Scientific Internet access - build SS server
Scientific Internet access - build SS server in Centos 6
This essay isa backup, don't publish and don't wide spreadly, just for my self.
For formatting compatibility, I chose the markdown syntax.
By the way, I refer to many articles/blogs on the Internet, but here I don't list them, for the reason mang people know. Thanks them very much.
Buy the VPS
- notice: is vps(Virtual Private Server), not other!
- you can use ssh to conncet it
- local overseas, better to choose some place with high speed/good line.
- choose service provider what you want/like, here don't recommend.
- make sure the ip address can connect.
- ping it
choose Centos 6 x86 bbr !!!bbr is a the Google Inc. optimization of acceleration
- it seems that ubuntu 18.04 x86_64 wiil work, too.
SSH connect vps
- make sure you username and password
- after buying the vps, change password(always random string at first, so you should change it) which you can remember.
- here, password is not what you sign in service provider, is your vps's password, in other word, it like a password of a computer.
- ssh connect it
- better the root user
ssh -p [port] username@ip_addr, by default,ssh username@ip_addr, then will enter the password which is mentioned before.(by default, ssh port is 22)
Install SS-Python
yum install wget(maybe option)cd /path/to/you/want(option)- command
wget --no-check-certificate -O ***.sh https://raw.githubusercontent.com/teddysun/***_install/master/***.sh
chmod +x ***.sh
./***.sh 2>&1 | tee ***.log - password(ss-server)-->port(1-65535)-->cipher
- use ipv6, modify
/etc/***.json:"server":"::"and/etc/init.d/*** restart- notice: it seem that
adoesn't work inviorigin, useibest!
- notice: it seem that
- can ss-Python, ss-R, etc. have scripts.
appendix
#!/usr/bin/env bash
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
export PATH
#=================================================================#
# System Required: CentOS 6+, Debian 7+, Ubuntu 12+ #
# Description: One click Install ***-Python server #
# Author: Teddysun <i@teddysun.com> #
# Thanks: @clowwindy <https://twitter.com/clowwindy> #
# Intro: https://teddysun.com/342.html #
#=================================================================#
clear
echo
echo "#############################################################"
echo "# One click Install ***-Python server #"
echo "# Intro: https://teddysun.com/342.html #"
echo "# Author: Teddysun <i@teddysun.com> #"
echo "# Github: https://github.com/***/*** #"
echo "#############################################################"
echo
libsodium_file="libsodium-1.0.17"
libsodium_url="https://github.com/jedisct1/libsodium/releases/download/1.0.17/libsodium-1.0.17.tar.gz"
# Current folder
cur_dir=`pwd`
# Stream Ciphers
ciphers=(
aes-256-gcm
aes-192-gcm
aes-128-gcm
aes-256-ctr
aes-192-ctr
aes-128-ctr
aes-256-cfb
aes-192-cfb
aes-128-cfb
camellia-128-cfb
camellia-192-cfb
camellia-256-cfb
chacha20-ietf-poly1305
chacha20-ietf
chacha20
rc4-md5
)
# Color
red='\033[0;31m'
green='\033[0;32m'
yellow='\033[0;33m'
plain='\033[0m'
# Make sure only root can run our script
[[ $EUID -ne 0 ]] && echo -e "[${red}Error${plain}] This script must be run as root!" && exit 1
# Disable selinux
disable_selinux(){
if [ -s /etc/selinux/config ] && grep 'SELINUX=enforcing' /etc/selinux/config; then
sed -i 's/SELINUX=enforcing/SELINUX=disabled/g' /etc/selinux/config
setenforce 0
fi
}
#Check system
check_sys(){
local checkType=$1
local value=$2
local release=''
local systemPackage=''
if [[ -f /etc/redhat-release ]]; then
release="centos"
systemPackage="yum"
elif grep -Eqi "debian|raspbian" /etc/issue; then
release="debian"
systemPackage="apt"
elif grep -Eqi "ubuntu" /etc/issue; then
release="ubuntu"
systemPackage="apt"
elif grep -Eqi "centos|red hat|redhat" /etc/issue; then
release="centos"
systemPackage="yum"
elif grep -Eqi "debian|raspbian" /proc/version; then
release="debian"
systemPackage="apt"
elif grep -Eqi "ubuntu" /proc/version; then
release="ubuntu"
systemPackage="apt"
elif grep -Eqi "centos|red hat|redhat" /proc/version; then
release="centos"
systemPackage="yum"
fi
if [[ "${checkType}" == "sysRelease" ]]; then
if [ "${value}" == "${release}" ]; then
return 0
else
return 1
fi
elif [[ "${checkType}" == "packageManager" ]]; then
if [ "${value}" == "${systemPackage}" ]; then
return 0
else
return 1
fi
fi
}
# Get version
getversion(){
if [[ -s /etc/redhat-release ]]; then
grep -oE "[0-9.]+" /etc/redhat-release
else
grep -oE "[0-9.]+" /etc/issue
fi
}
# CentOS version
centosversion(){
if check_sys sysRelease centos; then
local code=$1
local version="$(getversion)"
local main_ver=${version%%.*}
if [ "$main_ver" == "$code" ]; then
return 0
else
return 1
fi
else
return 1
fi
}
# Get public IP address
get_ip(){
local IP=$( ip addr | egrep -o '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' | egrep -v "^192\.168|^172\.1[6-9]\.|^172\.2[0-9]\.|^172\.3[0-2]\.|^10\.|^127\.|^255\.|^0\." | head -n 1 )
[ -z ${IP} ] && IP=$( wget -qO- -t1 -T2 ipv4.icanhazip.com )
[ -z ${IP} ] && IP=$( wget -qO- -t1 -T2 ipinfo.io/ip )
[ ! -z ${IP} ] && echo ${IP} || echo
}
get_char(){
SAVEDSTTY=`stty -g`
stty -echo
stty cbreak
dd if=/dev/tty bs=1 count=1 2> /dev/null
stty -raw
stty echo
stty $SAVEDSTTY
}
# Pre-installation settings
pre_install(){
if check_sys packageManager yum || check_sys packageManager apt; then
# Not support CentOS 5
if centosversion 5; then
echo -e "$[{red}Error${plain}] Not supported CentOS 5, please change to CentOS 6+/Debian 7+/Ubuntu 12+ and try again."
