ื‘ืึทืกื™ืงืก ืคื•ืŸ ื˜ืจืึทื ืกืคึผืขืจืึทื ื˜ ืคึผืจืึทืงืกื™ื™ื ื’ ื ื™ืฆืŸ 3proxy ืื•ืŸ iptables / netfilter ืึธื“ืขืจ ื•ื•ื™ ืฆื• "ืฉื˜ืขืœืŸ ืึทืœืฅ ื“ื•ืจืš ืึท ืคืจืืงืกื™"

ืื™ืŸ ื“ืขื ืึทืจื˜ื™ืงืœ ืื™ืš ื•ื•ืึธืœื˜ ื•ื•ื™ ืฆื• ืึทื ื˜ื“ืขืงืŸ ื“ื™ ืคึผืึทืกืึทื‘ื™ืœืึทื˜ื™ื– ืคื•ืŸ ื˜ืจืึทื ืกืคึผืขืจืึทื ื˜ ืคึผืจืึทืงืกื™ื™ื ื’, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืจื™ื“ืขืจืขืงื˜ ืึทืœืข ืึธื“ืขืจ ื˜ื™ื™ืœ ืคื•ืŸ ื“ื™ ืคืึทืจืงืขืจ ื“ื•ืจืš ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืคึผืจืึทืงืกื™ ืกืขืจื•ื•ืขืจืก ืœืขื’ืึทืžืจืข ืึทื ื ืึธื•ื˜ื™ืกื˜ ื“ื•ืจืš ืงืœื™ื™ืึทื ืฅ.

ื•ื•ืขืŸ ืื™ืš ืกื˜ืึทืจื˜ืขื“ ืกืึทืœื•ื•ื™ื ื’ ื“ืขื ืคึผืจืึธื‘ืœืขื, ืื™ืš ืื™ื– ื’ืขื•ื•ืขืŸ ืคื™ื™ืกื˜ ืžื™ื˜ ื“ื™ ืคืึทืงื˜ ืึทื– ื–ื™ื™ึทืŸ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ื”ืื˜ ืื™ื™ืŸ ื‘ืึทื˜ื™ื™ึทื˜ื™ืง ืคึผืจืึธื‘ืœืขื - ื“ื™ HTTPS ืคึผืจืึธื˜ืึธืงืึธืœ. ืื™ืŸ ื“ื™ ื’ื•ื˜ืข ืึทืœื˜ ื˜ืขื’, ืขืก ื–ืขื ืขืŸ ื’ืขื•ื•ืขืŸ ืงื™ื™ืŸ ืกืคึผืขืฆื™ืขืœ ืคึผืจืึธื‘ืœืขืžืก ืžื™ื˜ ื˜ืจืึทื ืกืคึผืขืจืึทื ื˜ ื”ื˜ื˜ืคึผ ืคึผืจืึทืงืกื™ื™ื ื’, ืึธื‘ืขืจ ืžื™ื˜ HTTPS ืคึผืจืึทืงืกื™ื™ื ื’, ื‘ืจืึทื•ื–ืขืจื– ื‘ืึทืจื™ื›ื˜ ื™ื ื˜ืขืจืคื™ืจืึทื ืก ืžื™ื˜ ื“ืขื ืคึผืจืึธื˜ืึธืงืึธืœ ืื•ืŸ ืึทื– ืก ื•ื•ื• ื“ื™ ื’ืœื™ืง ืขื ื“ืก.

ืื™ืŸ ื“ื™ ืคึผืจืึธืกื˜ ืื™ื ืกื˜ืจื•ืงืฆื™ืขืก ืคึฟืึทืจ ื“ื™ Squid ืคืจืืงืกื™ ืกืขืจื•ื•ืขืจ, ื–ื™ื™ ืืคื™ืœื• ืคึฟืึธืจืฉืœืึธื’ืŸ ื“ื–ืฉืขื ืขืจื™ื™ื˜ื™ื ื’ ื“ื™ื™ืŸ ืื™ื™ื’ืขื ืข ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืื•ืŸ ื™ื ืกื˜ืึทืœื™ืจืŸ ืขืก ืื•ื™ืฃ ืงืœื™ื™ืึทื ืฅ, ื•ื•ืึธืก ืื™ื– ื’ืึทื ืฅ ื•ืžื–ื™ืŸ ืื™ืŸ ืžื™ื ื“ืกื˜ืขืจ, ื™ืจืึทืฉืึทื ืึทืœ ืื•ืŸ ืงื•ืงื˜ ื•ื•ื™ ืึท MITM ื‘ืึทืคืึทืœืŸ. ืื™ืš ื•ื•ื™ืกืŸ ืึทื– ื˜ื™ื ื˜ืคื™ืฉ ืงืขื ืขืŸ ืฉื•ื™ืŸ ื˜ืึธืŸ ืขืคึผืขืก ืขื ืœืขืš, ืึธื‘ืขืจ ื“ืขืจ ืึทืจื˜ื™ืงืœ ืื™ื– ื•ื•ืขื’ืŸ ืึท ืคึผืจืึธื•ื•ืขืŸ ืื•ืŸ ืืจื‘ืขื˜ืŸ ืื•ืคึฟืŸ ื ื™ืฆืŸ 3proxy ืคึฟื•ืŸ ื“ื™ ืจืขืกืคึผืขืงื˜ืขื“ 3APA3A.

