å 容
- ã¯ããã«
- æ§æåŸã«ããã¯ããã€ãã¹ããã«ã¯ã©ãããã°ããã§ããïŒ
- åäœåç
- Padavanã«ãŒã¿ãŒã®æ§æ
- Keenetic OSã䜿çšããã«ãŒã¿ãŒã®æ§æ
- æ§æåŸã®ãšã©ãŒã蚺æããããã®åºæ¬çãªæ¹æ³
- ãããã€ããŒã«ããDNSã¯ãšãªã®ãã£ã«ã¿ãªã³ã°ã®è¿œå ãã€ãã¹
ã¯ããã«
çŽ2幎éã Zolg ããã¯ãã€ãã¹ ãªãã·ã§ã³ã䜿çšããŸãã ã ãããã¯ãŒã¯äžã®å€ãã®æ瀺ã¯ããã«åºã¥ããŠããŸãã ç§ãå«ãã
ãã¹ãŠãè¯ãã£ããããæé«ã¯åžžã«åã®æµã§ãããã ãŸããããã€ãã®æ°ããããã°ã©ã ã¯ãã¹ããŒããã«ãªããããŠãããã«ãŒã¿ãŒã®DNSãµãŒããŒããã€ãã¹ããŠãç¬èªã®æ¹æ³ã䜿çšããŠãã¡ã€ã³ã解決ããŸãã ããã«ãããã«ãŒã¿ãŒäžã®dnsmasqãããã¯è§£é€ã®ããã«ipsetã»ããã«ã¢ãã¬ã¹ãè¿œå ã§ããªããªããè«ççãªçµæãåŸãããŸã-ãªãœãŒã¹ã¯ããã¯ããããŸãŸã§ãã Android 9ã§ã¯ãDNS-over-TLSã®ãã€ãã£ããµããŒããã€ãŸã ããã¯ããã€ãã¹ãããã®æ¹æ³ã¯ãåäœãåæ¢ããŸãïŒä»ã®ããã€ã¹ã以åã«dnsmasqã«ã¢ã¯ã»ã¹ããããšããªãå ŽåïŒã 次ã«ããã¡ã€ã³ã®ãªã¹ãå šäœãantizapretããæŽæ°ãããšãæ¯åäºæž¬ã§ããªãçµæãçããŸãã ãªã¹ãã«ã¯ãå®éã«ãããã¯ãããŠããªããã¡ã€ã³ãå«ãŸããŠããå Žåãããããã®ãã¡ã€ã³ã®æäœã¯ã¡ã€ã³ãã£ãã«ãéããŠéèŠã§ãã åžžã«æ³šæãæããçæããããã¡ã€ã«ãæã§ç·šéããå¿ èŠããããŸãã 第äžã«ãäœäžãã®ã«ãžããªã©ã®èšå€§ãªãã¡ã€ã³ã®ãªã¹ãããæã¡æ©ããããšã«é£œã飜ãããŠããŸãã æéãçµã€ã«ã€ããŠããããã¯ããããªãœãŒã¹ã®å°ããªç¹å®ã®ãªã¹ãã ããå¿ èŠã§ããããšã«æ°ä»ããŸããã
ã ãã1幎éãç§ã¯å°ãä¿®æ£ãããããã¯è§£é€æ¹æ³ã䜿çšããŠããŸããããç§ã¯å®å šã«æºè¶³ããŠããŸãïŒ
- ã·ã³ãã«ããšå¶åŸ¡ã®å®¹æãïŒæ§æåŸïŒã
- ããã¯è§£é€ããå¿ èŠããããªãœãŒã¹ãå®å šã«å¶åŸ¡ããŸãã
- ããã»ããµãªãœãŒã¹ãšã«ãŒã¿ãŒRAMã®æå°èŠä»¶ã
- ããã¯ããã€ãã¹ããéã®åŸ®åŠãªãã¥ã¢ã³ã¹ãå¹ åºãã«ããŒã
ç§ã®ãªãã·ã§ã³ã¯ãæ°çŸããã³æ°åã®ãã¡ã€ã³ã®ããã¯ã解é€ããå¿ èŠãããå Žåãæ³å®ããŠããªãããšã«æ³šæããããšãéèŠã§ãã ã«ãŒã¿ãŒãèµ·åãããšãæå®ããããªã¹ãã®åãã¡ã€ã³ã解決ãããããã§ãã ãªã¹ãå ã®ãã¡ã€ã³ãå€ãã»ã©ãããã¯è§£é€ããå€ãã®ipsetã®åæåãé·ããªããŸãã
ããã¯ããã€ãã¹ããããã®åºæ¬ã¯åãã§ã-Torãããã¯ãŒã¯ã ãã®äœ¿çšã¯2ã€ã®åçŽãªèŠå ã«ãããã®ã§ã-ç¡æãããã³VPNãµãŒãã¹ãšã¯ç°ãªãããã·ã¢ã§Torããããã¯ãããå¯èœæ§ã¯ãŒãã«è¿ãã§ãã Torã¯ããã·ã¢ã®éº»è¬å¯å£²ã®åºç€ã§ãããäžéšããæäžéšã«è³ããŸã§ã§ãã Torããã¯ã¯ãåžå Žåãã®æ°ããããŒã«ã®æ€çŽ¢ãšå¿åæ§ã®äœäžã«ã€ãªããããã®çµæãå°å ã®æ³å·è¡æ©é¢ã®æŽ»åãæ£åžžã«æŽ»æ§åãããŸãã æçµçã«ãããã¯ãŠã€ã«ã¹ã®ããã«ãäžäœãªã³ã¯ã«æªåœ±é¿ãåãŒãå§ããŸãã æ¿åºé«å®ãšãã·ã¢ãžã®äžççãªéº»è¬å¯èŒžãšã®é¢ä¿ã«é¢ããææ°ã®é©ãã¹ããã¥ãŒã¹ãèãããšããã·ã¢ã§ã®Torã®åŠšå®³ã¯äºçŽ°ãªããšã§ããã«ãé¢ããããåãªãã¿ããŒã§ãã Roskomnadzorãããã®éšéã«äœååãå²ãåœãŠãããŠããŠãããã·ã¢ã®åäžã®è£å€æã¯Torããããã¯ããèš±å¯ããäžãããæã£ãŠããŸããã ãããŠããã·ã¢ã¯åã«éº»è¬ã«ownããŠããã«ãé¢ãããã誰ãé©ãããããæãããããããŸããïŒå°åŠçã¯äœãããããšããŠããã®ããç¥ã£ãŠããŸããã©ããªéã§ã-人çã®ãã®ãããªéªæªãªçå®ïŒã çŸåšã®ã¢ãŒãã§ã¯ãTorãããã¯ãŒã¯ããããã¯ãã確çã¯ããšã«ãã¿ãŒãžã¥çŸè¡é€šãµã€ãããããã¯ãã確çãããäœããªã£ãŠããŸãã
èšèŒãããŠããæé ã¯ãOpenWrtã䜿çšããã«ãŒã¿ãŒã«ç°¡åã«é©å¿ã§ããŸãã ãŸããå°ããªå€æŽã«ãããTorãOpenVPNã«ç°¡åã«çœ®ãæããããšãã§ããŸãã
æ§æåŸã«ããã¯ããã€ãã¹ããã«ã¯ã©ãããã°ããã§ããïŒ
ãã¹ãŠãéåžžã«ç°¡åã§ãã ãã¡ã€ã«/opt/etc/unblock.txtããããŸã-ããã¯ã解é€ããç°¡åãªãªã¹ãã§ãã ãã¡ã€ã³ãIPã¢ãã¬ã¹ãã¢ãã¬ã¹ç¯å²ããŸãã¯CIDRã®ããã¯ã解é€ã§ããŸãã 1è¡-1èŠçŽ ã 空ã®è¡ã¯èš±å¯ãããŸãããè¡ã®å é ã«ïŒæåã䜿çšããŠç¡èŠã§ããŸãã
ãããç§ã®å人çšãã¡ã€ã«ã®äŸã§ã
###- rutracker.org rutor.info rutor.is mega-tor.org kinozal.tv nnm-club.me nnm-club.ws tfile.me tfile-home.org tfile1.cc megatfile.cc megapeer.org megapeer.ru tapochek.net tparser.org tparser.me rustorka.com uniongang.tv fast-torrent.ru ### rezka.ag hdrezka.ag hdrezka.me filmix.co filmix.cc seasonvar.ru ### lib.rus.ec flibusta.is flibs.me flisland.net flibusta.site ### telegram.org tdesktop.com tdesktop.org tdesktop.info tdesktop.net telesco.pe telegram.dog telegram.me t.me telegra.ph web.telegram.org desktop.telegram.org updates.tdesktop.com venus.web.telegram.org flora.web.telegram.org vesta.web.telegram.org pluto.web.telegram.org aurora.web.telegram.org 149.154.160.0/20 91.108.4.0/22 91.108.8.0/22 91.108.12.0/22 91.108.16.0/22 91.108.56.0/22 109.239.140.0/24 67.198.55.0/24 ### 7-zip.org edem.tv 4pna.com 2019.vote ### Tor check.torproject.org ### IP ( # ) #195.82.146.214 ### CIDR ( # ) #103.21.244.0/22 ### ( # ) #100.100.100.200-100.100.100.210
ãã®ãã¡ã€ã«ãç·šéããããã³ãã³ããå®è¡ããŠæ°ããæ§æãé©çšããã ãã§ãã
unblock_update.sh
unblock.txtã®ãã¹ãŠã®ãªãœãŒã¹ã¯ãã«ãŒã¿ãŒãåèµ·åããããšãªãããã¯è§£é€ãããŸãã
åäœåç
- ã«ãŒã¿ãŒãåæåããããšãunblockãšããååã®ç©ºã®ipset IPã¢ãã¬ã¹ã®ã»ãããäœæãããŸãã