exit 1
fi
else
echo -e "[${red}Error${plain}] Your OS is not supported. please change OS to CentOS/Debian/Ubuntu and try again."
exit 1
fi
# Set *** config password
echo "Please enter password for ***-python"
read -p "(Default password: teddysun.com):" ***
[ -z "${***}" ] && ***="teddysun.com"
echo
echo "---------------------------"
echo "password = ${***}"
echo "---------------------------"
echo
# Set *** config port
while true
do
dport=$(shuf -i 9000-19999 -n 1)
echo "Please enter a port for ***-python [1-65535]"
read -p "(Default port: ${dport}):" ***
[ -z "$***" ] && ***=${dport}
expr ${***} + 1 &>/dev/null
if [ $? -eq 0 ]; then
if [ ${***} -ge 1 ] && [ ${***} -le 65535 ] && [ ${***:0:1} != 0 ]; then
echo
echo "---------------------------"
echo "port = ${***}"
echo "---------------------------"
echo
break
fi
fi
echo -e "[${red}Error${plain}] Please enter a correct number [1-65535]"
done
# Set *** config stream ciphers
while true
do
echo -e "Please select stream cipher for ***-python:"
for ((i=1;i<=${#ciphers[@]};i++ )); do
hint="${ciphers[$i-1]}"
echo -e "${green}${i}${plain}) ${hint}"
done
read -p "Which cipher you'd select(Default: ${ciphers[0]}):" pick
[ -z "$pick" ] && pick=1
expr ${pick} + 1 &>/dev/null
if [ $? -ne 0 ]; then
echo -e "[${red}Error${plain}] Please enter a number"
continue
fi
if [[ "$pick" -lt 1 || "$pick" -gt ${#ciphers[@]} ]]; then
echo -e "[${red}Error${plain}] Please enter a number between 1 and ${#ciphers[@]}"
continue
fi
***=${ciphers[$pick-1]}
echo
echo "---------------------------"
echo "cipher = ${***}"
echo "---------------------------"
echo
break
done
echo
echo "Press any key to start...or Press Ctrl+C to cancel"
char=`get_char`
# Install necessary dependencies
if check_sys packageManager yum; then
yum install -y python python-devel python-setuptools openssl openssl-devel curl wget unzip gcc automake autoconf make libtool
elif check_sys packageManager apt; then
apt-get -y update
apt-get -y install python python-dev python-setuptools openssl libssl-dev curl wget unzip gcc automake autoconf make libtool
fi
cd ${cur_dir}
}
# Download files
download_files(){
# Download libsodium file
if ! wget --no-check-certificate -O ${libsodium_file}.tar.gz ${libsodium_url}; then
echo -e "[${red}Error${plain}] Failed to download ${libsodium_file}.tar.gz!"
exit 1
fi
# Download *** file
if ! wget --no-check-certificate -O ***-master.zip https://github.com/***/***/archive/master.zip; then
echo -e "[${red}Error${plain}] Failed to download *** python file!"
exit 1
fi
# Download *** init script
if check_sys packageManager yum; then
if ! wget --no-check-certificate https://raw.githubusercontent.com/teddysun/***_install/master/*** -O /etc/init.d/***; then
echo -e "[${red}Error${plain}] Failed to download *** chkconfig file!"
exit 1
fi
elif check_sys packageManager apt; then
if ! wget --no-check-certificate https://raw.githubusercontent.com/teddysun/***_install/master/***-debian -O /etc/init.d/***; then
echo -e "[${red}Error${plain}] Failed to download *** chkconfig file!"
