feat(脚本): xray-core reality增加防止流量盗刷配置

This commit is contained in:
mack-a
2025-11-21 12:06:31 +08:00
parent c5bad68044
commit 1ca7059c46
+64 -55
View File
@@ -509,17 +509,17 @@ readInstallProtocolType() {
if echo "${row}" | grep -q VLESS_vision_reality_inbounds; then
currentInstallProtocolType="${currentInstallProtocolType}7,"
if [[ "${coreInstallType}" == "1" ]]; then
xrayVLESSRealityServerName=$(jq -r .inbounds[0].streamSettings.realitySettings.serverNames[0] "${row}.json")
xrayVLESSRealityServerName=$(jq -r .inbounds[1].streamSettings.realitySettings.serverNames[0] "${row}.json")
realityServerName=${xrayVLESSRealityServerName}
xrayVLESSRealityPort=$(jq -r .inbounds[0].port "${row}.json")
realityDomainPort=$(jq -r .inbounds[0].streamSettings.realitySettings.dest "${row}.json" | awk -F '[:]' '{print $2}')
realityDomainPort=$(jq -r .inbounds[1].streamSettings.realitySettings.target "${row}.json" | awk -F '[:]' '{print $2}')
currentRealityPublicKey=$(jq -r .inbounds[0].streamSettings.realitySettings.publicKey "${row}.json")
currentRealityPrivateKey=$(jq -r .inbounds[0].streamSettings.realitySettings.privateKey "${row}.json")
currentRealityPublicKey=$(jq -r .inbounds[1].streamSettings.realitySettings.publicKey "${row}.json")
currentRealityPrivateKey=$(jq -r .inbounds[1].streamSettings.realitySettings.privateKey "${row}.json")
currentRealityMldsa65Seed=$(jq -r .inbounds[0].streamSettings.realitySettings.mldsa65Seed "${row}.json")
currentRealityMldsa65Verify=$(jq -r .inbounds[0].streamSettings.realitySettings.mldsa65Verify "${row}.json")
currentRealityMldsa65Seed=$(jq -r .inbounds[1].streamSettings.realitySettings.mldsa65Seed "${row}.json")
currentRealityMldsa65Verify=$(jq -r .inbounds[1].streamSettings.realitySettings.mldsa65Verify "${row}.json")
frontingTypeReality=07_VLESS_vision_reality_inbounds
@@ -3990,7 +3990,7 @@ EOF
"security": "reality",
"realitySettings": {
"show": false,
"dest": "${realityServerName}:${realityDomainPort}",
"target": "${realityServerName}:${realityDomainPort}",
"xver": 0,
"serverNames": [
"${realityServerName}"
@@ -4016,42 +4016,6 @@ EOF
elif [[ -z "$3" ]]; then
rm /etc/v2ray-agent/xray/conf/12_VLESS_XHTTP_inbounds.json >/dev/null 2>&1
fi
# trojan_grpc
# if echo "${selectCustomInstallType}" | grep -q ",2," || [[ "$1" == "all" ]]; then
# if ! echo "${selectCustomInstallType}" | grep -q ",5," && [[ -n ${selectCustomInstallType} ]]; then
# fallbacksList=${fallbacksList//31302/31304}
# fi
# cat <<EOF >/etc/v2ray-agent/xray/conf/04_trojan_gRPC_inbounds.json
#{
# "inbounds": [
# {
# "port": 31304,
# "listen": "127.0.0.1",
# "protocol": "trojan",
# "tag": "trojangRPCTCP",
# "settings": {
# "clients": $(initXrayClients 2),
# "fallbacks": [
# {
# "dest": "31300"
# }
# ]
# },
# "streamSettings": {
# "network": "grpc",
# "grpcSettings": {
# "serviceName": "${customPath}trojangrpc"
# }
# }
# }
# ]
#}
#EOF
# elif [[ -z "$3" ]]; then
# rm /etc/v2ray-agent/xray/conf/04_trojan_gRPC_inbounds.json >/dev/null 2>&1
# fi
# VMess_WS
if echo "${selectCustomInstallType}" | grep -q ",3," || [[ "$1" == "all" ]]; then
fallbacksList=${fallbacksList}',{"path":"/'${customPath}'vws","dest":31299,"xver":1}'
cat <<EOF >/etc/v2ray-agent/xray/conf/05_VMess_WS_inbounds.json
@@ -4157,14 +4121,30 @@ EOF
initRealityClientServersName
initRealityKey
initRealityMldsa65
cat <<EOF >/etc/v2ray-agent/xray/conf/07_VLESS_vision_reality_inbounds.json
{
"inbounds": [
{
"tag": "dokodemo-in-VLESSReality",
"port": ${realityPort},
"protocol": "dokodemo-door",
"settings": {
"address": "127.0.0.1",
"port": 45987,
"network": "tcp"
},
"sniffing": {
"enabled": true,
"destOverride": [
"tls"
],
"routeOnly": true
}
},
{
"listen": "127.0.0.1",
"port": 45987,
"protocol": "vless",
"tag": "VLESSReality",
"settings": {
"clients": $(initXrayClients 7),