- å®å ã®ãã¹ãŠã®ãã±ããããããã¯è§£é€ããTorãµãŒãã¹ã«ãªãã€ã¬ã¯ãããã«ãŒã«ããã¡ã€ã¢ãŠã©ãŒã«ã«è¿œå ãããŸãã
- TorãµãŒãã¹ã¯ãééãããã·ã¢ãŒãã§éå§ãããŸãã
- ç¹å¥ãªã¹ã¯ãªããunblock_ipset.shãèµ·åãããunblock.txtãããã¹ãŠã®ãã¡ã€ã³ã解決ããããããã®IPã¢ãã¬ã¹ããããã¯è§£é€ã»ããã«è¿œå ãããŸãã ãã®ãã¡ã€ã«ã®IPã¢ãã¬ã¹ãç¯å²ãããã³CIDRããããã¯è§£é€ã«è¿œå ãããŸãã
- Dnsmasqã¯ãè¿œå ã®æ§æãã¡ã€ã«unblock.dnsmasqã䜿çšããŠèµ·åãããŸããããã¯ã解決æã«unblock.txtããunblockã»ããã«ãã¡ã€ã³IPã¢ãã¬ã¹ãè¿œå ããããšã瀺ããŸãã
- cronã¯ãç¹å®ã®é »åºŠã§unblock_ipset.shãå®è¡ãããã¥ã¢ã³ã¹ã®å¯èœæ§ã®ããã±ãŒã¹ãéšåçã«è£æ£ããŸãã
- å¿ èŠã«å¿ããŠããããã€ããŒãDNSããã£ã«ã¿ãªã³ã°ãããšãunblock.txtã®ãã¹ãŠã®ãã¡ã€ã³ïŒããã³ãããã®ã¿ïŒãdnscrypt-proxyãä»ããŠè§£æ±ºãããŸãã
Padavanã«ãŒã¿ãŒã®æ§æ
Padavanãã¡ãŒã ãŠã§ã¢ãã€ã³ã¹ããŒã«ãããã«ãŒã¿ãŒãšãæ§ææžã¿ã®Entwareããã±ãŒãžãããŒãžã£ãŒãå¿ èŠã§ãã Windowsã§ã¯ã PuTTYã¯ã©ã€ã¢ã³ãã䜿çšããŠãSSHçµç±ã§ã«ãŒã¿ãŒã«æ¥ç¶ã§ããŸãã
å€ãEntware-ngã§ã¯ãªããEntwareã䜿çšããŠããããšã確èªããŠãã ããã / opt / var / opkg-listsãã©ã«ããŒã®å 容ã衚瀺ããŸãã entwareãŸãã¯entware-ngãã¡ã€ã«ããããŸãã 2çªç®ã®ã±ãŒã¹ã§ã¯ãã«ãŒã¿ãŒã®Padavanãã¡ãŒã ãŠã§ã¢ãææ°ããŒãžã§ã³ã«æŽæ°ããEntwareããã±ãŒãžãããŒãžã£ãŒãåã€ã³ã¹ããŒã«ããå¿ èŠããããŸãã ãã®åŸãã¹ããããã€ã¹ãããã®æé ã«é²ã¿ãŸãã
ã¬ãã¥ãŒã瀺ããããã«ãäž»ã«ã«ãŒã¿ãŒã®å éšã¡ã¢ãªã§åæèšå®ãæ£ãããªãïŒã€ãŸããinit.dããã®ã¹ã¯ãªãããããŒããããŠããªãïŒäººã ã Xiaomi Mi Router 3ãŸãã¯3Gããæã¡ã§ãå éšã¡ã¢ãªã®Entwareãæ£ããåäœãããã©ããäžæãªå ŽåïŒèªåèµ·åïŒããã¹ãŠãå床ã»ããã¢ããããŸãã ããã¡ããŠã¹ãåããŸãã ã¹ã¯ãªãããæŽæ°ããŸãïŒ1ïŒã ãœãŒã¹ã³ãŒããæŽæ°ããŸãïŒ2ïŒã ææ°ã®ãã¡ãŒã ãŠã§ã¢ãåéããŠãã©ãã·ã¥ããŸãïŒ4ïŒã ãã¡ãŒã ãŠã§ã¢èšå®ããªã»ããããŸãïŒNVRAMããã³ãã¡ã€ã«ã¹ãã¬ãŒãžïŒ-[詳现èšå®]> [管ç]> [èšå®]ã ã«ãŒã¿ãŒã§ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãæ§æããSSHãæå¹ã«ããŸãã PROMETHEUS Firmware> RWFS Formattingã§å®è¡ããŸãã ã詳现ã>ã管çã>ãèšå®ã>ãR / Wã»ã¯ã·ã§ã³ã§ãã¡ã€ã«ã·ã¹ãã ãããŠã³ãã>ãUBIFSããéžæããŸãã ã«ãŒã¿ãŒãåèµ·åããŸãã å éšã¡ã¢ãªããã®çŸåšã®Entwareèµ·åã¹ã¯ãªããã¯ãã¹ãŠèªåçã«ç»é²ããããã¹ãŠãæèšã®ããã«æ©èœããŸãã
ãã¹ãã®ããã«ãææ°ã®ãã¡ãŒã ãŠã§ã¢-32a93dbãåããäžè¬çãªXiaomi Mi Router 3GïŒEntwareã¯å éšã¡ã¢ãªã«ã€ã³ã¹ããŒã«ãããŠããŸãïŒã䜿çšããŸããã äŒèª¬ã®èµ€ã¡ããWT3020 AD / F / Hã§ã10ãã«ã§ãã¹ãŠãæ©èœããŸãã
1.ã«ãŒã¿ãŒã«å¿ èŠãªãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ãã
opkg update opkg install mc tor tor-geoip bind-dig cron
mc-çå€äžã®åžä»€å®ãã¡ã€ã«ãããŒãžã£ãŒã 䟿å©ãªmceditãšãã£ã¿ãŒã®ããã ãã«å¿ èŠã§ãã å¥ã®ããã¹ããšãã£ã¿ã®äœ¿çšã«æ £ããŠããå Žåã¯ãmcãã€ã³ã¹ããŒã«ã§ããŸããã
tor -TorãµãŒãã¹ã
tor-geoip -Torã®geo-IPããŒã¿ããŒã¹ã
bind-dig -DNSã¯ã©ã€ã¢ã³ãïŒnslookupãšãã¹ãã®ã¢ããã°ïŒã
cron-ã¿ã¹ã¯ã¹ã±ãžã¥ãŒã©ã
2. ipsetãåæåããè€æ°ã®ãããã¯è§£é€IPã¢ãã¬ã¹ãäœæããŸãïŒstart_script.shïŒ
å¿ èŠãªã¢ãžã¥ãŒã«ãæ¥ç¶ããã«ãŒã¿ãŒã®èµ·åæã«unblockãšããååã®ç©ºã®ã¢ãã¬ã¹ã»ãããäœæããŸãã ãããè¡ãã«ã¯ããšãã£ã¿ãŒã§/etc/storage/start_script.shãã¡ã€ã«ãéããŸãã
mcedit /etc/storage/start_script.sh
æåŸã«è¿œå ïŒ
modprobe ip_set modprobe ip_set_hash_ip modprobe ip_set_hash_net modprobe ip_set_bitmap_ip modprobe ip_set_list_set modprobe xt_set ipset create unblock hash:net
ãããã¡ãã貌ãä»ããã«ã¯ãShift + Insertã䜿çšããä¿å-F2ãçµäº-F10ã䜿çšããŸãã
å¿ èŠã«å¿ããŠãã«ãŒã¿ãŒã®Webã€ã³ã¿ãŒãã§ã€ã¹ããstart_script.shãã¡ã€ã«ãç·šéã§ããŸã-ã詳现èšå®ã>ãã«ã¹ã¿ãã€ãºã>ãã¹ã¯ãªããã>ãã«ãŒã¿ãŒãåæåããåã«å®è¡ã ç·šéåŸããé©çšããã¯ãªãã¯ããŸãã
3. Torã®ã»ããã¢ãã
Toræ§æãã¡ã€ã«ã®å 容ãåé€ããŸãã
cat /dev/null > /opt/etc/tor/torrc
Toræ§æãã¡ã€ã«ãéããŸãã
mcedit /opt/etc/tor/torrc
å 容ã貌ãä»ãïŒShift + InsertïŒïŒ
User admin PidFile /opt/var/run/tor.pid ExcludeExitNodes {RU},{UA},{AM},{KG},{BY} StrictNodes 1 TransPort 192.168.0.1:9141 ExitRelay 0 ExitPolicy reject *:* ExitPolicy reject6 *:* GeoIPFile /opt/share/tor/geoip GeoIPv6File /opt/share/tor/geoip6 DataDirectory /opt/var/lib/tor
å¿ èŠã«å¿ããŠã 192.168.0.1ãã«ãŒã¿ãŒïŒLANïŒã®å éšã¢ãã¬ã¹ã«çœ®ãæããŸãã ç°¡åãªæ§æã®èª¬æïŒ
- åºåããŒããé€å€ïŒãã·ã¢ããŠã¯ã©ã€ããã¢ã«ã¡ãã¢ãã«ã®ã¹ã¿ã³ããã©ã«ãŒã·ã
- ééãããã·ãã¢ãã¬ã¹192.168.0.1ãããŒã9141ã«æããŸãã
- åºå£ç¹ã§ããããšãæåŠããŸãã
4.ããã¯ããã€ãã¹ããããã®ãã¡ã€ã³ã®ãªã¹ãïŒã ãã§ãªãïŒïŒunblock.txtïŒ