ื“ืขืจื ืึธืš, ืžื™ืจ ื•ื•ืขืœืŸ ืงื•ืงืŸ ืื™ืŸ ื“ืขื ืคึผืจืึธืฆืขืก ืคื•ืŸ ื‘ื•ื™ืขืŸ 3proxy ืคึฟื•ืŸ ืžืงื•ืจ, ื–ื™ื™ืŸ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ, ืคื•ืœ ืื•ืŸ ืกืขืœืขืงื˜ื™ื•ื• ืคึผืจืึทืงืกื™ื™ื ื’ ื ื™ืฆืŸ NAT, ืงืึทื ืึทืœ ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’ ืฆื• ืขื˜ืœืขื›ืข ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืคึผืจืึทืงืกื™ ืกืขืจื•ื•ืขืจืก, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ืึท ืจืึทื•ื˜ืขืจ ืื•ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ืฅ. ืžื™ืจ ื ื•ืฆืŸ Debian 9 x64 ื•ื•ื™ ื“ื™ ืึทืก. ืึธื ื”ื™ื™ื‘ืŸ!

ื™ื ืกื˜ืึธืœื™ื ื’ 3proxy ืื•ืŸ ืœื•ื™ืคืŸ ืึท ืจืขื’ื•ืœืขืจ ืคึผืจืึทืงืกื™ ืกืขืจื•ื•ืขืจ

1. ื™ื ืกื˜ืึทืœื™ืจืŸ ifconfig (ืคึฟื•ืŸ ื“ื™ ื ืขืฅ ืžื›ืฉื™ืจื™ื ืคึผืขืงืœ)
apt-get install net-tools
2. ื™ื ืกื˜ืึทืœื™ืจืŸ ืžื™ื“ื ื™ื™ื˜ ืงืึทืžืึทื ื“ืขืจ
apt-get install mc
3. ืžื™ืจ ืื™ืฆื˜ ื”ืึธื‘ืŸ 2 ื™ื ื˜ืขืจืคื™ื™ืกื™ื–:
enp0s3 - ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง, ืงื•ืงื˜ ืื•ื™ืฃ ื“ื™ ืื™ื ื˜ืขืจื ืขื˜
enp0s8 - ื™ื ืขืจืœืขืš, ืžื•ื–ืŸ ืงื•ืงืŸ ืื™ืŸ ื“ื™ ื”ื™ื’ืข ื ืขืฅ
ืื•ื™ืฃ ืื ื“ืขืจืข ื“ืขื‘ื™ืึทืŸ-ื‘ืื–ื™ืจื˜ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื–, ื“ื™ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ื–ืขื ืขืŸ ื™ื•ื–ืฉืึทื•ื•ืึทืœื™ ื’ืขืจื•ืคืŸ eth0 ืื•ืŸ eth1.
ifconfig -a

ื™ื ืขืจืคื™ื™ืกื™ื–enp0s3: ืคืœืึทื’ืก = 4163 mtu 1500
inet 192.168.23.11 ื ืขื˜ืžืึทืกืง 255.255.255.0 ื‘ืจืึธื“ืงืึทืกื˜ 192.168.23.255
inet6 fe80::a00:27ff:fec2:bae4 prefixlen 64 scopeid 0x20 ether 08:00:27:c2:ba:e4 txqueuelen 1000 (ืขื˜ื”ืขืจื ืขื˜)
ืจืงืก ืคึผืึทืงื™ืฅ 6412 ื‘ื™ื˜ืขืก 8676619 (8.2 MiB)
ืจืงืก ืขืจืจืึธืจืก 0 ื“ืจืึทืคึผื˜ 0 ืึธื•ื•ื•ืขืจืจืึทื ื– 0 ืจืึทื 0
ื˜ืงืก ืคึผืึทืงื™ืฅ 1726 ื‘ื™ื˜ืขืก 289128 (282.3 ืงื™ื‘)
ื˜ืงืก ืขืจืจืึธืจืก 0 ื“ืจืึทืคึผื˜ 0 ืึธื•ื•ื•ืขืจืจืึทื ื– 0 ื˜ืจืขื’ืขืจ 0 ืงืึทืœื™ื–ืฉืึทื ื– 0

enp0s8: ืคืœืึทื’ืก = 4098 mtu 1500
ether 08:00:27:79:a7:e3 txqueuelen 1000 (ืขื˜ื”ืขืจื ืขื˜)
RX ืคึผืึทืงื™ืฅ 0 ื‘ื™ื˜ืขืก 0 (0.0 ื‘)
ืจืงืก ืขืจืจืึธืจืก 0 ื“ืจืึทืคึผื˜ 0 ืึธื•ื•ื•ืขืจืจืึทื ื– 0 ืจืึทื 0
TX ืคึผืึทืงื™ืฅ 0 ื‘ื™ื˜ืขืก 0 (0.0 ื‘)
ื˜ืงืก ืขืจืจืึธืจืก 0 ื“ืจืึทืคึผื˜ 0 ืึธื•ื•ื•ืขืจืจืึทื ื– 0 ื˜ืจืขื’ืขืจ 0 ืงืึทืœื™ื–ืฉืึทื ื– 0

