProxy新版本
check_New_ver(){
New_ver=$(curl -s https://api.github.com/repos/elesssss/MTProxy/releases/latest | grep -oP '"tag_name": "\K([^"]+)')
Old_ver=$(cat ${Old_ver_file})
if [[ "${Old_ver}" != "${New_ver}" ]]; then
echo -e "${Info} 发现 MTProxy 已有新版本 [ ${New_ver} ],旧版本 [ ${Old_ver} ]"
read -e -p "是否更新 ? [Y/n] :" yn
[[ -z "${yn}" ]] && yn="y"
if [[ $yn == [Yy] ]]; then
cp ${mtproxy_conf} /tmp/mtproxy.conf
rm -rf ${mtproxy_dir}
Download
mv /tmp/mtproxy.conf ${mtproxy_conf}
fi
else
echo -e "${Info} 当前 MTProxy 已是最新版本 [ ${New_ver} ]"
sleep 2
menu
fi
}
Download(){
if [[ ! -e "${mtproxy_dir}" ]]; then
mkdir "${mtproxy_dir}"
fi
cd "${mtproxy_dir}"
echo -e "${Info} 开始下载 mtproxy......"
check_Arch
wget --no-check-certificate https://github.com/elesssss/MTProxy/releases/download/${New_ver}/MTProxy-${New_ver}-linux-${Arch}.tar.gz
tar xvf MTProxy-${New_ver}-linux-${Arch}.tar.gz
rm -f MTProxy-${New_ver}-linux-${Arch}.tar.gz
chmod +x mtproxy
echo "${New_ver}" >${Old_ver_file}
}
Write_config(){
cat >${mtproxy_conf} <<-EOF
PORT=${mtp_port}
PASSWORD=${mtp_passwd}
SECURE=${SECURE}
FAKE-TLS=${mtp_tls}
TAG=${mtp_tag}
IPadderv4=${mtp_nat_ipv4}
NTP_TIME=time.google.com
BUFFER-WRITE=${buffer_write}
BUFFER-READ=${buffer_read}
STATS-BIND=${stats_bind}
ANTI-REPLAY-MAX-SIZE=${anti_replay_max_size}
MULTIPLEX-PER-CONNECTION=${multiplex_per_connection}
EOF
}
Write_Service(){
cat >/etc/systemd/system/mtproxy.service <<-'EOF'
[Unit]
Description=MTProxy
After=network.target
[Service]
Type=simple
WorkingDirectory=/usr/local/MTProxy
EnvironmentFile=/usr/local/MTProxy/config.toml
ExecStart=/usr/local/MTProxy/mtproxy run -b 0.0.0.0:${PORT} -4 ${IPadderv4}:${PORT} ${SECURE} ${TAG} --ntp-server=${NTP_TIME}
StandardOutput=append:/usr/local/MTProxy/mtproxy.log
StandardError=append:/usr/local/MTProxy/mtproxy.log
Restart=always
[Install]
WantedBy=multi-user.target
EOF
systemctl enable mtproxy
}
Read_config(){
[[ ! -e ${mtproxy_conf} ]] && echo -e "${Error} MTProxy 配置文件不存在 !" && exit 1
port=$(cat ${mtproxy_conf} | grep 'PORT=' | awk -F 'PORT=' '{print $NF}')
password=$(cat ${mtproxy_conf} | grep 'PASSWORD=' | awk -F 'PASSWORD=' '{print $NF}')
fake_tls=$(cat ${mtproxy_conf} | grep 'FAKE-TLS=' | awk -F 'FAKE-TLS=' '{print $NF}')
tag=$(cat ${mtproxy_conf} | grep 'TAG=' | awk -F 'TAG=' '{print $NF}')
nat_ipv4=$(cat ${mtproxy_conf} | grep 'IPadderv4=' | awk -F 'IPadderv4=' '{print $NF}')
nat_ipv6=$(cat ${mtproxy_conf} | grep 'NAT-IPv6=' | awk -F 'NAT-IPv6=' '{print $NF}')
secure=$(cat ${mtproxy_conf} | grep 'SECURE=' | awk -F 'SECURE=' '{print $NF}')
buffer_write=$(cat ${mtproxy_conf} | grep 'BUFFER-WRITE=' | awk -F 'BUFFER-WRITE=' '{print $NF}')
buffer_read=$(cat ${mtproxy_conf} | grep 'BUFFER-READ=' | awk -F 'BUFFER-READ=' '{print $NF}')
stats_bind=$(cat ${mtproxy_conf} | grep 'STATS-BIND=' | awk -F 'STATS-BIND=' '{print $NF}')
anti_replay_max_size=$(cat ${mtproxy_conf} | grep 'ANTI-REPLAY-MAX-SIZE=' | awk -F 'ANTI-REPLAY-MAX-SIZE=' '{print $NF}')