unblock.txtã¯ããã¯ã解é€ããç°¡åãªãªã¹ãã§ãã ãã¡ã€ã³ãIPã¢ãã¬ã¹ãç¯å²ããŸãã¯CIDRã®ããã¯ã解é€ã§ããŸãã 1è¡-1èŠçŽ ã 空è¡ïŒã¹ããŒã¹ãšã¿ããå«ãïŒã¯ç¡èŠãããŸãã è¡ã®å é ã«ïŒæåã䜿çšããŠãç¡èŠããããšãã§ããŸãã
ãã¡ã€ã«/opt/etc/unblock.txtãäœæããŸãã
mcedit /opt/etc/unblock.txt
åè¡ã«ã¯ããã¡ã€ã³åãIPã¢ãã¬ã¹ãç¯å²ããŸãã¯CIDRãå«ããããšãã§ããŸãã ïŒæåã䜿çšããŠãè¡ã«ã³ã¡ã³ããä»ããããšãã§ããŸãã
ãããç§ã®å人çšãã¡ã€ã«ã®äŸã§ã
###- rutracker.org rutor.info rutor.is mega-tor.org kinozal.tv nnm-club.me nnm-club.ws tfile.me tfile-home.org tfile1.cc megatfile.cc megapeer.org megapeer.ru tapochek.net tparser.org tparser.me rustorka.com uniongang.tv fast-torrent.ru ### rezka.ag hdrezka.ag hdrezka.me filmix.co filmix.cc seasonvar.ru ### lib.rus.ec flibusta.is flibs.me flisland.net flibusta.site ### telegram.org tdesktop.com tdesktop.org tdesktop.info tdesktop.net telesco.pe telegram.dog telegram.me t.me telegra.ph web.telegram.org desktop.telegram.org updates.tdesktop.com venus.web.telegram.org flora.web.telegram.org vesta.web.telegram.org pluto.web.telegram.org aurora.web.telegram.org 149.154.160.0/20 91.108.4.0/22 91.108.8.0/22 91.108.12.0/22 91.108.16.0/22 91.108.56.0/22 109.239.140.0/24 67.198.55.0/24 ### 7-zip.org edem.tv 4pna.com 2019.vote ### Tor check.torproject.org ### IP ( # ) #195.82.146.214 ### CIDR ( # ) #103.21.244.0/22 ### ( # ) #100.100.100.200-100.100.100.210
5.ãã¡ã€ã³ã®ç¹å®ã®ãªã¹ãã®ãããã¯è§£é€IPã¢ãã¬ã¹ã®ã»ãããå ¥åããã¹ã¯ãªããïŒunblock_ipset.shïŒ
ã¹ã¯ãªãã/opt/bin/unblock_ipset.shãäœæããŸãã
mcedit /opt/bin/unblock_ipset.sh
å 容ã貌ãä»ãïŒShift + InsertïŒïŒ
#!/bin/sh until ADDRS=$(dig +short google.com @localhost) && [ -n "$ADDRS" ] > /dev/null 2>&1; do sleep 5; done while read line || [ -n "$line" ]; do [ -z "$line" ] && continue [ "${line:0:1}" = "#" ] && continue cidr=$(echo $line | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}/[0-9]{1,2}') if [ ! -z "$cidr" ]; then ipset -exist add unblock $cidr continue fi range=$(echo $line | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}-[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}') if [ ! -z "$range" ]; then ipset -exist add unblock $range continue fi addr=$(echo $line | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}') if [ ! -z "$addr" ]; then ipset -exist add unblock $addr continue fi dig +short $line @localhost | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' | awk '{system("ipset -exist add unblock "$1)}' done < /opt/etc/unblock.txt
å®è¡æš©ãäžããïŒ
chmod +x /opt/bin/unblock_ipset.sh
ã¹ã¯ãªããã¯éåžžã«ã·ã³ãã«ã§ããããäœæ¥ã®æ¬è³ªã§ã... google.comãã¡ã€ã³è§£æ±ºãæ©èœããã®ãåŸ ã£ãŠããŸãïŒãããè¡ãããªãå Žåãã«ãŒã¿ãŒããŸã åæåã®ããã»ã¹ã«ãããããã«ãŒã¿ãŒã®èµ·åæã«å€ãã®ãããã¯è§£é€ãè¡ãããŸããïŒã unblock.txtãã¡ã€ã«ã®è¡ãèªã¿åããŸãã èªã¿åãè¡ã¯ãå é ãšæ«å°Ÿã®ã¹ããŒã¹ãšã¿ããèªåçã«åé€ããŸãã 空ã®è¡ãã¹ãããããŸãã ïŒæåã§å§ãŸãè¡ãã¹ãããããŸãã CIDRã®ã©ã€ã³ãæ¢ããŠããŸãã CIDRãèŠã€ãã£ãããããããããã¯è§£é€ã«è¿œå ããŸãã æååã®ç¯å²ãæ¢ããŠããŸãã èŠã€ãã£ãå Žåã¯ããããã¯è§£é€ã«è¿œå ããŸãã æååã§IPã¢ãã¬ã¹ãæ¢ããŠããŸãã IPãèŠã€ãã£ãå Žåãããããããã¯è§£é€ã«è¿œå ããŸãã æã£ãŠè¡ã解決ããŸãããã çµæã®ãã¹ãŠã®IPã¢ãã¬ã¹ããããã¯è§£é€ã«è¿œå ãããŸãã
6.ãã¡ã€ã³ã®ç¹å®ã®ãªã¹ãããè¿œå ã®dnsmasqæ§æãã¡ã€ã«ãçæããããã®ã¹ã¯ãªããïŒunblock_dnsmasq.shïŒ
ã¹ã¯ãªãã/opt/bin/unblock_dnsmasq.shãäœæããŸãã
mcedit /opt/bin/unblock_dnsmasq.sh
å 容ã貌ãä»ãïŒShift + InsertïŒïŒ
#!/bin/sh cat /dev/null > /opt/etc/unblock.dnsmasq while read line || [ -n "$line" ]; do [ -z "$line" ] && continue [ "${line:0:1}" = "#" ] && continue echo $line | grep -Eq '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' && continue echo "ipset=/$line/unblock" >> /opt/etc/unblock.dnsmasq done < /opt/etc/unblock.txt
å®è¡æš©ãäžããïŒ
chmod +x /opt/bin/unblock_dnsmasq.sh
ã¹ã¯ãªããã¯éåžžã«ã·ã³ãã«ã§ããããäœæ¥ã®æ¬è³ªã§ã... /opt/etc/unblock.txtããé çªã«è¡ãèªã¿åããŸãã èªã¿åãè¡ã¯ãå é ãšæ«å°Ÿã®ã¹ããŒã¹ãšã¿ããèªåçã«åé€ããŸãã 空ã®è¡ãã¹ãããããŸãã ïŒã§å§ãŸãè¡ãã¹ãããããŸãã IPã¢ãã¬ã¹ïŒIPãç¯å²ãCIDRïŒãå«ãè¡ãã€ãŸã ãã¡ã€ã³åãæã€æååã®ã¿ã«é¢å¿ããããŸãã ãã¡ã€ã«/opt/etc/unblock.dnsmasqã«ããipset = / domain_name / unblockããšãã圢åŒã®è¡ãè¿œå ããŸãã ããã¯ãç¹å®ã®ãã¡ã€ã³ã®IPã¢ãã¬ã¹ã決å®ããåŸããããã¯è§£é€ã»ããã«èªåçã«è¿œå ãããããšãæå³ããŸãã
