下载地址: http://3proxy.ru/current/3proxy-0.7-devel-120711025833.zip,解压,进入解压出来的目录3proxy-0.7-devel-120711025833\bin\,在里面建立一个3proxy.cfg文件,内容如下:
from https://www.blackhatworld.com/seo/never-buy-proxies-again-setup-your-own-proxy-server.872539/
nscache 65536 timeouts 1 5 30 60 180 1800 15 60
users "linfeng:CL:iloveu"
auth iponly allow * parent 1000 socks5+ 127.0.0.1 1080
proxy -n -a -p3128 (这里的proxy是http proxy)
复制c:\windows\system32\cmd.exe文件到 解压出来的目录3proxy-0.7-devel-120711025833\bin\。
然后运行 3proxy-0.7-devel-120711025833\bin\里面的cmd.exe,输入3proxy.exe 3proxy.cfg,回车。
也可在 3proxy-0.7-devel-120711025833\bin\里面建立一个start 3proxy.bat文件,内容为
3proxy.exe 3proxy.cfg,然后双击该bat文件。
然后设置浏览器的http代理为127.0.0.1:3128,即可翻墙。
以上的 这行:socks -n -a -p3129 ,意思是3proxy在本机建立了一个socks proxy,这样设置你的浏览器
的socks代理为127.0.0.1:3129,也是可翻墙的。
相关帖子:
http://briteming.blogspot.co.uk/2013/04/pcprivoxypolipoopera-mobileopera-mobile.html
https://dream4ever.org/showthread.php?t=147191
-------------------
3proxy -a tiny proxy server(c) 2002-2014 by Vladimir '3APA3A' Dubrovin <3proxy@3proxy.ru> Please read doc/html/index.html and man pages. 3proxy Combined proxy server may be used as Windows 95/98/NT/2000/XP/2003/Vista executable or service (supports installation and removal). It uses config file to read it's configuration (see 3proxy.cfg.sample for details). --install installs and starts proxy as NT/2000/XP service (config file should be located in the same directory) --remove removes the service (should be stopped before via net stop 3proxy). 3proxy.exe is all-in-one, it doesn't require all others .exe to work. See 3proxy.cfg.sample for examples, see man 3proxy.cfg proxy HTTP proxy server, binds to port 3128 ftppr FTP proxy server, binds to port 21 socks SOCKS 4/5 proxy server, binds to port 1080 ftppr FTP proxy server, please do not mess it with FTP over HTTP proxy used in browsers pop3p POP3 proxy server, binds to port 110. You must specify POP3 username as username@target.host.ip[:port] port is 110 by default. Exmple: in Username configuration for you e-mail reader set someuser@pop.somehost.ru, to obtains mail for someuser from pop.somehost.ru via proxy. smtpp SMTP proxy server, binds to port 25. You must specify SMTP username as username@target.host.ip[:port] port is 25 by default. Exmple: in Username configuration for you e-mail reader set someuser@mail.somehost.ru, to send mail as someuser via mail.somehost.ru via proxy. icqpr ICQ/AIM proxy. Maps some TCP port to TCP port of ICQ server and performs packets translation. Example: icqpr 5190 login.icq.com 5190 msnpr MSN proxy (beta) tcppm TCP port mapping. Maps some TCP port on local machine to TCP port on remote host. udppm UDP port mapping. Maps some UDP port on local machine to UDP port on remote machine. Only one user simulationeously can use UDP mapping, so it cann't be used for public service in large networks. It's OK to use it to map to DNS server in small network or to map Counter-Strike server for single client (you can use few mappings on different ports for different clients in last case). mycrypt Program to obtain crypted password fro cleartext. Supports both MD5/crypt and NT password. mycrypt password produces NT password mycrypt salt password produces MD5/crypt password with salt "salt". dighosts Utility for building networks list from web page. countersutil Utility to manage counters file. Run utility with --help option for command line reference. Latest version is available from http://3proxy.ru/from https://github.com/z3APA3A/3proxy---------------------Please read doc/html/index.html and man pages. Features: 1. General + HTTP/1.1 Proxy with keep-alive client and server support, transparent proxy support. + Anonymous and random client emulation HTTP proxy mode + FTP over HTTP support. + DNS caching with built-in resolver + HTTPS (CONNECT) proxy + SOCKSv4/4.5 Proxy + SOCKSv5 Proxy + UDP and bind