multiplex_per_connection=$(cat ${mtproxy_conf} | grep 'MULTIPLEX-PER-CONNECTION=' | awk -F 'MULTIPLEX-PER-CONNECTION=' '{print $NF}')
}
Set_port(){
while true; do
echo -e "请输入 MTProxy 端口 [10000-65535]"
read -e -p "(默认:随机生成):" mtp_port
[[ -z "${mtp_port}" ]] && mtp_port=$(shuf -i10000-65000 -n1)
echo $((${mtp_port} + 0)) &>/dev/null
if [[ $? -eq 0 ]]; then
if [[ ${mtp_port} -ge 10000 ]] && [[ ${mtp_port} -le 65535 ]]; then
echo && echo "========================"
echo -e " 端口 : ${Red_globa} ${mtp_port} ${Nc}"
echo "========================" && echo
break
else
echo "输入错误, 请输入正确的端口。"
fi
else
echo "输入错误, 请输入正确的端口。"
fi
done
}
Set_passwd(){
while true; do
echo "请输入 MTProxy 密匙(普通密钥必须为32位,[0-9][a-z][A-Z],建议留空随机生成)"
read -e -p "(若需要开启TLS伪装建议直接回车):" mtp_passwd
if [[ -z "${mtp_passwd}" ]]; then
echo -e "是否开启TLS伪装?[Y/n]"
read -e -p "(默认:Y 启用):" mtp_tls
[[ -z "${mtp_tls}" ]] && mtp_tls="Y"
if [[ "${mtp_tls}" == [Yy] ]]; then
echo -e "请输入TLS伪装域名"
read -e -p "(默认:itunes.apple.com):" fake_domain
[[ -z "${fake_domain}" ]] && fake_domain="itunes.apple.com"
mtp_tls="YES"
mtp_passwd=$(${mtproxy_dir}/mtproxy generate-secret -c ${fake_domain} tls)
else
mtp_tls="NO"
mtp_passwd=$(date +%s%N | md5sum | head -c 32)
fi
else
if [[ ${#mtp_passwd} != 32 ]]; then
echo -e "你输入的密钥不是标准秘钥,是否为启用TLS伪装的密钥?[Y/n]"
read -e -p "(默认:N 不是):" mtp_tls
[[ -z "${mtp_tls}" ]] && mtp_tls="N"
if [[ "${mtp_tls}" == [Nn] ]]; then
echo -e "${Error} 你输入的密钥不是标准秘钥(32位字符)。" && continue
else
mtp_tls="YES"
fi
else
mtp_tls="NO"
fi
fi
echo && echo "========================"
echo -e " 密码 : ${Red_globa} ${mtp_passwd} ${Nc}"
echo
echo -e " 是否启用TLS伪装 : ${Red_globa} ${mtp_tls} ${Nc}"
echo "========================" && echo
break
done
echo -e "是否启用强制安全模式?[Y/n]
启用[安全混淆模式]的客户端链接(即密匙头部有 dd 字符),降低服务器被墙几率,建议开启。"
read -e -p "(默认:Y 启用):" mtp_secure
[[ -z "${mtp_secure}" ]] && mtp_secure="Y"
if [[ "${mtp_secure}" == [Yy] ]]; then
mtp_secure="YES"
else
mtp_secure="NO"
fi
if [[ "${mtp_tls}" == "NO" && "${mtp_secure}" == "YES" ]]; then
SECURE=dd${mtp_passwd}
else
SECURE=${mtp_passwd}
fi
echo && echo "========================"
echo -e " 密匙 : ${Red_globa} ${SECURE} ${Nc}"
echo "========================" && echo
}
Set_tag(){
echo "请输入 MTProxy 的 TAG标签(TAG标签必须是32位,TAG标签只有在通过官方机器人 @MTProxybot 分享代理账号后才会获得,不清楚请留空回车)"
read -e -p "(默认:回车跳过):" mtp_tag
if [[ ! -z "${mtp_tag}" ]]; then
echo && echo "========================"
echo -e " TAG : ${Red_globa} ${mtp_tag} ${Nc}"
echo "========================" && echo
else
echo
fi
}
Set_nat(){
echo -e "如果本机是NAT服务器(谷歌云、微软云、阿里云等,网卡绑定的IP为 10.xx.xx.xx 开头的),则需要指定公网 IPv4。"
read -e -p "(默认:自动检测 IPv4 地址):" mtp_nat_ipv4
if [[ -z "${mtp_nat_ipv4}" ]]; then
getipv4
if [[ "${ipv4}" == "IPv4_Error" ]]; then
mtp_nat_ipv4=""
else
mtp_nat_ipv4="${ipv4}"
fi
echo && echo "========================"
echo -e " IPv4 : ${Red_globa} ${mtp_nat_ipv4} ${Nc}"
echo "========================" && echo
fi
}
Set(){
check_installed_status
echo && echo -e "你要做什么?