ืœื: ืคืœืึทื’ืก=73 mtu 65536
inet 127.0.0.1 ื ืขื˜ืžืึทืกืง 255.0.0.0
inet6 :: 1 ืคึผืจืขืคื™ืงืกืœืขืŸ 128 scopeid 0x10 ืฉืœื™ื™ืฃ txqueuelen 1 (ืœืึธืงืึทืœ ืœื•ืคึผื‘ืึทืงืง)
RX ืคึผืึทืงื™ืฅ 0 ื‘ื™ื˜ืขืก 0 (0.0 ื‘)
ืจืงืก ืขืจืจืึธืจืก 0 ื“ืจืึทืคึผื˜ 0 ืึธื•ื•ื•ืขืจืจืึทื ื– 0 ืจืึทื 0
TX ืคึผืึทืงื™ืฅ 0 ื‘ื™ื˜ืขืก 0 (0.0 ื‘)
ื˜ืงืก ืขืจืจืึธืจืก 0 ื“ืจืึทืคึผื˜ 0 ืึธื•ื•ื•ืขืจืจืึทื ื– 0 ื˜ืจืขื’ืขืจ 0 ืงืึทืœื™ื–ืฉืึทื ื– 0

ื“ื™ enp0s8 ืฆื•ื‘ื™ื ื“ ืื™ื– ืื™ืฆื˜ ื ื™ืฉื˜ ื’ืขื ื™ืฆื˜, ืžื™ืจ ื•ื•ืขืœืŸ ื’ืขื‘ืŸ ืขืก ื•ื•ืขืŸ ืžื™ืจ ื•ื•ื™ืœืŸ ืฆื• ื ื•ืฆืŸ Proxy NAT ืึธื“ืขืจ NAT ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ. ืขืก ืื™ื– ื“ืขืžืึธืœื˜ ืึทื– ืขืก ื•ื•ืึธืœื˜ ื–ื™ื™ืŸ ืœืึทื“ื–ืฉื™ืงืึทืœ ืฆื• ื‘ืึทืฉื˜ื™ืžืขืŸ ืขืก ืึท ืกื˜ืึทื˜ื™ืง IP.

4. ืœืึธืžื™ืจ ืึธื ื”ื™ื™ื‘ืŸ ืฆื• ื™ื ืกื˜ืึทืœื™ืจืŸ 3proxy

4.1 ื™ื ืกื˜ืึธืœื™ื ื’ ื™ืงืขืจื“ื™ืง ืคึผืึทืงืึทื“ื–ืฉืึทื– ืคึฟืึทืจ ืงืึทืžืคึผื™ื™ืœื™ื ื’ 3proxy ืคึฟื•ืŸ ืงื•ื•ืืœืŸ

root@debian9:~# apt-get install build-essential libevent-dev libssl-dev -y

4.2. ืœืึธืžื™ืจ ืžืึทื›ืŸ ืึท ื˜ืขืงืข ืคึฟืึทืจ ื“ืึทื•ื ืœืึธื•ื“ื™ื ื’ ื“ื™ ืึทืจืงื™ื™ื•ื• ืžื™ื˜ ืžืงื•ืจื™ื

root@debian9:~# mkdir -p /opt/proxy

4.3. ื–ืืœ ืก ื’ื™ื™ืŸ ืฆื• ื“ืขื ื˜ืขืงืข

root@debian9:~# cd /opt/proxy

4.4. ืื™ืฆื˜ ืœืึธื–ืŸ ืื•ื ื“ื– ืืจืืคืงืืคื™ืข ื“ื™ ืœืขืฆื˜ืข 3proxy ืคึผืขืงืœ. ืื™ืŸ ื“ืขืจ ืฆื™ื™ื˜ ืคื•ืŸ ืฉืจื™ื™ื‘ืŸ, ื“ื™ ืœืขืฆื˜ืข ืกื˜ืึทื‘ื™ืœ ื•ื•ืขืจืกื™ืข ืื™ื– ื’ืขื•ื•ืขืŸ 0.8.12 (18/04/2018) ืืจืืคืงืืคื™ืข ืขืก ืคึฟื•ืŸ ื“ืขืจ ื‘ืึทืึทืžื˜ืขืจ 3proxy ื•ื•ืขื‘ื–ื™ื™ื˜ืœ

root@debian9:/opt/proxy# wget https://github.com/z3APA3A/3proxy/archive/0.8.12.tar.gz