support for SOCKSv5 (fully compatible with SocksCAP/FreeCAP for UDP) + Transparent SOCKS redirection for HTTP, POP3, FTP, SMTP, ICQ + POP3 Proxy + FTP proxy + DNS proxy + TCP port mapper + UDP port mapper + SMTP proxy + ICQ/AOL proxy + Threaded application (no child process). + Web administration and statistics + Plugins for functionality extension + Native 64 bit application for 64 bit OS, including 64-bit editions of Windows. + IPv6 support 2. Proxy chaining and network connections + Connect back proxy support to bypass firewalls + Parent proxy support for any type of incoming connection + Username/password authentication for parent proxy(s). + HTTPS/SOCKS4/SOCKS5 and redirection parent support + Random parent selection + Chain building (multihop proxing) + Load balancing between few network connections by choosing network interface 3. Logging + turnable log format compatible with any log parser + stdout logging + file logging + syslog logging (Unix) + ODBC logging + log file rotation (hourly, daily, weekly, monthly) + automatic log file comperssion with external archiver (for files) + automatic removal of older log files + Character filtering for log files + different log files for different servces are supported 4. Access control + ACL-driven (user/source/destination/protocol/weekday/daytime or combined) bandwith limitation for incoming and (!)outgoing trafic. + ACL-driven (user/source/destination/protocol/weekday/daytime or combined) traffic limitation per day, week or month for incoming and (!) outgoing traffic + User authentication by DNS hostname + User authentication by username / password + Access control by username, source IP, destination IP, destination port and destination action (POST, PUT, GET, etc), weekday and daytime. + Access control by username/password for SOCKSv5 and HTTP/HTTPS/FTP + Cleartext or encrypted (crypt/MD5 or NT) passwords. + Connection redirection + Access control by requested action (CONNECT/BIND, HTTP GET/POST/PUT/HEAD/OTHER). + NTLM (v1 only) authentication for HTTP proxy access + All access control entries now support weekday and time limitations + Hostnames and * templates are supported instead of IP address 5. Extensions + Regular expression filtering (with PCRE) via PCREPlugin currently HTTP traffic only for URLs, HTTP headers and HTTP data. + Authentication with Windows username/password (cleartext only!) + SSL/TLS decryptions with certificate spoofing + NAT support under Linux 6. Configuration + support for configuration files + support for includes in configuration files + interface binding + running as daemon process + utility for automated networks list building + configuration reload on any file change Unix + support for chroot + support for setgid + support for setuid + support for signals Windows + support --install as service + support --remove as service + support for service START, STOP, PAUSE and CONTINUE commands (on PAUSE no new connection accepted, but active connections still in progress, on CONTINUE configuration is reloaded) Windows 95/98/ME + support --install as service + support --remove as service 6. Compilation + MSVC (static) + Intel Windows Compiler (msvcrt.dll) + Windows/gcc (msvcrt.dll) + Cygwin/gcc (cygwin.dll) + Unix/gcc + Unix/ccc + Solaris + Mac OS X, iPhone OS + Linux and derivered systems + Lite version for Windows 95/98/NT/2000/XP/2003 + 32 bit and 64 bit versions for Windows Vista and above, Windows 2008 server and above 3proxy Combined proxy server may be used as executable or service (supports installation and removal). It uses config file to read it's configuration (see 3proxy.cfg.sample for details). --install installs and starts proxy as Windows service (config file should be located in the same directory) --remove removes the service (should be stopped before via 'net stop 3proxy'). 