å¿ ãã¹ã¯ãªãããå®è¡ããŠãunblock.dnsmasqãã¡ã€ã«ãçæããŠãã ããã
unblock_dnsmasq.sh
unblock.dnsmasqãã¡ã€ã«ãäœæãããããšã確èªããŸãã
cat /opt/etc/unblock.dnsmasq
7.ãã¡ã€ã³ã®ãªã¹ããç·šéããåŸã®ã·ã¹ãã ã®æå匷å¶æŽæ°çšã¹ã¯ãªããïŒunblock_update.shïŒ
ã¹ã¯ãªãã/opt/bin/unblock_update.shãäœæããŸãã
mcedit /opt/bin/unblock_update.sh
å 容ã貌ãä»ãïŒShift + InsertïŒïŒ
#!/bin/sh ipset flush unblock /opt/bin/unblock_dnsmasq.sh restart_dhcpd sleep 3 /opt/bin/unblock_ipset.sh &
å®è¡æš©ãäžããïŒ
chmod +x /opt/bin/unblock_update.sh
8.ã«ãŒã¿ãŒã®èµ·åæã«äžé£ã®ãããã¯è§£é€ãèªåçã«èšå®ããã¹ã¯ãªããïŒS99unblockïŒ
ã¹ã¯ãªãã/opt/etc/init.d/S99unblockãäœæããŸãã
mcedit /opt/etc/init.d/S99unblock
å 容ã貌ãä»ãïŒShift + InsertïŒïŒ
#!/bin/sh [ "$1" != "start" ] && exit 0 /opt/bin/unblock_ipset.sh &
å®è¡æš©ãäžããïŒ
chmod +x /opt/etc/init.d/S99unblock
9.å®å ãunblockããTorãžã®ãã±ããã®è»¢éïŒpost_iptables_script.shïŒ
ãšãã£ã¿ãŒã§ãã¡ã€ã«/etc/storage/post_iptables_script.shãéããŸãã
mcedit /etc/storage/post_iptables_script.sh
æåŸã«è¿œå ïŒ
iptables -t nat -A PREROUTING -i br0 -p tcp -m set --match-set unblock dst -j REDIRECT --to-port 9141
å¿ èŠã«å¿ããŠãã«ãŒã¿ãŒã®ãŠã§ãã€ã³ã¿ãŒãã§ãŒã¹ã§post_iptables_script.shãã¡ã€ã«ãç·šéã§ããŸã-ã詳现èšå®ã>ãã«ã¹ã¿ãã€ãºã>ãã¹ã¯ãªããã>ããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®åèµ·ååŸã«å®è¡ãã ç·šéåŸããé©çšããã¯ãªãã¯ããŸãã
åããã¡ã€ã«ã«ïŒããã¯ãªãã·ã§ã³ã§ãïŒãè¿œå ããŠãå€éšããŒã53ãžã®ãã¹ãŠã®èŠæ±ãèªåã«ãªãã€ã¬ã¯ãã§ããŸãã ããã¯ãããŒã«ã«ãããã¯ãŒã¯äžã®ã¯ã©ã€ã¢ã³ãããµãŒãããŒãã£ã®DNSãµãŒãã¹ã䜿çšããªãããã«ããããã«å¿ èŠã§ãã èŠæ±ã¯éåžžã®DNSãµãŒããŒãééããŸãã
iptables -t nat -I PREROUTING -i br0 -p udp --dport 53 -j DNAT --to 192.168.0.1 iptables -t nat -I PREROUTING -i br0 -p tcp --dport 53 -j DNAT --to 192.168.0.1
å¿ èŠã«å¿ããŠã 192.168.0.1ãã«ãŒã¿ãŒïŒLANïŒã®å éšã¢ãã¬ã¹ã«çœ®ãæããŸãã
10.è¿œå ã®æ§æãã¡ã€ã«ãdnsmasqã«æ¥ç¶ãã
äœæããunblock.dnsmasqãã¡ã€ã«ãdnsmasqã«æ¥ç¶ããå¿ èŠããããŸãã ãããè¡ãã«ã¯ããšãã£ã¿ãŒã§ãã¡ã€ã«/etc/storage/dnsmasq/dnsmasq.confãéããŸãã
mcedit /etc/storage/dnsmasq/dnsmasq.conf
æåŸã«è¿œå ïŒ
conf-file=/opt/etc/unblock.dnsmasq
å¿ èŠã«å¿ããŠïŒããã¯ãªãã·ã§ã³ã§ãïŒã解å床ãšä¿¡é Œæ§ã®ããã«ãµãŒããŒãè¿œå ã§ããŸãã
server=8.8.8.8
å¿ èŠã«å¿ããŠãã«ãŒã¿ãŒã®ãŠã§ãã€ã³ã¿ãŒãã§ãŒã¹ã§ã詳现ã>ãLANã>ãDHCPãµãŒããŒã>ããŠãŒã¶ãŒdnsmasq.confæ§æãã¡ã€ã«ãã®dnsmasq.confãã¡ã€ã«ãç·šéã§ããŸãã ç·šéåŸããé©çšããã¯ãªãã¯ããŸãã
11.ãããã¯è§£é€ã»ããã®å 容ãå®æçã«æŽæ°ããã¿ã¹ã¯ãcronã«è¿œå ããŸã
ããã¯ãããã°ã©ã /ããã€ã¹ãç¬èªã®è§£æ±ºæ¹æ³ã䜿çšãããã¡ã€ã³IPã¢ãã¬ã¹ãå€æŽãããå Žåã®è¿œå ä¿éºã§ãã å¿ èŠãªããšã¯ãå¿ èŠãªé »åºŠã§unblock_ipset.shã¹ã¯ãªãããå®è¡ããããšã ãã§ãã ããšãã°ãåå6æã«æ¯æ¥èµ·åããŸãã
cronæ§æãã¡ã€ã«ã®ã«ãŒãåãadminã«çœ®ãæããŸãã
sed -i 's/root/admin/g' /opt/etc/crontab
ãšãã£ã¿ãŒã§ãã¡ã€ã«/ opt / etc / crontabãéããŸãã
mcedit /opt/etc/crontab
æåŸã«è¿œå ïŒ
00 06 * * * admin /opt/bin/unblock_ipset.sh
å¿ èŠã«å¿ããŠãä»ã®ãã¹ãŠã®ãã³ãã¬ãŒãã¿ã¹ã¯ãã³ã¡ã³ãåã§ããŸãã crontabãã¡ã€ã«ã¯æ¬¡ã®ããã«ãªããŸãã
12.ã«ãŒã¿ãŒã®åèµ·å
ã³ãã³ããå®è¡ããŸãïŒ
reboot
åèµ·ååŸããã©ãŠã¶ã§check.torproject.org Webãµã€ããéããŸãïŒunblock.txtã«è¿œå ããå¿ èŠããããŸãïŒã ãã¹ãŠãæ£ããè¡ã£ãå Žåããããã§ãšãããããŸããããšããç¢æã衚瀺ãããŸãã ãã®ãã©ãŠã¶ãŒã¯Torã䜿çšããããã«æ§æãããŠããŸãã "ïŒ
Keenetic OSã䜿çšããã«ãŒã¿ãŒã®æ§æ
Entware Package ManagerïŒOPKGïŒããã§ã«æ§æãããŠããKeenetic / Zyxelã«ãŒã¿ãŒãå¿ èŠã§ãã ããšãã°ã以äžã¯EntwareããµããŒãããã«ãŒã¿ãŒã®ãªã¹ãã§ããKeneticIIãKenetic IIIãExtraãExtra IIãGiga IIãGiga IIIãOmniãOmni IIãVivaãUltraãUltra IIãOmniïŒKN-1410ïŒãExtraïŒKN -1710ïŒãGigaïŒKN-1010ïŒãUltraïŒKN-1810ïŒãVivaïŒKN-1910ïŒãDSLïŒKN-2010ïŒãDuoïŒKN-2110ïŒã Entwareãæ§æããæé ã¯ã ããã«ãããŸã ïŒæ倧10ãã€ã³ãïŒã
以åã®ããŒãžã§ã³ïŒ2.07æªæºã®ãã¡ãŒã ãŠã§ã¢ïŒã§æ¢ã«EntwareãµããŒããè¿œå ããå Žåã¯ãå€ãEntware-ngã䜿çšããŠããããšã確èªããŠãã ããã
ãNetfilterãµãã·ã¹ãã ã«ãŒãã«ã¢ãžã¥ãŒã«ã-[äžè¬èšå®]> [ã³ã³ããŒãã³ãã»ããã®å€æŽ]ãæå¹ã«ããŠãã ããã 䜿çšå¯èœãªãªã¹ãã«ãªãå Žåã¯ãæåã«IPv6ãããã³ã«ã³ã³ããŒãã³ããã€ã³ã¹ããŒã«ããŠãã ããã ããã衚瀺ãããªãå Žåã¯ããããªãã§è©ŠããŠãã ããããã ããç¯å²ãšCIDRã§ããã¯è§£é€ã§ããªãå¯èœæ§ãé«ããªããŸãïŒhashïŒnet setããµããŒããããªãããïŒã
ãã¹ãã§ã¯ãææ°ã®ãã¡ãŒã ãŠã§ã¢2.14.C.0.0-4ãåããKeenetic UltraïŒKN-1810ïŒã䜿çšããŸããã