4.5. ื–ืืœ ืก ืึทื ืคึผืึทืง ื“ื™ ื“ืึทื•ื ืœืึธื•ื“ื™ื“ ืึทืจืงื™ื™ื•ื•

root@debian9:/opt/proxy# tar zxvf 0.8.12.tar.gz

4.6. ื’ื™ื™ืŸ ืฆื• ื“ื™ ืึทื ืคึผืึทืงื˜ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืฆื• ื‘ื•ื™ืขืŸ ื“ืขื ืคึผืจืึธื’ืจืึทื

root@debian9:/opt/proxy# cd 3proxy-0.8.12

4.7. ื•ื•ื™ื™ึทื˜ืขืจ, ืžื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืœื™ื™ื’ืŸ ืึท ืฉื•ืจื” ืฆื• ื“ื™ ื›ืขื“ืขืจ ื˜ืขืงืข ืึทื–ื•ื™ ืึทื– ืื•ื ื“ื–ืขืจ ืกืขืจื•ื•ืขืจ ืื™ื– ื’ืึธืจ ืึทื ืึทื ืึทืžืึทืก (ืขืก ื˜ืึทืงืข ืึทืจื‘ืขื˜, ืึทืœืฅ ืื™ื– ืึธืคึผื’ืขืฉื˜ืขืœื˜, ืงืœื™ืขื ื˜ IPs ื–ืขื ืขืŸ ืคืึทืจื‘ืึธืจื’ืŸ)

root@debian9:/opt/proxy/3proxy-0.8.12# nano +29 src/proxy.h

ืœื™ื™ื’ ืึท ืฉื•ืจื”

#define ANONYMOUS 1

ื“ืจื•ืง Ctrl + x ืื•ืŸ ืึทืจื™ื™ึทืŸ ืฆื• ืจืึทื˜ืขื•ื•ืขืŸ ื“ื™ ืขื ื“ืขืจื•ื ื’ืขืŸ.

4.8. ื–ืืœ ืก ืึธื ื”ื™ื™ื‘ืŸ ืึทืกืขืžื‘ืึทืœื™ื ื’ ื“ื™ ืคึผืจืึธื’ืจืึทื

root@debian9:/opt/proxy/3proxy-0.8.12# make -f Makefile.Linux

ืžืึทื›ืŸืœืึธื’ืžืึทื›ืŸ [2]: ืœืึธื–ืŸ ื“ื™ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ '/opt/proxy/3proxy-0.8.12/src/plugins/TransparentPlugin'
ืžืึทื›ืŸ [1]: ืœืึธื–ืŸ ื“ื™ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ '/opt/proxy/3proxy-0.8.12/src'

ืงื™ื™ืŸ ืขืจืจืึธืจืก, ืœืึธืžื™ืจ ืคืึธืจื–ืขืฆืŸ.

4.9. ื™ื ืกื˜ืึทืœื™ืจืŸ ื“ื™ ืคึผืจืึธื’ืจืึทื ืื•ื™ืฃ ื“ื™ ืกื™ืกื˜ืขื

root@debian9:/opt/proxy/3proxy-0.8.12# make -f Makefile.Linux install

4.10. ื’ื™ื™ืŸ ืฆื• ื“ื™ ื•ื•ืึธืจืฆืœ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืื•ืŸ ื˜ืฉืขืง ื•ื•ื• ื“ื™ ืคึผืจืึธื’ืจืึทื ืื™ื– ืื™ื ืกื˜ืึทืœื™ืจืŸ

root@debian9:/opt/proxy/3proxy-0.8.12# cd ~/
root@debian9:~# whereis 3proxy

3proxy: /usr/local/bin/3proxy /usr/local/etc/3proxy

4.11. ืœืึธืžื™ืจ ืฉืึทืคึฟืŸ ืึท ื˜ืขืงืข ืคึฟืึทืจ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืขืก ืื•ืŸ ืœืึธื’ืก ืื™ืŸ ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ 'ืก ื”ื™ื™ื ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ

root@debian9:~# mkdir -p /home/joke/proxy/logs

4.12. ื’ื™ื™ืŸ ืฆื• ื“ื™ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ื•ื•ื• ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื–ืึธืœ ื–ื™ื™ืŸ

root@debian9:~# cd /home/joke/proxy/

4.13. ืฉืึทืคึฟืŸ ืึท ืœื™ื™ื“ื™ืง ื˜ืขืงืข ืื•ืŸ ื ืึธื›ืžืึทื›ืŸ ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื“ืึธืจื˜

root@debian9:/home/joke/proxy# cat > 3proxy.conf

3proxy.confื“ื™ื™ืžืึทืŸ
pidfile /home/joke/proxy/3proxy.pid
nserver 8.8.8.8
nscache 65536
ื‘ืึทื ื™ืฆืขืจ ื˜ืขืกื˜ืขืจ: CL:1234
ื˜ื™ื™ืžืึทื•ืฅ 1 5 30 60 180 1800 16 60
ืงืœืึธืฅ /home/joke/proxy/logs/3proxy.log D
ืœืึธื’ืคืึธืจืžืึทื˜ "- +_ืœ% ื˜.%. % ื .% ืคึผ % E % ื• % C: % c % ืจ: % ืจ % ืึธ % ืื™ืš % ื” % ื”"
ื“ืจื™ื™ืขืŸ 3
ืึธื˜ ืฉื˜ืึทืจืง
ื’ืœื™ื™ึทืš
ืœืึธื–ืŸ ื˜ืขืกื˜ืขืจ
ืกืึทืงืก -p3128
ืคืจืืงืกื™ -p8080