3proxy.exe is all-in-one, it doesn't require all others .exe to work. See 3proxy.cfg.sample for examples, see man 3proxy.cfg proxy HTTP proxy server, binds to port 3128 ftppr FTP proxy server, binds to port 21 socks SOCKS 4/5 proxy server, binds to port 1080 ftppr FTP proxy server, please do not mess it with FTP over HTTP proxy used in browsers pop3p POP3 proxy server, binds to port 110. You must specify POP3 username as username@target.host.ip[:port] port is 110 by default. Exmple: in Username configuration for you e-mail reader set someuser@pop.somehost.ru, to obtains mail for someuser from pop.somehost.ru via proxy. smtpp SMTP proxy server, binds to port 25. You must specify SMTP username as username@target.host.ip[:port] port is 25 by default. Exmple: in Username configuration for you e-mail reader set someuser@mail.somehost.ru, to send mail as someuser via mail.somehost.ru via proxy. icqpr ICQ/AIM proxy. Maps some TCP port to TCP port of ICQ server and performs packets translation. Example: icqpr 5190 login.icq.com 5190 tcppm TCP port mapping. Maps some TCP port on local machine to TCP port on remote host. udppm UDP port mapping. Maps some UDP port on local machine to UDP port on remote machine. Only one user simulationeously can use UDP mapping, so it cann't be used for public service in large networks. It's OK to use it to map to DNS server in small network or to map Counter-Strike server for single client (you can use few mappings on different ports for different clients in last case). mycrypt Program to obtain crypted password fro cleartext. Supports both MD5/crypt and NT password. mycrypt password produces NT password mycrypt salt password produces MD5/crypt password with salt "salt". dighosts Utility for building networks list from web page. Run utility with --help option for command line reference. Latest version is available from http://3proxy.ru/from https://github.com/z3APA3A/3proxy------------
Now the actul Work starts to setup proxy serve Steps to follow : Install Ubuntu 14 when you purchase VPS and then run below commands in SSH terminal (Use Putty for SSH access)
- apt-get update
- apt-get -y install fail2ban software-properties-common
- apt-get install nano
- apt-get install build-essential libevent-dev libssl-dev
- cd /etc
- wget http://3proxy.ru/0.7.1.1/3proxy-0.7.1.1.tgz
- tar zxvf 3proxy-0.7.1.1.tgz
- rm 3proxy-0.7.1.1.tgz
- cd 3proxy
- nano src/proxy.h
- add line - #define ANONYMOUS 1 (this makes proxy anonymous)
- make -f Makefile.Linux
- make -f Makefile.Linux install
- mkdir log
- cd cfg
- nano 3proxy.cfg
- Add ips here along with Username : Password : Port in this format : proxy -p3128 -a -iYour Ip here -eYour Ip here
- Edit username and password in the same file in this format : users UsernameHere:CL
asswordHere - Allow your username in the same file (You will see the Allow option , just add your username there)
- chmod 0777 3proxy.cfg
- cd ../
- nano scripts/rc.d/proxy.sh ( enter the directory where you installed 3Proxy script! )
- sh scripts/rc.d/proxy.sh start
- nano /etc/rc.local
- sh /etc/3proxy/scripts/rc.d/proxy.sh start
- Update Ubuntu
- Install Fail2ban
- Install Nano editor
- Install libevent and libssl
- Download 3Proxy script
- Unzip it to directory
- And edit the Proxy.h file through Nano and add line #define ANONYMOUS1
- Edit 3Proxy.cfg through Nano and add your ips along with port , username and password
- Then edit proxy.sh and enter where you installed 3Proxy
- Reboot the server and thats it !
from https://www.blackhatworld.com/seo/never-buy-proxies-again-setup-your-own-proxy-server.872539/
------------------
https://github.com/h1777/3proxy-socks
------------------
https://github.com/hidden-refuge/3proxy
--------------------------------------------------
内网服务器利用跳板机代理程序3Proxy访问公网
在服务器运维的时候,需要将服务器联网更新系统以及安装依赖,当时利用了一个 软件ccproxy 。在使用过程中也挺不错的,唯一的缺点就是需要安装软件,需要激活(否则限制连接数)。
这里介绍另一个开源软件,无需安装就可使用!