${Green}1.${Nc} 修改 端口配置
${Green}2.${Nc} 修改 密码配置
${Green}3.${Nc} 修改 TAG 配置
${Green}4.${Nc} 修改 NAT 配置
${Green}5.${Nc} 修改 全部配置" && echo
read -e -p "(默认: 取消):" mtp_modify
[[ -z "${mtp_modify}" ]] && echo -e "${Info}已取消..." && exit 1
if [[ "${mtp_modify}" == "1" ]]; then
Read_config
mtp_passwd=${password}
mtp_tls=${fake_tls}
mtp_tag=${tag}
mtp_nat_ipv4=${nat_ipv4}
mtp_nat_ipv6=${nat_ipv6}
SECURE=${secure}
Set_port
Write_config
Restart
elif [[ "${mtp_modify}" == "2" ]]; then
Read_config
mtp_port=${port}
mtp_tag=${tag}
mtp_nat_ipv4=${nat_ipv4}
mtp_nat_ipv6=${nat_ipv6}
SECURE=${secure}
Set_passwd
Write_config
Restart
elif [[ "${mtp_modify}" == "3" ]]; then
Read_config
mtp_port=${port}
mtp_passwd=${passwd}
mtp_tls=${fake_tls}
mtp_nat_ipv4=${nat_ipv4}
mtp_nat_ipv6=${nat_ipv6}
SECURE=${secure}
Set_tag
Write_config
Restart
elif [[ "${mtp_modify}" == "4" ]]; then
Read_config
mtp_port=${port}
mtp_passwd=${password}
mtp_tls=${fake_tls}
mtp_tag=${tag}
SECURE=${secure}
Set_nat
Write_config
Restart
elif [[ "${mtp_modify}" == "5" ]]; then
Read_config
Set_port
Set_passwd
Set_tag
Set_nat
Write_config
Restart
else
echo -e "${Error} 请输入正确的数字(1-5)" && exit 1
fi
}
Install(){
[[ -e ${mtproxy_file} ]] && echo -e "${Error} 检测到 MTProxy 已安装 !" && exit 1
echo -e "${Info} 开始安装/配置 依赖..."
install_base
echo -e "${Info} 开始下载/安装..."
check_New_ver
Download
echo -e "${Info} 开始设置 用户配置..."
Set_port
Set_passwd
Set_tag
Set_nat
echo -e "${Info} 开始写入 配置文件..."
Write_config
echo -e "${Info} 开始写入 Service..."
Write_Service
echo -e "${Info} 所有步骤 执行完毕,开始启动..."
Start
}
Start(){
check_installed_status
check_pid
if [[ ! -z ${PID} ]]; then
echo -e "${Error} MTProxy 正在运行,请检查 !"
sleep 1s
menu
else
systemctl start mtproxy.service
sleep 1s
check_pid
if [[ ! -z ${PID} ]]; then
View
fi
fi
}
Stop(){
check_installed_status
check_pid
if [[ -z ${PID} ]]; then
echo -e "${Error} MTProxy 没有运行,请检查 !"
sleep 1s
menu
else
systemctl stop mtproxy.service
sleep 1s
menu
fi
}
Restart(){
check_installed_status
check_pid
if [[ ! -z ${PID} ]]; then
systemctl stop mtproxy
sleep 1s
fi
systemctl start mtproxy
sleep 1s
check_pid
[[ ! -z ${PID} ]] && View
}
Update(){
check_installed_status
check_New_ver
}
Uninstall(){
check_installed_status
echo "确定要卸载 MTProxy ? (y/N)"
echo
read -e -p "(默认: n):" unyn
[[ -z ${unyn} ]] && unyn="n"
if [[ ${unyn} == [Yy] ]]; then
check_pid
if [[ ! -z $PID ]]; then
systemctl stop mtproxy
fi
systemctl disable mtproxy
rm -rf ${mtproxy_dir} /etc/systemd/system/mtproxy.service
echo
echo "MTProxy 卸载完成 !"
echo
else
echo
echo -e "${Tip}卸载已取消..."