ืฆื• ืจืึทื˜ืขื•ื•ืขืŸ, ื“ืจื™ืงืŸ ืงื˜ืจืœ + ื–

4.14. ื–ืืœ ืก ืžืึทื›ืŸ ืึท ืคึผื™ื“ ื˜ืขืงืข ืึทื–ื•ื™ ืึทื– ืขืก ื–ืขื ืขืŸ ืงื™ื™ืŸ ืขืจืจืึธืจืก ื‘ืขืฉืึทืก ืกื˜ืึทืจื˜ืึทืคึผ.

root@debian9:/home/joke/proxy# cat > 3proxy.pid

ืฆื• ืจืึทื˜ืขื•ื•ืขืŸ, ื“ืจื™ืงืŸ ืงื˜ืจืœ + ื–

4.15. ื–ืืœ ืก ืงืึทื˜ืขืจ ื“ื™ ืคืจืืงืกื™ ืกืขืจื•ื•ืขืจ!

root@debian9:/home/joke/proxy# 3proxy /home/joke/proxy/3proxy.conf

4.16. ื–ืืœ ืก ื–ืขืŸ ืื•ื™ื‘ ื“ืขืจ ืกืขืจื•ื•ืขืจ ืื™ื– ืฆื•ื’ืขื”ืขืจื˜ ืื•ื™ืฃ ืคึผืึธืจืฅ

root@debian9:~/home/joke/proxy# netstat -nlp

ื ืขื˜ืกื˜ืึทื˜ ืงืœืึธืฅืึทืงื˜ื™ื•ื• ืื™ื ื˜ืขืจื ืขื˜ ืงืึทื ืขืงืฉืึทื ื– (ื‘ืœื•ื™ื– ืกืขืจื•ื•ืขืจืก)
ืคึผืจืึธื˜ืึธ ืจืขื•ื•-ืง ืฉื™ืงืŸ-ืง ืœืืงืืœืข ืึทื“ืจืขืก ืคืจืขืžื“ ืึทื“ืจืขืก ืฉื˜ืึทื˜ PID / ืคึผืจืึธื’ืจืึทื ื ืึธืžืขืŸ
tcp 0 0 0.0.0.0:8080 0.0.0.0:* ื”ืขืจืŸ 504/3ืคึผืจืึธืงืกื™
ื˜ืงืคึผ 0 0 0.0.0.0:22 0.0.0.0:* ื”ืขืจืŸ 338/ืฉื“
tcp 0 0 0.0.0.0:3128 0.0.0.0:* ื”ืขืจืŸ 504/3ืคึผืจืึธืงืกื™
tcp6 0 0 :::22 :::* ื”ืขืจืŸ 338/ืฉื“
ื•ื“ืคึผ 0 0 0.0.0.0:68 0.0.0.0:* 352/ื“ื”ืงืœื™ืขื ื˜

ื•ื•ื™ ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ, ืื•ื ื“ื–ืขืจ ื•ื•ืขื‘ ืคืจืืงืกื™ ืœื™ืกืึทื ื– ืฆื• ืคึผืึธืจื˜ 8080, Socks5 ืคืจืืงืกื™ ืœื™ืกืึทื ื– ืฆื• ืคึผืึธืจื˜ 3128.

4.17. ืฆื• ืึทื•ื˜ืึธืกื˜ืึทืจื˜ ื“ื™ ืคึผืจืึทืงืกื™ ื“ื™ื ืกื˜ ื ืึธืš ืึท ืจืขื‘ืึธืึธื˜, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืœื™ื™ื’ืŸ ืขืก ืฆื• Cron.

root@debian9:/home/joke/proxy# crontab -e

ืœื™ื™ื’ ืึท ืฉื•ืจื”

@reboot /usr/local/bin/3proxy /home/joke/proxy/3proxy.conf

ืžื™ืจ ื“ืจื™ืงืŸ ืึทืจื™ื™ึทืŸ, ื–ื™ื ื˜ Cron ื–ืึธืœ ื–ืขืŸ ื“ื™ ืกื•ืฃ ืคื•ืŸ ืฉื•ืจื” ื›ืึทืจืึทืงื˜ืขืจ ืื•ืŸ ืจืึทื˜ืขื•ื•ืขืŸ ื“ื™ ื˜ืขืงืข.

ืขืก ื–ืึธืœ ื–ื™ื™ืŸ ืึท ืึธื ื–ืึธื’ ื•ื•ืขื’ืŸ ื™ื ืกื˜ืึธืœื™ื ื’ ืึท ื ื™ื™ึท ืงืจืึธื ื˜ืึทื‘.

crontab: ื™ื ืกื˜ืึธืœื™ื ื’ ื ื™ื™ึท crontab

4.18. ืœืึธืžื™ืจ ืจืขื‘ืึธืึธื˜ ื“ื™ ืกื™ืกื˜ืขื ืื•ืŸ ืคึผืจื•ื‘ื™ืจืŸ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ื“ื™ ืคืจืืงืกื™ ื“ื•ืจืš ื“ืขื ื‘ืœืขื˜ืขืจืขืจ. ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ, ืžื™ืจ ื ื•ืฆืŸ ื“ื™ Firefox ื‘ืœืขื˜ืขืจืขืจ (ืคึฟืึทืจ ืึท ื•ื•ืขื‘ ืคืจืืงืกื™) ืื•ืŸ ื“ื™ FoxyProxy ืึทื“ื™ืฉืึทืŸ ืคึฟืึทืจ ืกืึทืงืก 5 ืžื™ื˜ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ.

root@debian9:/home/joke/proxy# reboot

4.19. ื ืึธืš ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ื“ื™ ืึธืคึผืขืจืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืคึผืจืึทืงืกื™ ื ืึธืš ืึท ืจืขื‘ืึธืึธื˜, ืื™ืจ ืงืขื ืขืŸ ื–ืขืŸ ื“ื™ ืœืึธื’ืก. ื“ืขื ืงืึทืžืคึผืœื™ืฅ ื“ื™ ืคึผืจืึทืงืกื™ ืกืขืจื•ื•ืขืจ ืกืขื˜ืึทืคึผ.