下载地址
官网下载:https://3proxy.ru/download/stable/
Github仓库下载:https://github.com/3proxy/3proxy/releases
目前该软件部分杀软报毒;
来自DeepSeek的解释:
"3proxy 是一个功能强大的代理服务器工具,虽然其设计初衷是为了合法的网络代理服务(如转发流量、隐藏 IP 等),但它也可能被恶意软件或攻击者用于非法活动,例如: 构建跳板服务器以隐藏攻击者的踪迹 绕过防火墙或访问受限内容 由于这些潜在的滥用场景,杀毒软件可能会将其标记为“风险软件”或“潜在威胁”。 杀毒软件的误报机制 许多杀毒软件使用启发式分析或行为检测技术来识别潜在威胁。如果某个程序的行为模式与已知恶意软件相似
(例如监听端口、转发流量等),即使它本身是合法的,也可能会被误报为病毒 风险软件分类 3proxy 被归类为“RiskWare”(风险软件)的情况并不少见。这类软件本身并非恶意,但可能被滥用于恶意目的。
例如: RiskWare/Win32.3proxy 和 RiskWare/Win64.3proxy 都曾被报告为风险软件。 这种分类通常是因为它们可以被用来绕过网络安全策略或隐藏网络活动 用户行为的影响 如果你从非官方渠道下载了 3proxy,或者文件被篡改(例如捆绑了恶意代码),
那么杀毒软件可能会直接将其视为病毒。此外,如果 3proxy 被配置为开放公网访问且未设置认证,
也可能触发杀毒 软件的警报。" 如想使用就得将该软件设置到杀软的白名单中,才能继续使用! 微软发布的说明:
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Program:Win32/TinyProxy
所以下载该软件,浏览器安全级别高的话,下载有些难度。
使用教程
简单方式
最简单方式,仅需五步完成!
第一步:直接新建或修改配置 3proxy.cfg
nserver 8.8.8.8
nserver 8.8.4.4
nscache 65536
proxy -p808
allow * *
第二歩:打开命令行终端
第三步:输入启动命令 3proxy.exe
第四步:查看本机IP,可利用 ipconfig 查看。或者网络配置信息中查看!
第五步:在需要联网的服务器上执行以下内容(请将 192.168.1.50 换成 你自己的本机IP即可)
export proxy="http://192.168.1.50:808"
export sproxy="socks://192.168.1.50:808"
export http_proxy=$proxy
export FTP_PROXY=$proxy
export ftp_proxy=$proxy
export all_proxy=$sproxy
export ALL_PROXY=$sproxy
export HTTPS_PROXY=$proxy
export https_proxy=$proxy
export HTTP_PROXY=$proxy
export no_proxy="localhost, 127.0.0.1, ::1"