éèŠãªãç¥ããã ã·ã¹ãã ã®éåžžã®DNSãµãŒããŒãç¡å¹ã«ããå¿ èŠããããŸãã代ããã«dnsmasqã䜿çšããŸãã DNSãµãŒãã¹ïŒYandex.DNS / SkyDNS / AdGuard DNSïŒãã¯ã©ã€ã¢ã³ãã«åå¥ã«å²ãåœãŠãæ©èœã¯å€±ãããŸãããå¿ èŠã«å¿ããŠdnsmasqèšå®ã§ã°ããŒãã«ã«äœ¿çšã§ããŸãã
1.ã«ãŒã¿ãŒã«å¿ èŠãªãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ãã
opkg update opkg install mc tor tor-geoip bind-dig cron dnsmasq-full ipset iptables
mc-çå€äžã®åžä»€å®ãã¡ã€ã«ãããŒãžã£ãŒã 䟿å©ãªmceditãšãã£ã¿ãŒã®ããã ãã«å¿ èŠã§ãã å¥ã®ããã¹ããšãã£ã¿ã®äœ¿çšã«æ £ããŠããå Žåã¯ãmcãã€ã³ã¹ããŒã«ã§ããŸããã
tor -TorãµãŒãã¹ã
tor-geoip -Torã®geo-IPããŒã¿ããŒã¹ã
bind-dig -DNSã¯ã©ã€ã¢ã³ãïŒnslookupãšãã¹ãã®ã¢ããã°ïŒã
cron-ã¿ã¹ã¯ã¹ã±ãžã¥ãŒã©ã
dnsmasq-full -DNSãµãŒããŒã
ipsetããã³iptablesã¯ipsetããã³iptablesã³ã³ãœãŒã«ãŠãŒãã£ãªãã£ã§ãïŒããããã·ã¹ãã äžã«ãã§ã«ååšããå¿ èŠã§ã¯ãªãã®ã§ãã»ãã¥ãªãã£ã®ããã«è¿œå ããŸããïŒã
2. ipsetã®åæåãè€æ°ã®ãããã¯è§£é€IPã¢ãã¬ã¹ã®äœæïŒ100-ipset.shïŒ
ã«ãŒã¿ãŒã·ã¹ãã ãå€ãã®ããã·ã¥ããµããŒãããŠããããšã確èªããŸãïŒnet
ipset create test hash:net
ããŒã ããšã©ãŒãã¡ãã»ãŒãžãåºããªãã£ãå ŽåããµããŒãããããããã«æ瀺ã«åŸã£ãŠãã ããã ãã以å€ã®å ŽåïŒãšã©ãŒãããïŒã次ã®ã¹ã¯ãªããã§ã¯ã hashïŒnetãhashïŒipã«çœ®ãæããå¿ èŠããããŸãã ãã®å Žåãç¯å²ãšCIDRã®ããã¯ã解é€ããæ©èœã倱ãããŸãã
ã«ãŒã¿ã®èµ·åæã«ãããã¯è§£é€ãšåŒã°ãã空ã®ã¢ãã¬ã¹ã»ãããäœæããŸãã ãããè¡ãã«ã¯ããã¡ã€ã«/opt/etc/ndm/fs.d/100-ipset.shãäœæããŸãã
mcedit /opt/etc/ndm/fs.d/100-ipset.sh
å 容ã貌ãä»ãïŒShift + InsertïŒïŒ
#!/bin/sh [ "$1" != "start" ] && exit 0 ipset create unblock hash:net -exist exit 0
ãããã¡ãã貌ãä»ããã«ã¯ãShift + Insertã䜿çšããä¿å-F2ãçµäº-F10ã䜿çšããŸãã
å®è¡æš©ãäžããïŒ
chmod +x /opt/etc/ndm/fs.d/100-ipset.sh
3. Torã®ã»ããã¢ãã
Toræ§æãã¡ã€ã«ã®å 容ãåé€ããŸãã
cat /dev/null > /opt/etc/tor/torrc
Toræ§æãã¡ã€ã«ãéããŸãã
mcedit /opt/etc/tor/torrc
å 容ã貌ãä»ãïŒShift + InsertïŒïŒ
User root PidFile /opt/var/run/tor.pid ExcludeExitNodes {RU},{UA},{AM},{KG},{BY} StrictNodes 1 TransPort 192.168.0.1:9141 ExitRelay 0 ExitPolicy reject *:* ExitPolicy reject6 *:* GeoIPFile /opt/share/tor/geoip GeoIPv6File /opt/share/tor/geoip6 DataDirectory /opt/var/lib/tor
å¿ èŠã«å¿ããŠã 192.168.0.1ãã«ãŒã¿ãŒïŒLANïŒã®å éšã¢ãã¬ã¹ã«çœ®ãæããŸãã ç°¡åãªæ§æã®èª¬æïŒ
- åºåããŒããé€å€ïŒãã·ã¢ããŠã¯ã©ã€ããã¢ã«ã¡ãã¢ãã«ã®ã¹ã¿ã³ããã©ã«ãŒã·ã
- ééãããã·ãã¢ãã¬ã¹192.168.0.1ãããŒã9141ã«æããŸãã
- åºå£ç¹ã§ããããšãæåŠããŸãã
4.ããã¯ããã€ãã¹ããããã®ãã¡ã€ã³ã®ãªã¹ãïŒã ãã§ãªãïŒïŒunblock.txtïŒ
unblock.txtã¯ããã¯ã解é€ããç°¡åãªãªã¹ãã§ãã ãã¡ã€ã³ãIPã¢ãã¬ã¹ãç¯å²ããŸãã¯CIDRã®ããã¯ã解é€ã§ããŸãã 1è¡-1èŠçŽ ã 空è¡ïŒã¹ããŒã¹ãšã¿ããå«ãïŒã¯ç¡èŠãããŸãã è¡ã®å é ã«ïŒæåã䜿çšããŠãç¡èŠããããšãã§ããŸãã
ãã¡ã€ã«/opt/etc/unblock.txtãäœæããŸãã
mcedit /opt/etc/unblock.txt
åè¡ã«ã¯ããã¡ã€ã³åãIPã¢ãã¬ã¹ãç¯å²ããŸãã¯CIDRãå«ããããšãã§ããŸãã ïŒæåã䜿çšããŠãè¡ã«ã³ã¡ã³ããä»ããããšãã§ããŸãã
ãããç§ã®å人çšãã¡ã€ã«ã®äŸã§ã
###- rutracker.org rutor.info rutor.is mega-tor.org kinozal.tv nnm-club.me nnm-club.ws tfile.me tfile-home.org tfile1.cc megatfile.cc megapeer.org megapeer.ru tapochek.net tparser.org tparser.me rustorka.com uniongang.tv fast-torrent.ru ### rezka.ag hdrezka.ag hdrezka.me filmix.co filmix.cc seasonvar.ru ### lib.rus.ec flibusta.is flibs.me flisland.net flibusta.site ### telegram.org tdesktop.com tdesktop.org tdesktop.info tdesktop.net telesco.pe telegram.dog telegram.me t.me telegra.ph web.telegram.org desktop.telegram.org updates.tdesktop.com venus.web.telegram.org flora.web.telegram.org vesta.web.telegram.org pluto.web.telegram.org aurora.web.telegram.org 149.154.160.0/20 91.108.4.0/22 91.108.8.0/22 91.108.12.0/22 91.108.16.0/22 91.108.56.0/22 109.239.140.0/24 67.198.55.0/24 ### 7-zip.org edem.tv 4pna.com 2019.vote ### Tor check.torproject.org ### IP ( # ) #195.82.146.214 ### CIDR ( # ) #103.21.244.0/22 ### ( # ) #100.100.100.200-100.100.100.210
5.ãã¡ã€ã³ã®ç¹å®ã®ãªã¹ãã®ãããã¯è§£é€IPã¢ãã¬ã¹ã®ã»ãããå ¥åããã¹ã¯ãªããïŒunblock_ipset.shïŒ
ã¹ã¯ãªãã/opt/bin/unblock_ipset.shãäœæããŸãã
mcedit /opt/bin/unblock_ipset.sh
å 容ã貌ãä»ãïŒShift + InsertïŒïŒ