3 ืคืจืืงืกื™ ืงืœืึธืฅ1542573996.018 PROXY.8080 00000 ื˜ืขืกื˜ืขืจ 192.168.23.10:50915 217.12.15.54:443 1193 6939 0 CONNECT_ads.yahoo.com:443HTTP
1542574289.634 SOCK5.3128 00000 ื˜ืขืกื˜ืขืจ 192.168.23.10:51193 54.192.13.69:443 0 0 0 CONNECT_normandy.cdn.mozilla.net:443

ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื•ืŸ ืœื•ื™ืคืŸ ื˜ืจืึทื ืกืคึผืึทืจืขื ื˜ ืคึผืจืึธืงืกื™ NAT โ€‹โ€‹ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ

ืื™ืŸ ื“ืขื ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ, ืึทืœืข ื“ืขื•ื•ื™ืกืขืก ืื•ื™ืฃ ื“ื™ ื™ื ืขืจืœืขืš ื ืขืฅ ื•ื•ืขื˜ ื˜ืจืึทื ืกืคึผืขืจืึทื ื˜ ืึทืจื‘ืขื˜ืŸ ืื•ื™ืฃ ื“ื™ ืื™ื ื˜ืขืจื ืขื˜ ื“ื•ืจืš ืึท ื•ื•ื™ื™ึทื˜ ืคึผืจืึทืงืกื™ ืกืขืจื•ื•ืขืจ. ืœืขื’ืึทืžืจืข ืึทืœืข ื˜ืงืคึผ ืงืึทื ืขืงืฉืึทื ื– ื•ื•ืขื˜ ื–ื™ื™ืŸ ืจื™ื“ืขืจืขืงื˜ื™ื“ ืฆื• ืื™ื™ื ืขืจ ืึธื“ืขืจ ืžืขืจ (ื˜ืึทืงืข ื™ืงืกืคึผืึทื ื“ื– ื“ื™ ืงืึทื ืึทืœ ื‘ืจื™ื™ื˜, ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื‘ื™ื™ึทืฉืคึผื™ืœ ื ื•ืž 2!) ืคืจืืงืกื™ ืกืขืจื•ื•ืขืจืก. ื“ื™ ื“ื ืก ื“ื™ื ืกื˜ ื•ื•ืขื˜ ื ื•ืฆืŸ 3proxy (dnspr) ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื–. UDP ื•ื•ืขื˜ ื ื™ืฉื˜ "ื’ื™ื™ืŸ" ืึทื•ื˜ื•ื•ืขืจื“, ื•ื•ื™ื™ึทืœ ืžื™ืจ ื–ืขื ืขืŸ ื ื™ืฉื˜ ื ืึธืš ื ื™ืฆืŸ ื“ื™ ืคืึธืจื•ื™ืก ืžืขืงืึทื ื™ื–ืึทื (ืคืึทืจืงืจื™ืคึผืœื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ ืื™ืŸ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ).

1. ืขืก ืื™ื– ืฆื™ื™ื˜ ืฆื• ื’ืขื‘ืŸ ื“ื™ enp0s8 ืฆื•ื‘ื™ื ื“

root@debian9:~# nano /etc/network/interfaces

/etc/network/interfaces ื˜ืขืงืข# ื“ืขืจ ื˜ืขืงืข ื‘ืืฉืจื™ื™ื‘ื˜ ื“ื™ ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ื‘ื ื™ืžืฆื ืื•ื™ืฃ ื“ื™ื™ืŸ ืกื™ืกื˜ืขื
# ืื•ืŸ ื•ื•ื™ ืฆื• ืึทืงื˜ืึทื•ื•ื™ื™ื˜ ื–ื™ื™. ืคึฟืึทืจ ืžืขืจ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข, ื–ืขืŸ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– (5).