配置文件
以下是完整配置文件说明,需要更多功能可参考使用。
#!/usr/local/bin/3proxy
# 是的,3proxy.cfg 可以是可执行的,在这种情况下,你应该放置类似以下内容:
# config /usr/local/3proxy/3proxy.cfg
# 来指定在重新加载时 3proxy 应该读取哪个配置文件。
# system "echo Hello world!"
# 如果代理启动时需要执行某些外部命令,可以使用 system。
# 我们可以配置 nservers 来避免不安全的 gethostbyname() 使用 <button class="citation-flag" data-index="1">。
nserver 10.1.2.1
nserver 10.2.2.2
# nscache 很好地节省了速度、流量和带宽。
nscache 65536
# nsrecord porno.security.nnov.ru 0.0.0.0
# 没有人能够通过名称访问 porno.security.nnov.ru。
# nsrecord wpad.security.nnov.ru www.security.nnov.ru
# wpad.security.nnov.ru 将解析为 www.security.nnov.ru。
timeouts 1 5 30 60 180 1800 15 60
# 在这里我们可以更改超时值。
users 3APA3A:CL:3apa3a "test:CR:$1$qwer$CHFTUFGqkjue9HyhcMHEe1"
# 注意,"" 是必需的,否则 $... 被视为包含文件名。
# $1$qwer$CHFTUFGqkjue9HyhcMHEe1 是 MD5 加密格式的 'test' 密码。
# users $/usr/local/etc/3proxy/passwd
# 这个例子展示了如何包含密码文件。对于包含的文件,
# <CR> 和 <LF> 被视为字段分隔符。
# daemon
# 现在我们将不再依赖任何控制台(守护进程化)。daemon 必须在 *nix 上给出
# 任何重要命令之前。
service
# 在 NT 下如果希望 3proxy 作为服务启动,则 service 是必需的。
# log /var/log/3proxy/log D
log c:\3proxy\logs\3proxy.log D
# log 允许指定日志文件位置和轮换,D 表示日志文件每天创建一次。
# logformat "L%d-%m-%Y %H:%M:%S %z %N.%p %E %U %C:%c %R:%r %O %I %h %T"
# logformat "Linsert into log (l_date, l_user, l_service, l_in, l_out, l_descr) values ('%d-%m-%Y %H:%M:%S', '%U', '%N', %I, %O, '%T')"
# 兼容 Squid access.log:
#
# "- +_G%t.%. %D %C TCP_MISS/200 %I %1-1T %2-2T %U DIRECT/%R application/unknown"
# 或者,更兼容的格式没有 %D
# "- +_G%t.%. 1 %C TCP_MISS/200 %I %1-1T %2-2T %U DIRECT/%R application/unknown"
#
# 兼容 ISA 2000 代理 WEBEXTD.LOG(字段用 TAB 分隔):
#
# "- + L%C %U Unknown Y %Y-%m-%d %H:%M:%S w3proxy 3PROXY - %n %R %r %D %O %I http TCP %1-1T %2-2T - - %E - - -"
#
# 兼容 ISA 2004 代理 WEB.w3c
#
# "- + L%C %U Unknown %Y-%m-%d %H:%M:%S 3PROXY - %n %R %r %D %O %I http %1-1T %2-2T - %E - - Internal External 0x0 Allowed"
#
# 兼容 ISA 2000/2004 防火墙 FWSEXTD.log(字段用 TAB 分隔):
#
# "- + L%C %U unnknown:0:0.0 N %Y-%m-%d %H:%M:%S fwsrv 3PROXY - %n %R %r %D %O %I %r TCP Connect - - - %E - - - - -"
#
# 兼容 HTTPD 标准日志(Apache 和其他):
#
# "-""+_L%C - %U [%d/%o/%Y:%H:%M:%S %z] ""%T"" %E %I"
# 或者更兼容的格式没有错误代码
# "-""+_L%C - %U [%d/%o/%Y:%H:%M:%S %z] ""%T"" 200 %I"
# 在日志文件中,我们希望用下划线代替空格。
logformat "- +_L%t.%. %N.%p %E %U %C:%c %R:%r %O %I %h %T"
# archiver gz /bin/gzip %F
# archiver zip zip -m -qq %A %F
# archiver zip pkzipc -add -silent -move %A %F
archiver rar rar a -df -inul %A %F