"decryption": "none",
@@ -4180,7 +4160,7 @@ EOF
"security": "reality",
"realitySettings": {
"show": false,
"dest": "${realityServerName}:${realityDomainPort}",
"target": "${realityServerName}:${realityDomainPort}",
"xver": 0,
"serverNames": [
"${realityServerName}"
@@ -4195,12 +4175,39 @@ EOF
"6ba85179e30d4fc2"
]
}
},
"sniffing": {
"enabled": true,
"destOverride": [
"http",
"tls",
"quic"
],
"routeOnly": true
}
}
],
"routing": {
"rules": [
{
"inboundTag": [
"dokodemo-in"
],
"domain": [
"${realityServerName}"
],
"outboundTag": "z_direct_outbound"
},
{
"inboundTag": [
"dokodemo-in"
],
"outboundTag": "blackhole_out"
}
]
}
}
EOF
cat <<EOF >/etc/v2ray-agent/xray/conf/08_VLESS_vision_gRPC_inbounds.json
{
"inbounds": [
@@ -4244,6 +4251,7 @@ EOF
removeXrayOutbound wireguard_out_IPv6
removeXrayOutbound wireguard_out_IPv4
addXrayOutbound z_direct_outbound
addXrayOutbound blackhole_out
fi
}
@@ -5344,7 +5352,7 @@ showAccounts() {
# VLESS reality vision
if echo ${currentInstallProtocolType} | grep -q ",7,"; then
echoContent skyBlue "============================= VLESS reality_vision [推荐] ==============================\n"
jq .inbounds[0].settings.clients//.inbounds[0].users ${configPath}07_VLESS_vision_reality_inbounds.json | jq -c '.[]' | while read -r user; do
jq .inbounds[1].settings.clients//.inbounds[0].users ${configPath}07_VLESS_vision_reality_inbounds.json | jq -c '.[]' | while read -r user; do
local email=
email=$(echo "${user}" | jq -r .email//.name)
@@ -6392,7 +6400,7 @@ ipv6Routing() {
read -r -p "请按照上面示例录入域名:" domainList
if [[ "${coreInstallType}" == "1" ]]; then
addInstallRouting IPv6_out outboundTag "${domainList}"
addXrayRouting IPv6_out outboundTag "${domainList}"
addXrayOutbound IPv6_out
fi
@@ -6603,7 +6611,7 @@ blacklist() {
echoContent yellow "5.添加规则为增量配置,不会删除之前设置的内容\n"
read -r -p "请按照上面示例录入域名:" domainList
if [[ "${coreInstallType}" == "1" ]]; then
addInstallRouting blackhole_out outboundTag "${domainList}"
addXrayRouting blackhole_out outboundTag "${domainList}"
addXrayOutbound blackhole_out
fi
@@ -6619,7 +6627,7 @@ blacklist() {
if [[ "${coreInstallType}" == "1" ]]; then
unInstallRouting blackhole_out outboundTag
addInstallRouting blackhole_out outboundTag "cn"
addXrayRouting blackhole_out outboundTag "cn"
addXrayOutbound blackhole_out
fi
@@ -6658,7 +6666,7 @@ blacklist() {
reloadCore
}
# 添加routing配置
addInstallRouting() {
addXrayRouting() {
local tag=$1 # warp-socks
local type=$2 # outboundTag/inboundTag
@@ -6838,7 +6846,7 @@ addWireGuardRoute() {
# xray
if [[ "${coreInstallType}" == "1" ]]; then
addInstallRouting "wireguard_out_${type}" "${tag}" "${domainList}"
addXrayRouting "wireguard_out_${type}" "${tag}" "${domainList}"
addXrayOutbound "wireguard_out_${type}"
fi
# sing-box
@@ -7602,7 +7610,7 @@ setVMessWSRoutingOutbounds() {
setVMessWSTLSPath="/${setVMessWSTLSPath}"
fi
addXrayOutbound "VMess-out"
addInstallRouting VMess-out outboundTag "${domainList}"
addXrayRouting VMess-out outboundTag "${domainList}"
reloadCore
echoContent green " ---> 添加分流成功"
exit 0
@@ -9504,7 +9512,7 @@ menu() {
cd "$HOME" || exit
echoContent red "\n=============================================================="
echoContent green "作者:mack-a"
echoContent green "当前版本:v3.4.33"
echoContent green "当前版本:v3.4.34"
echoContent green "Githubhttps://github.com/mack-a/v2ray-agent"
echoContent green "描述:八合一共存脚本\c"
showInstallStatus
@@ -9518,6 +9526,7 @@ menu() {
echoContent yellow "优质常驻套餐DMIT CN2-GIA"
echoContent green "https://www.v2ray-agent.com/archives/186cee7b-9459-4e57-b9b2-b07a4f36931c"
echoContent yellow "VPS探针:https://ping.v2ray-agent.com/"
echoContent red " "
echoContent red "=============================================================="
if [[ -n "${coreInstallType}" ]]; then
echoContent yellow "1.重新安装"