ืžืงื•ืจ /etc/network/interfaces.d/*

# ื“ื™ ืœื•ืคึผื‘ืึทืงืง ื ืขืฅ ืฆื•ื‘ื™ื ื“
ืžืึทืฉื™ืŸ ืขืก
ืื•ื™ื‘ ืขืก ืื™ื– ื ื™ืฉื˜ ืึท ืœื•ืคึผื‘ืึทืงืง

# ื“ื™ ืขืจืฉื˜ื™ืง ื ืขืฅ ืฆื•ื‘ื™ื ื“
ืœืึธื–ืŸ-ื”ืึธื˜ืคึผืœื•ื’ ืขื ืคึผ0ืก3
iface enp0s3 inet dhcp

# ื“ื™ ืฆื•ื•ื™ื™ื˜ื™ืง ื ืขืฅ ืฆื•ื‘ื™ื ื“
ืœืึธื–ืŸ-ื”ืึธื˜ืคึผืœื•ื’ ืขื ืคึผ0ืก8
iface enp0s8 ื™ื ืขื˜ ืกื˜ืึทื˜ื™ืง
ืึทื“ืจืขืก 192.168.201.254
ื ืขื˜ืžืึทืกืง 255.255.255.0

ื“ืึธ ืžื™ืจ ืึทืกื™ื™ื ื“ ื“ื™ enp0s8 ืฆื•ื‘ื™ื ื“ ืึท ืกื˜ืึทื˜ื™ืง ืึทื“ืจืขืก 192.168.201.254 ืื•ืŸ ืึท ืžืึทืกืงืข 255.255.255.0
ื”ื™ื˜ ื“ื™ ืงืึธื ืคื™ื’ื•ืจืึทื˜ื™ืึธืŸ Ctrl + X ืื•ืŸ ืจืขื‘ืึธืึธื˜

root@debian9:~# reboot

2. ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ื“ื™ ื™ื ื˜ืขืจืคื™ื™ืกื™ื–

root@debian9:~# ifconfig

ifconfig ืงืœืึธืฅenp0s3: ืคืœืึทื’ืก = 4163 mtu 1500
inet 192.168.23.11 ื ืขื˜ืžืึทืกืง 255.255.255.0 ื‘ืจืึธื“ืงืึทืกื˜ 192.168.23.255
inet6 fe80::a00:27ff:fec2:bae4 prefixlen 64 scopeid 0x20 ether 08:00:27:c2:ba:e4 txqueuelen 1000 (ืขื˜ื”ืขืจื ืขื˜)
ืจืงืก ืคึผืึทืงื™ืฅ 61 ื‘ื™ื˜ืขืก 7873 (7.6 ืงื™ื‘)
ืจืงืก ืขืจืจืึธืจืก 0 ื“ืจืึทืคึผื˜ 0 ืึธื•ื•ื•ืขืจืจืึทื ื– 0 ืจืึทื 0
ื˜ืงืก ืคึผืึทืงื™ืฅ 65 ื‘ื™ื˜ืขืก 10917 (10.6 ืงื™ื‘)
ื˜ืงืก ืขืจืจืึธืจืก 0 ื“ืจืึทืคึผื˜ 0 ืึธื•ื•ื•ืขืจืจืึทื ื– 0 ื˜ืจืขื’ืขืจ 0 ืงืึทืœื™ื–ืฉืึทื ื– 0

enp0s8: ืคืœืึทื’ืก = 4163 mtu 1500
inet 192.168.201.254 ื ืขื˜ืžืึทืกืง 255.255.255.0 ื‘ืจืึธื“ืงืึทืกื˜ 192.168.201.255
inet6 fe80::a00:27ff:fe79:a7e3 prefixlen 64 scopeid 0x20 ether 08:00:27:79:a7:e3 txqueuelen 1000 (ืขื˜ื”ืขืจื ืขื˜)
RX ืคึผืึทืงื™ืฅ 0 ื‘ื™ื˜ืขืก 0 (0.0 ื‘)
ืจืงืก ืขืจืจืึธืจืก 0 ื“ืจืึทืคึผื˜ 0 ืึธื•ื•ื•ืขืจืจืึทื ื– 0 ืจืึทื 0
TX ืคึผืึทืงื™ืฅ 8 ื‘ื™ื˜ืขืก 648 (648.0 ื‘)
ื˜ืงืก ืขืจืจืึธืจืก 0 ื“ืจืึทืคึผื˜ 0 ืึธื•ื•ื•ืขืจืจืึทื ื– 0 ื˜ืจืขื’ืขืจ 0 ืงืึทืœื™ื–ืฉืึทื ื– 0

ืœื: ืคืœืึทื’ืก=73 mtu 65536
inet 127.0.0.1 ื ืขื˜ืžืึทืกืง 255.0.0.0
inet6 :: 1 ืคึผืจืขืคื™ืงืกืœืขืŸ 128 scopeid 0x10 ืฉืœื™ื™ืฃ txqueuelen 1 (ืœืึธืงืึทืœ ืœื•ืคึผื‘ืึทืงืง)
RX ืคึผืึทืงื™ืฅ 0 ื‘ื™ื˜ืขืก 0 (0.0 ื‘)
ืจืงืก ืขืจืจืึธืจืก 0 ื“ืจืึทืคึผื˜ 0 ืึธื•ื•ื•ืขืจืจืึทื ื– 0 ืจืึทื 0
TX ืคึผืึทืงื™ืฅ 0 ื‘ื™ื˜ืขืก 0 (0.0 ื‘)
ื˜ืงืก ืขืจืจืึธืจืก 0 ื“ืจืึทืคึผื˜ 0 ืึธื•ื•ื•ืขืจืจืึทื ื– 0 ื˜ืจืขื’ืขืจ 0 ืงืึทืœื™ื–ืฉืึทื ื– 0