echo
fi
}
getipv4(){
get_public_ip
if [[ -z "${ipv4}" ]]; then
ipv4="IPv4_Error"
fi
}
getipv6(){
get_public_ip
if [[ -z "${ipv6}" ]]; then
ipv6="IPv6_Error"
fi
}
get_public_ip(){
regex_pattern='^(eth|ens|eno|esp|enp|venet|vif)[0-9]+'
InterFace=($(ip link show | awk -F': ' '{print $2}' | grep -E "$regex_pattern" | sed "s/@.*//g"))
ipv4=""
ipv6=""
for i in "${InterFace[@]}"; do
Public_IPv4=$(curl -s4m8 --interface "$i" ip.gs -k | sed '/^\(2a09\|104\.28\)/d')
Public_IPv6=$(curl -s6m8 --interface "$i" ip.gs -k | sed '/^\(2a09\|104\.28\)/d')
# 检查是否获取到IP地址
if [[ -n "$Public_IPv4" ]]; then
ipv4="$Public_IPv4"
fi
if [[ -n "$Public_IPv6" ]]; then
ipv6="$Public_IPv6"
fi
done
}
View(){
check_installed_status
Read_config
#getipv4
#getipv6
clear && echo
echo -e "Mtproto Proxy 用户配置:"
echo -e "————————————————"
echo -e " 地址\t: ${Green}${nat_ipv4}${Nc}"
[[ ! -z "${nat_ipv6}" ]] && echo -e " 地址\t: ${Green}${nat_ipv6}${Nc}"
echo -e " 端口\t: ${Green}${port}${Nc}"
echo -e " 密匙\t: ${Green}${secure}${Nc}"
[[ ! -z "${tag}" ]] && echo -e " TAG \t: ${Green}${tag}${Nc}"
echo -e " 链接\t: ${Red}tg://proxy?server=${nat_ipv4}&port=${port}&secret=${secure}${Nc}"
echo -e " 链接\t: ${Red}https://t.me/proxy?server=${nat_ipv4}&port=${port}&secret=${secure}${Nc}"
[[ ! -z "${nat_ipv6}" ]] && echo -e " 链接\t: ${Red}tg://proxy?server=${nat_ipv6}&port=${port}&secret=${secure}${Nc}"
[[ ! -z "${nat_ipv6}" ]] && echo -e " 链接\t: ${Red}https://t.me/proxy?server=${nat_ipv6}&port=${port}&secret=${secure}${Nc}"
echo
echo -e " TLS伪装模式\t: ${Green}${fake_tls}${Nc}"
echo
echo -e " ${Red}注意\t:${Nc} 密匙头部的 ${Green}dd${Nc} 字符是代表客户端启用${Green}安全混淆模式${Nc}(TLS伪装模式除外),可以降低服务器被墙几率。"
backmenu
}
View_Log(){
check_installed_status
[[ ! -e ${mtproxy_log} ]] && echo -e "${Error} MTProxy 日志文件不存在 !" && exit 1
echo && echo -e "${Tip} 按 ${Red}Ctrl+C${Nc} 终止查看日志" && echo -e "如果需要查看完整日志内容,请用 ${Red}cat ${mtproxy_log}${Nc} 命令。" && echo
tail -f ${mtproxy_log}
}
Esc_Shell(){
exit 0
}
backmenu(){
echo ""
read -rp "请输入“y”退出, 或按任意键回到主菜单:" back2menuInput
case "$backmenuInput" in
y) exit 1 ;;
*) menu ;;
esac
}
menu() {
clear
echo -e "${Green}######################################
# ${Red}MTProxy 一键脚本 ${Green}#
# 作者: ${Yellow}你挺好看啊🍏 ${Green}#
######################################
0.${Nc} 退出脚本
———————————————————————
${Green} 1.${Nc} 安装 MTProxy
${Green} 2.${Nc} 更新 MTProxy
${Green} 3.${Nc} 卸载 MTProxy
———————————————————————
${Green} 4.${Nc} 启动 MTProxy
${Green} 5.${Nc} 停止 MTProxy
${Green} 6.${Nc} 重启 MTProxy
———————————————————————
${Green} 7.${Nc} 设置 MTProxy配置
${Green} 8.${Nc} 查看 MTProxy链接
${Green} 9.${Nc} 查看 MTProxy日志
———————————————————————" && echo
if [[ -e ${mtproxy_file} ]]; then
check_pid
if [[ ! -z "${PID}" ]]; then
echo -e " 当前状态: ${Green}已安装${Nc} 并 ${Green}已启动${Nc}"
check_installed_status
Read_config
echo -e " ${Info}MTProxy 链接: ${Red}https://t.me/proxy?server=${nat_ipv4}&port=${port}&secret=${secure}${Nc}"
else
echo -e " 当前状态: ${Green}已安装${Nc} 但 ${Red}未启动${Nc}"
fi
else
echo -e " 当前状态: ${Red}未安装${Nc}"
fi
echo
read -e -p " 请输入数字 [0-9]:" num
case "$num" in
0)
Esc_Shell
;;
1)
Install
;;
2)
Update
;;
3)
Uninstall
;;
4)
Start
;;
5)
Stop
;;
6)
Restart
;;
7)
Set
;;
8)
View
;;
9)
View_Log
;;
*)
echo -e "${Error} 请输入正确数字 [0-9]"
;;
esac
}
menu