#!/bin/sh until ADDRS=$(dig +short google.com @localhost) && [ -n "$ADDRS" ] > /dev/null 2>&1; do sleep 5; done while read line || [ -n "$line" ]; do [ -z "$line" ] && continue [ "${line:0:1}" = "#" ] && continue cidr=$(echo $line | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}/[0-9]{1,2}') if [ ! -z "$cidr" ]; then ipset -exist add unblock $cidr continue fi range=$(echo $line | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}-[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}') if [ ! -z "$range" ]; then ipset -exist add unblock $range continue fi addr=$(echo $line | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}') if [ ! -z "$addr" ]; then ipset -exist add unblock $addr continue fi dig +short $line @localhost | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' | awk '{system("ipset -exist add unblock "$1)}' done < /opt/etc/unblock.txt
å®è¡æš©ãäžããïŒ
chmod +x /opt/bin/unblock_ipset.sh
ã¹ã¯ãªããã¯éåžžã«ã·ã³ãã«ã§ãããããã®äœæ¥ã®æ¬è³ªã§ã... google.comãã¡ã€ã³è§£æ±ºãæ©èœããã®ãåŸ ã£ãŠããŸãïŒãããè¡ãããªãå Žåãã«ãŒã¿ãŒããŸã åæååŠçäžã§ãããããã«ãŒã¿ãŒã®èµ·åæã«å€ãã®ãããã¯è§£é€ãè¡ãããŸããïŒã unblock.txtãã¡ã€ã«ã®è¡ãèªã¿åããŸãã èªã¿åãè¡ã¯ãå é ãšæ«å°Ÿã®ã¹ããŒã¹ãšã¿ããèªåçã«åé€ããŸãã 空ã®è¡ãã¹ãããããŸãã ïŒæåã§å§ãŸãè¡ãã¹ãããããŸãã CIDRã®ã©ã€ã³ãæ¢ããŠããŸãã CIDRãèŠã€ãã£ãããããããããã¯è§£é€ã«è¿œå ããŸãã ç¯å²ã®ç¯å²ãæ¢ããŠããŸãã èŠã€ãã£ãå Žåã¯ããããã¯è§£é€ã«è¿œå ããŸãã æååã§IPã¢ãã¬ã¹ãæ¢ããŠããŸãã IPãèŠã€ãã£ãå Žåãããããããã¯è§£é€ã«è¿œå ããŸãã æã£ãŠè¡ã解決ããŸãããã çµæã®ãã¹ãŠã®IPã¢ãã¬ã¹ããããã¯è§£é€ã«è¿œå ãããŸãã
6.ãã¡ã€ã³ã®ç¹å®ã®ãªã¹ãããè¿œå ã®dnsmasqæ§æãã¡ã€ã«ãçæããããã®ã¹ã¯ãªããïŒunblock_dnsmasq.shïŒ
ã¹ã¯ãªãã/opt/bin/unblock_dnsmasq.shãäœæããŸãã
mcedit /opt/bin/unblock_dnsmasq.sh
å 容ã貌ãä»ãïŒShift + InsertïŒïŒ
#!/bin/sh cat /dev/null > /opt/etc/unblock.dnsmasq while read line || [ -n "$line" ]; do [ -z "$line" ] && continue [ "${line:0:1}" = "#" ] && continue echo $line | grep -Eq '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' && continue echo "ipset=/$line/unblock" >> /opt/etc/unblock.dnsmasq done < /opt/etc/unblock.txt
å®è¡æš©ãäžããïŒ
chmod +x /opt/bin/unblock_dnsmasq.sh
ã¹ã¯ãªããã¯éåžžã«åçŽã§ãã /opt/etc/unblock.txtããè¡ãé çªã«èªã¿åããŸãã èªã¿åãè¡ã¯ãå é ãšæ«å°Ÿã®ã¹ããŒã¹ãšã¿ããèªåçã«åé€ããŸãã 空ã®è¡ãã¹ãããããŸãã ïŒã§å§ãŸãè¡ãã¹ãããããŸãã IPã¢ãã¬ã¹ïŒIPãŸãã¯CIDRïŒãå«ãè¡ãã¹ãããããŸãã ãã¡ã€ã³åãæã€æååã®ã¿ã«é¢å¿ããããŸãã ãã¡ã€ã«/opt/etc/unblock.dnsmasqã«ããipset = / domain_name / unblockããšãã圢åŒã®è¡ãè¿œå ããŸãã ããã¯ãç¹å®ã®ãã¡ã€ã³ã®IPã¢ãã¬ã¹ã決å®ããåŸãããããèªåçã«ãããã¯è§£é€ã»ããã«è¿œå ãããããšãæå³ããŸãã
å¿ ãã¹ã¯ãªãããå®è¡ããŠãunblock.dnsmasqãã¡ã€ã«ãçæããŠãã ããã
unblock_dnsmasq.sh
unblock.dnsmasqãã¡ã€ã«ãäœæãããããšã確èªããŸãã
cat /opt/etc/unblock.dnsmasq
7.ãã¡ã€ã³ã®ãªã¹ããç·šéããåŸã®ã·ã¹ãã ã®æå匷å¶æŽæ°çšã¹ã¯ãªããïŒunblock_update.shïŒ
ã¹ã¯ãªãã/opt/bin/unblock_update.shãäœæããŸãã
mcedit /opt/bin/unblock_update.sh
å 容ã貌ãä»ãïŒShift + InsertïŒïŒ
#!/bin/sh ipset flush unblock /opt/bin/unblock_dnsmasq.sh /opt/etc/init.d/S56dnsmasq restart /opt/bin/unblock_ipset.sh &
å®è¡æš©ãäžããïŒ
chmod +x /opt/bin/unblock_update.sh
8.ã«ãŒã¿ãŒã®èµ·åæã«äžé£ã®ãããã¯è§£é€ãèªåçã«èšå®ããã¹ã¯ãªããïŒS99unblockïŒ
ã¹ã¯ãªãã/opt/etc/init.d/S99unblockãäœæããŸãã
mcedit /opt/etc/init.d/S99unblock
å 容ã貌ãä»ãïŒShift + InsertïŒïŒ
#!/bin/sh [ "$1" != "start" ] && exit 0 /opt/bin/unblock_ipset.sh &
å®è¡æš©ãäžããïŒ
chmod +x /opt/etc/init.d/S99unblock
9.å®å ãunblockããTorãžã®ãã±ããã®è»¢éïŒ100-redirect.shïŒ
ãããè¡ãã«ã¯ããã¡ã€ã«/opt/etc/ndm/netfilter.d/100-redirect.shãäœæããŸãã
mcedit /opt/etc/ndm/netfilter.d/100-redirect.sh
å 容ã貌ãä»ãïŒShift + InsertïŒïŒ
#!/bin/sh [ "$type" == "ip6tables" ] && exit 0 if [ -z "$(iptables-save 2>/dev/null | grep unblock)" ]; then ipset create unblock hash:net -exist iptables -w -t nat -A PREROUTING -i br0 -p tcp -m set --match-set unblock dst -j REDIRECT --to-port 9141 fi exit 0