exit 1
fi
fi
}
# Config ***
config_***(){
cat > /etc/***.json<<-EOF
{
"server":"0.0.0.0",
"server_port":${***},
"local_address":"127.0.0.1",
"local_port":1080,
"password":"${***}",
"timeout":300,
"method":"${***}",
"fast_open":false
}
EOF
}
# Firewall set
firewall_set(){
echo -e "[${green}Info${plain}] firewall set start..."
if centosversion 6; then
/etc/init.d/iptables status > /dev/null 2>&1
if [ $? -eq 0 ]; then
iptables -L -n | grep -i ${***} > /dev/null 2>&1
if [ $? -ne 0 ]; then
iptables -I INPUT -m state --state NEW -m tcp -p tcp --dport ${***} -j ACCEPT
iptables -I INPUT -m state --state NEW -m udp -p udp --dport ${***} -j ACCEPT
/etc/init.d/iptables save
/etc/init.d/iptables restart
else
echo -e "[${green}Info${plain}] port ${***} has already been set up."
fi
else
echo -e "[${yellow}Warning${plain}] iptables looks like shutdown or not installed, please manually set it if necessary."
fi
elif centosversion 7; then
systemctl status firewalld > /dev/null 2>&1
if [ $? -eq 0 ]; then
default_zone=$(firewall-cmd --get-default-zone)
firewall-cmd --permanent --zone=${default_zone} --add-port=${***}/tcp
firewall-cmd --permanent --zone=${default_zone} --add-port=${***}/udp
firewall-cmd --reload
else
echo -e "[${yellow}Warning${plain}] firewalld looks like not running or not installed, please enable port ${***} manually if necessary."
fi
fi
echo -e "[${green}Info${plain}] firewall set completed..."
}
# Install ***
install(){
# Install libsodium
if [ ! -f /usr/lib/libsodium.a ]; then
cd ${cur_dir}
tar zxf ${libsodium_file}.tar.gz
cd ${libsodium_file}
./configure --prefix=/usr && make && make install
if [ $? -ne 0 ]; then
echo -e "[${red}Error${plain}] libsodium install failed!"
install_cleanup
exit 1
fi
fi
ldconfig
# Install ***
cd ${cur_dir}
unzip -q ***-master.zip
if [ $? -ne 0 ];then
echo -e "[${red}Error${plain}] unzip ***-master.zip failed! please check unzip command."
install_cleanup
exit 1
fi
cd ${cur_dir}/***-master
python setup.py install --record /usr/local/***_install.log
if [ -f /usr/bin/ssserver ] || [ -f /usr/local/bin/ssserver ]; then
chmod +x /etc/init.d/***
if check_sys packageManager yum; then
chkconfig --add ***
chkconfig *** on
elif check_sys packageManager apt; then
update-rc.d -f *** defaults
fi
/etc/init.d/*** start
else
echo
echo -e "[${red}Error${plain}] *** install failed! please visit https://teddysun.com/342.html and contact."
install_cleanup
exit 1
fi
clear
echo
echo -e "Congratulations, ***-python server install completed!"
echo -e "Your Server IP : \033[41;37m $(get_ip) \033[0m"
echo -e "Your Server Port : \033[41;37m ${***} \033[0m"
echo -e "Your Password : \033[41;37m ${***} \033[0m"
echo -e "Your Encryption Method: \033[41;37m ${***} \033[0m"
echo
echo "Welcome to visit:https://teddysun.com/342.html"
echo "Enjoy it!"
echo
}
# Install cleanup
install_cleanup(){
cd ${cur_dir}
rm -rf ***-master.zip ***-master ${libsodium_file}.tar.gz ${libsodium_file}
}
# Uninstall ***
uninstall_***(){
printf "Are you sure uninstall ***? (y/n) "
printf "\n"
read -p "(Default: n):" answer
[ -z ${answer} ] && answer="n"
if [ "${answer}" == "y" ] || [ "${answer}" == "Y" ]; then
ps -ef | grep -v grep | grep -i "ssserver" > /dev/null 2>&1
if [ $? -eq 0 ]; then
/etc/init.d/*** stop
fi
if check_sys packageManager yum; then
chkconfig --del ***
elif check_sys packageManager apt; then
update-rc.d -f *** remove
fi
# delete config file
rm -f /etc/***.json
rm -f /var/run/***.pid
rm -f /etc/init.d/***
rm -f /var/log/***.log
if [ -f /usr/local/***_install.log ]; then
cat /usr/local/***_install.log | xargs rm -rf
fi
echo "*** uninstall success!"
else
echo
echo "uninstall cancelled, nothing to do..."
echo
fi
}
# Install ***-python
install_***(){
disable_selinux
pre_install
download_files
config_***
if check_sys packageManager yum; then
firewall_set
fi
install
install_cleanup
}
# Initialization step
action=$1
[ -z $1 ] && action=install
case "$action" in
install|uninstall)
${action}_***
;;
*)
echo "Arguments error! [${action}]"
echo "Usage: `basename $0` [install|uninstall]"
;;
esac
浙公网安备 33010602011771号