# 如果指定了压缩器,日志文件将在关闭后被压缩。
# 你应该指定扩展名、路径到压缩器和命令行,%A 将被替换为存档文件名,%f - 原始文件名。
# 原始文件不会被删除,因此压缩器应处理它。
rotate 30
# 我们将保留最后 30 个日志文件。
auth iponly
# auth nbname
# auth strong
# auth 指定用户身份验证类型。如果你指定 none,代理不会做任何事情来检查用户名。
# 如果你指定 nbname,代理会向客户端的 UDP/137 发送 NetBIOS 名称请求包并解析
# messanger 服务的 NetBIOS 名称。
# Strong 意味着代理将检查密码。对于强身份验证,未知用户将不允许使用代理,无论 ACL 如何。
# 如果你不想检查用户名但希望 ACL 生效,你应该指定 auth iponly。
# allow ADMINISTRATOR,root
# allow * 127.0.0.1,192.168.1.1 * *
# parent 1000 http 192.168.1.2 80 * * * 80
# allow * 192.168.1.0/24 * 25,53,110,20-21,1024-65535
# 如果用户名匹配 ADMINISTRATOR 或 root,或者客户端 IP 是 127.0.0.1 或 192.168.1.1,
# 我们将允许一切。否则,我们将重定向任何对端口 80 的请求到我们的 Web 服务器 192.168.0.2。
# 我们将允许从网络 192.168.1.0/24 到 SMTP、POP3、FTP、DNS 和非特权端口的任何出站连接。
# 注意,redirect 也可以与代理或 portmapper 一起使用。它允许你为不同的客户端重定向请求到不同的端口或不同的服务器。
# 共享互联网访问
external 10.1.1.1
# external 是 3proxy 用于出站连接的地址。0.0.0.0 表示任何接口。使用 0.0.0.0 不好,因为它允许连接到 127.0.0.1。
internal 192.168.1.1
# internal 是代理监听传入请求的接口地址。127.0.0.1 表示只有本地主机才能使用此代理。这是你应该为客户端指定的代理 IP。
# 你可以使用 0.0.0.0,但你不应该这样做,因为这样可能会导致你的网络中出现开放代理。
auth none
# 不需要身份验证。
dnspr
# dnsproxy 监听 UDP/53 以回答客户端的 DNS 请求。它需要 nserver/nscache 配置。
# external $./external.ip
# internal $./internal.ip
# 这只是提供外部和内部地址的另一种形式,允许你从文件中读取这些地址。
auth strong
# 我们想保护内部接口。
deny * * 127.0.0.1,192.168.1.1
# 并允许 HTTP 和 HTTPS 流量。
allow * * * 80-88,8080-8088 HTTP
allow * * * 443,8443 HTTPS
proxy -n
auth none
# pop3p 将在没有任何身份验证的情况下使用。这不是一个好的选择,
# 因为可以使用 pop3p 访问任何端口。
pop3p
tcppm 25 mail.my.provider 25
# udppm -s 53 ns.my.provider 53
# 我们可以将端口 TCP/25 映射到提供商的 SMTP 服务器,并将 UDP/53 映射到提供商的 DNS。
# 现在我们可以使用我们的代理作为 SMTP 和 DNS 服务器。
# -s 开关用于 UDP 表示“单包”服务 - 而不是设置一段时间的关联,只会在 1 个数据包上设置关联。
# 对于像 DNS 这样的服务非常有用,但对于一些大规模的服务(如多媒体流或在线游戏)则不然。
auth strong
flush
allow 3APA3A,test
maxconn 20
socks
# 对于 socks,我们将使用密码身份验证和不同的访问控制 -
# 我们刷新先前配置的 ACL 列表并创建一个新的列表,以允许用户 test 和 3APA3A 从任何位置连接。
auth strong
flush
internal 127.0.0.1
allow 3APA3A 127.0.0.1
maxconn 3
admin
# 仅允许用户 3APA3A 从 127.0.0.1 地址通过 127.0.0.1 地址访问管理界面。
# 将外部 80 和 443 端口映射到内部 Web 服务器。
# 下面的例子展示了如何使用 3proxy 在内部网络中发布 Web 服务器到互联网。
# 我们必须切换内部和外部地址并刷新任何 ACL。
# auth none
# flush
# external $./internal.ip
# internal $./external.ip
# maxconn 300
# tcppm 80 websrv 80
# tcppm 443 websrv 443
# chroot /usr/local/jail
# setgid 65535
# setuid 65535
# 现在我们不需要任何 root 权限。我们可以 chroot并设置 setgid/setuid。
最后总结
该工具本身没有问题,但是没办法。像我们经常使用的FRP也是会报毒。大家自行斟酌吧!