æé 2 ã§hashïŒnetã§ã¯ãªãhashïŒipã䜿çšããå ŽåãhashïŒnetãhashïŒipã«çœ®ãæããŸããå®éã2ã€ã®ã¹ããããããããã¯è§£é€ã®ã»ãããäœæããæ©èœãããã«è€è£œããŸããããã¯ãfs.dããã®ã¹ã¯ãªããããŸã å®è¡ãéå§ããŠããããã¹ã¯ãªããnetfilter.dãæ¢ã«å®è¡ãããŠããå Žåãã»ãã¥ãªãã£ã®ããã«å¿ èŠã§ãããããã¯è§£é€ã以åã«äœæãããŠããŠãåé¡ãããŸãããã³ãã³ãã¯åã«ç¡èŠãããŸããåããã¡ã€ã«ã«ïŒããã¯ãªãã·ã§ã³ã§ãïŒãè¿œå ããŠãå€éšããŒã53ãžã®ãã¹ãŠã®èŠæ±ãèªåã«ãªãã€ã¬ã¯ãã§ããŸããããã¯ãããŒã«ã«ãããã¯ãŒã¯äžã®ã¯ã©ã€ã¢ã³ãããµãŒãããŒãã£ã®DNSãµãŒãã¹ã䜿çšããªãããã«ããããã«å¿ èŠã§ããèŠæ±ã¯éåžžã®DNSãµãŒããŒãééããŸããæåŸã®åºå£ã®åã«ã次ãè¿œå ããŸãã
if [ -z "$(iptables-save 2>/dev/null | grep "udp \-\-dport 53 \-j DNAT")" ]; then iptables -w -t nat -I PREROUTING -i br0 -p udp --dport 53 -j DNAT --to 192.168.0.1 fi if [ -z "$(iptables-save 2>/dev/null | grep "tcp \-\-dport 53 \-j DNAT")" ]; then iptables -w -t nat -I PREROUTING -i br0 -p tcp --dport 53 -j DNAT --to 192.168.0.1 fi
å¿ èŠã«å¿ããŠã192.168.0.1ãã«ãŒã¿ãŒïŒLANïŒã®å éšã¢ãã¬ã¹ã«çœ®ãæããŸãã
å®è¡æš©ãäžããïŒ
chmod +x /opt/etc/ndm/netfilter.d/100-redirect.sh
10. dnsmasqãæ§æããdnsmasqã«è¿œå ã®æ§æãã¡ã€ã«ãæ·»ä»ãã
dnsmasqæ§æãã¡ã€ã«ã®å 容ãåé€ããŸãã
cat /dev/null > /opt/etc/dnsmasq.conf
dnsmasqæ§æãã¡ã€ã«ãéããŸãã
mcedit /opt/etc/dnsmasq.conf
å 容ã貌ãä»ãïŒShift + InsertïŒïŒ
user=nobody bogus-priv no-negcache clear-on-reload bind-dynamic listen-address=192.168.0.1 listen-address=127.0.0.1 min-port=4096 cache-size=1536 expand-hosts log-async conf-file=/opt/etc/unblock.dnsmasq server=8.8.8.8
å¿ èŠã«å¿ããŠã192.168.0.1ãã«ãŒã¿ãŒïŒLANïŒã®å éšã¢ãã¬ã¹ã«çœ®ãæããŸãã
11.ãããã¯è§£é€ã»ããã®å 容ãå®æçã«æŽæ°ããã¿ã¹ã¯ãcronã«è¿œå ããŸã
ããã¯ãããã°ã©ã /ããã€ã¹ãç¬èªã®è§£æ±ºæ¹æ³ã䜿çšãããã¡ã€ã³IPã¢ãã¬ã¹ãå€æŽãããå Žåã®è¿œå ä¿éºã§ããå¿ èŠãªããšã¯ãå¿ èŠãªé »åºŠã§unblock_ipset.shã¹ã¯ãªãããå®è¡ããããšã ãã§ããããšãã°ãåå6æã«æ¯æ¥èµ·åããŸãã
ãšãã£ã¿ãŒã§ãã¡ã€ã«/ opt / etc / crontabãéããŸãã
mcedit /opt/etc/crontab
æåŸã«è¿œå ïŒ
00 06 * * * root /opt/bin/unblock_ipset.sh
å¿ èŠã«å¿ããŠãä»ã®ãã¹ãŠã®ãã³ãã¬ãŒãã¿ã¹ã¯ãã³ã¡ã³ãåã§ããŸããcrontabãã¡ã€ã«ã¯æ¬¡ã®ããã«ãªããŸãã
12.éåžžã®DNSãµãŒããŒã®ç¡å¹åãšã«ãŒã¿ãŒã®åèµ·å
Keenetic Router CLIã«æ¥ç¶ããŸãïŒãSSHãµãŒããŒãã³ã³ããŒãã³ããã·ã¹ãã ã«è¿œå ãããŠããå ŽåãTelnetã®ããŒã23ãšSSHã®ããŒã22ïŒã
ã³ãã³ããå®è¡ããŸãïŒ
opkg dns-override system configuration save system reboot
ãã¡ãŒã ãŠã§ã¢ã«çµã¿èŸŒãŸããDNSãµãŒããŒã¯ãªãã«ãªãã代ããã«Entwareã®dnsmasqã䜿çšãããŸããèµ·åæã®ã«ãŒã¿ãŒã¯ãoptãã©ã«ããŒãããŠã³ããããŠãããã©ããã確èªããŸãïŒEntwareã®USBãã©ãã·ã¥ãã©ã€ã/ãã©ã€ãããããŸãïŒãååšããå Žåãéåžžã®DNSãµãŒããŒã¯äœ¿çšãããŸãããããã§ãªãå Žåã¯ã䜿çšãããŸããã€ãŸããã©ãã·ã¥ãã©ã€ããåãå€ããŠã«ãŒã¿ãŒãåèµ·åãããšãåãšåãããã«ïŒã»ããã¢ããããåã«ïŒãã¹ãŠãæ©èœããŸãã
åèµ·ååŸããã©ãŠã¶ã§check.torproject.org Webãµã€ããéããŸãïŒunblock.txtã«è¿œå ããå¿ èŠããããŸãïŒããã¹ãŠãæ£ããè¡ã£ãå Žåããããã§ãšãããããŸããããšããç¢æã衚瀺ãããŸãããã®ãã©ãŠã¶ãŒã¯Torã䜿çšããããã«æ§æãããŠããŸãã "ïŒ
æ§æåŸã®ãšã©ãŒã蚺æããããã®åºæ¬çãªæ¹æ³
ãµã€ãcheck.torproject.orgïŒunblock.txtã«è¿œå ããå¿ èŠããããŸãïŒã§ã®ãã§ãã¯ã«åæ ŒããŠãããããã€ããŒããã®ã¹ã¿ããä»ã®ãªãœãŒã¹ã«å¯ŸããŠéãããŠããïŒãŸãã¯éããªãïŒå Žåããããã€ããŒã¯DNSãã©ãã£ãã¯ã«å¹²æžããåçã眮ãæããŸã- DNSã¯ãšãªã®ãã£ã«ã¿ãªã³ã°ãããã«ãã€ãã¹ããå¿ èŠããããŸãã
æ§æåŸã«äœããæ£åžžã«æ©èœããªãå Žåã¯ãç°¡åãªã³ãã³ãã䜿çšããŠåé¡ã®ã¹ããããç¹å®ããŸãã
ãããã¯è§£é€ã»ããã®å 容ã衚瀺ããŸãã
ipset list unblock
ã·ã¹ãã ããã®ãããªã»ããããªãããšãå ±åããå Žåããšã©ãŒã¯ã¹ããã2ã«ãããŸããŸãã¯ã·ã¹ãã ã®Netfilterã¢ãžã¥ãŒã«ãæå¹ã«ããŸããã§ããïŒKeneticã®å ŽåïŒã
ã»ããã空ã§ããããšãå€æããå Žåãunblock_ipset.shã¹ã¯ãªããã¯æ©èœããŠããªãã£ããããS99unblockèµ·åã¹ã¯ãªããã§èµ·åããå¿ èŠããããŸãããã®unblock_ipset.shã¹ã¯ãªãããæåã§å®è¡ããŸããã»ããããã£ã±ãã®å Žåããšã©ãŒã¯ã¹ããã8ã«ãããŸããã¹ã¯ãªãããå®è¡ã§ããªãå ŽåïŒgoogle.comã®è§£æ±ºãåŸ æ©ããŠããå¯èœæ§ãé«ãïŒããšã©ãŒã¯DNSãµãŒããŒåŽã®ã©ããã«ãããŸããããããã¹ããã10ãŸãã¯6
ã§ããiptablesã§ãªãã€ã¬ã¯ãã確èªããŸãïŒ
iptables-save 2>/dev/null | grep unblock
ååšããªãå Žåããšã©ãŒã¯ã¹ããã9ã«
ãããŸãããã¹ãŠã®ãµã€ãããŸã£ããæ©èœããªãå Žåãã€ãŸã DNSã¯æ©èœããããšã©ãŒã¯ã¹ããŒãž6ãŸãã¯10ã®ã©ããã«ãããŸãããããããã¹ããŒãž9ã«
ãããŸããunblock.txtã®ãã¹ãŠã®ãµã€ããæ©èœããªãïŒã¿ã€ã ã¢ãŠããè¶ éïŒããä»ã®ãã¹ãŠãæ©èœããå Žåãåé¡ã¯ToråŽã®ã©ããã«ããããšã©ãŒã¹ããŒãž3ã§ã
ãããã€ããŒã«ããDNSã¯ãšãªã®ãã£ã«ã¿ãªã³ã°ã®è¿œå ãã€ãã¹
ãããã€ããŒãããããã¯ããããªãœãŒã¹ã®å¿çã眮ãæããããšã«ããDNSãã©ãã£ãã¯ã«å¹²æžããå Žåããããåé¿ããã®ã¯éåžžã«ç°¡åã§ãããã®ããã«ãdnscrypt-proxyã䜿çšããŸãããåžæã®å Žåã¯ãdnscryptãã¹ã¿ãããŒïŒDNS over TLSïŒã«ç°¡åã«çœ®ãæããããšãã§ããŸãã
dnscryptã¯ãunblock.txtã«ãªã¹ããããŠãããã¡ã€ã³ã«ã®ã¿äœ¿çšãããŸããä»ã®ãã¹ãŠã®ã¯ãšãªã¯ãéåžžã®DNSãµãŒããŒãééããŸãã
ãããã€ããŒãDNSã¯ãšãªããã£ã«ã¿ãªã³ã°ããªãããšã確å®ãªå Žåããã®è¿œå ã®æ§æãè¡ãå¿ èŠã¯ãããŸããã
äžèšã®ããã¯ãã€ãã¹ãæ¢ã«èšå®ããŠããå¿ èŠããããŸãã次ã®èšå®ã¯ãPadavanãšKeenetic OSã§åãã§ãã
ã«ãŒã¿ãŒã«è¿œå ã®ãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããŸãã
opkg update opkg install dnscrypt-proxy2
dnscrypt-proxyæ§æãã¡ã€ã«ãéããŸãã
mcedit /opt/etc/dnscrypt-proxy.toml
listen_addressesãfallback_resolverãèŠã€ããŠããã©ã¡ãŒã¿ãŒããã£ãã·ã¥ããŠå€æŽããŸãã
listen_addresses = ['127.0.0.1:9153'] fallback_resolver = '77.88.8.8:1253' cache = false
77.88.8.8:1253ã¯ãéæšæºããŒããæã€Yandex DNSãµãŒããŒã¢ãã¬ã¹ã§ããdnscrypt-proxyã«åé¡ãããå Žåã®ããã¯ã¢ããã§ãã
dnscrypt-proxyãå®è¡ããŸãã
/opt/etc/init.d/S09dnscrypt-proxy2 start
dnscrypt-proxyãæ©èœããŠããããšã確èªããŸãïŒå¿çãšããŠIPã¢ãã¬ã¹ã®ãªã¹ãã衚瀺ãããŸãïŒã
dig +short google.com @localhost -p 9153
ãšãã£ã¿ãŒã§/opt/bin/unblock_ipset.shã¹ã¯ãªãããéããŸãïŒ
mcedit /opt/bin/unblock_ipset.sh
å 容ã次ã®ãã®ã«çœ®ãæããŸãã
#!/bin/sh until ADDRS=$(dig +short google.com @localhost -p 9153) && [ -n "$ADDRS" ] > /dev/null 2>&1; do sleep 5; done while read line || [ -n "$line" ]; do [ -z "$line" ] && continue [ "${line:0:1}" = "#" ] && continue cidr=$(echo $line | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}/[0-9]{1,2}') if [ ! -z "$cidr" ]; then ipset -exist add unblock $cidr continue fi range=$(echo $line | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}-[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}') if [ ! -z "$range" ]; then ipset -exist add unblock $range continue fi addr=$(echo $line | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}') if [ ! -z "$addr" ]; then ipset -exist add unblock $addr continue fi dig +short $line @localhost -p 9153 | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' | awk '{system("ipset -exist add unblock "$1)}' done < /opt/etc/unblock.txt
å°ããªå€æŽãå ããŸãã-解決ã®ããã®æãã¯éåžžã®DNSãµãŒããŒã䜿çšãããããŒã9153ã®dnscrypt-proxyã䜿çšããŸãããšãã£ã¿ãŒ
ã§/opt/bin/unblock_dnsmasq.shã¹ã¯ãªãããéããŸãã
mcedit /opt/bin/unblock_dnsmasq.sh
å 容ã次ã®ãã®ã«çœ®ãæããŸãã
#!/bin/sh cat /dev/null > /opt/etc/unblock.dnsmasq while read line || [ -n "$line" ]; do [ -z "$line" ] && continue [ "${line:0:1}" = "#" ] && continue echo $line | grep -Eq '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' && continue echo "ipset=/$line/unblock" >> /opt/etc/unblock.dnsmasq echo "server=/$line/127.0.0.1#9153" >> /opt/etc/unblock.dnsmasq done < /opt/etc/unblock.txt
å°ããªå€æŽãå ããŸãã-unblock.dnsmasqãã¡ã€ã«ãçæãããšãã«ããserver = / domain_name / 127.0.0.1ïŒ9153ãã®ãããªè¡ãè¿œå ãããŸãããããã¯ããªã¹ãããã®ãã¡ã€ã³ã®è§£æ±ºãdnscrypt-proxyãä»ããŠè¡ãããããšãæå³ããŸãã
unblock_update.shãå®è¡ããŸãã
unblock_update.sh
ã§ããè€éãªèšå®ã¯ãã¹ãŠé ããŠããŸããããã§ãå¿ èŠã«å¿ããŠunblock.txtãªã¹ããç·šéãããããããã¡ã€ã³ãŸãã¯IPã¢ãã¬ã¹ãè¿œå ãŸãã¯åé€ããŠããã¯ã解é€ããunblock_update.shã³ãã³ãã䜿çšããŠå€æŽãæå¹ã«ããŸãã
æŽæ°04/01/2019ãå€ãã®å Žåãèšäºã«ã¯äžè¬çãªè³ªåãå«ãå人çãªã¡ãã»ãŒãžããããŸããããã§æãäžè¬çãªçããããŸãã
.onionãã¡ã€ã³ãŸãŒã³ãµã€ããå©çšå¯èœã«ããæ¹æ³ã¯ïŒ
torrcã«è¿œå ïŒ
VirtualAddrNetwork 10.254.0.0/16 DNSPort 127.0.0.1:9053 AutomapHostsOnResolve 1
ãªããªã³ãŸãŒã³ã®ãã¹ãŠã®ãã¡ã€ã³ã«ã¢ã¯ã»ã¹ããã«ã¯ãdnsmasq.confã«è¿œå ããŸãã
server=/onion/127.0.0.1#9053 ipset=/onion/unblock
ãªããªã³ãŸãŒã³ã®ãã¹ãŠã®ãã¡ã€ã³ã§ã¯ãªããç¹å®ã®ãã¡ã€ã³ã®ã¿ãžã®ã¢ã¯ã»ã¹ãéãããå Žåã¯ãdnsmasq.confã«æ¬¡ã®ãšã³ããªãè¿œå ããŸãã
server=/rutorc6mqdinc4cz.onion/127.0.0.1#9053 ipset=/rutorc6mqdinc4cz.onion/unblock server=/nnmclub5toro7u65.onion/127.0.0.1#9053 ipset=/nnmclub5toro7u65.onion/unblock server=/flibustahezeous3.onion/127.0.0.1#9053 ipset=/flibustahezeous3.onion/unblock
ã«ãŒã¿ãŒã§å®è¡ãããŠããVPNãµãŒããŒã®ã¯ã©ã€ã¢ã³ãã®ããã¯ããã€ãã¹ããæ¹æ³
torrcã§ãè¡ãTransPortã«çœ®ãæããŸãã
TransPort 0.0.0.0:9141
å¿ èŠãªã€ã³ã¿ãŒãã§ã€ã¹ïŒã€ã³ã¿ãŒãã§ã€ã¹-VPNãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ïŒã§è¿œå ã®ãªãã€ã¬ã¯ããè¿œå ããŸãã
iptables -t nat -A PREROUTING -i -p tcp -m set --match-set unblock dst -j REDIRECT --to-port 9141