3. ืึทืœืฅ ื’ืขืืจื‘ืขื˜ ืื•ื™ืก, ืื™ืฆื˜ ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ 3proxy ืคึฟืึทืจ ื˜ืจืึทื ืกืคึผืขืจืึทื ื˜ ืคึผืจืึทืงืกื™ื™ื ื’.

root@debian9:~# cd /home/joke/proxy/
root@debian9:/home/joke/proxy# cat > 3proxytransp.conf

ื‘ื™ื™ึทืฉืคึผื™ืœ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืคื•ืŸ ื˜ืจืึทื ืกืคึผืขืจืึทื ื˜ ืคืจืืงืกื™ ืกืขืจื•ื•ืขืจ ื ื•ืž 1ื“ื™ื™ืžืึทืŸ
pidfile /home/joke/proxy/3proxy.pid
nserver 8.8.8.8
nscache 65536
ื˜ื™ื™ืžืึทื•ืฅ 1 5 30 60 180 1800 16 60
ืงืœืึธืฅ /home/joke/proxy/logs/3proxy.log D
ืœืึธื’ืคืึธืจืžืึทื˜ "- +_ืœ% ื˜.%. % ื .% ืคึผ % E % ื• % C: % c % ืจ: % ืจ % ืึธ % ืื™ืš % ื” % ื”"
ื“ืจื™ื™ืขืŸ 3
ื’ืœื™ื™ึทืš
ืึทื•ื˜ื” ื™ืคึผืึธื ืœื™
dnspr
ืœืึธื–ืŸ *
ืคืึธื˜ืขืจ 1000 ืกืึทืงืก 5 IP_ADDRESS ืคื•ืŸ EXTERNAL_PROXY 3128 ื˜ืขืกื˜ืขืจ 1234
ืคึผืœื•ื’ื™ืŸ /opt/proxy/3proxy-0.8.12/src/TransparentPlugin.ld.so transparent_plugin
tcppm -i0.0.0.0 888 127.0.0.1 11111

4. ืื™ืฆื˜ ืžื™ืจ ืงืึทื˜ืขืจ 3proxy ืžื™ื˜ ื“ื™ ื ื™ื™ึท ืงืึธื ืคื™ื’
root@debian9:/home/joke/proxy# /usr/local/bin/3proxy /home/joke/proxy/3proxytransp.conf

5. ืœื™ื™ื’ ืฆื• ืงืจืึธื ื˜ืึทื‘ ื•ื•ื™ื“ืขืจ
root@debian9:/home/joke/proxy# crontab -e
@reboot /usr/local/bin/3proxy /home/joke/proxy/3proxytransp.conf

6. ืœืึธืžื™ืจ ื–ืขืŸ ื•ื•ืึธืก ืื•ื ื“ื–ืขืจ ืคืจืืงืกื™ ืื™ื– ืื™ืฆื˜ ืฆื•ื’ืขื”ืขืจื˜
root@debian9:~# netstat -nlp

ื ืขื˜ืกื˜ืึทื˜ ืงืœืึธืฅืึทืงื˜ื™ื•ื• ืื™ื ื˜ืขืจื ืขื˜ ืงืึทื ืขืงืฉืึทื ื– (ื‘ืœื•ื™ื– ืกืขืจื•ื•ืขืจืก)
ืคึผืจืึธื˜ืึธ ืจืขื•ื•-ืง ืฉื™ืงืŸ-ืง ืœืืงืืœืข ืึทื“ืจืขืก ืคืจืขืžื“ ืึทื“ืจืขืก ืฉื˜ืึทื˜ PID / ืคึผืจืึธื’ืจืึทื ื ืึธืžืขืŸ
ื˜ืงืคึผ 0 0 0.0.0.0:22 0.0.0.0:* ื”ืขืจืŸ 349/ืฉื“
tcp 0 0 0.0.0.0:888 0.0.0.0:* ื”ืขืจืŸ 354/3ืคึผืจืึธืงืกื™
tcp6 0 0 :::22 :::* ื”ืขืจืŸ 349/ืฉื“
ื•ื“ืคึผ 0 0 0.0.0.0:53 0.0.0.0:* 354/3ืคึผืจืึธืงืกื™
ื•ื“ืคึผ 0 0 0.0.0.0:68 0.0.0.0:* 367/ื“ื”ืงืœื™ืขื ื˜

7. ืื™ืฆื˜ ื“ื™ ืคึผืจืึทืงืกื™ ืื™ื– ื’ืจื™ื™ื˜ ืฆื• ืึธื ื ืขืžืขืŸ ืงื™ื™ืŸ ื˜ืงืคึผ ืงืึทื ืขืงืฉืึทื ื– ืื•ื™ืฃ ืคึผืึธืจื˜ 888, ื“ื ืก ืื•ื™ืฃ ืคึผืึธืจื˜ 53, ืึทื–ื•ื™ ืึทื– ื–ื™ื™ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืจื™ื“ืขืจืขืงื˜ื™ื“ ืฆื• ื“ื™ ื•ื•ื™ื™ึทื˜ ืกืึทืงืก5 ืคืจืืงืกื™ ืื•ืŸ ื“ื ืก ื’ื•ื’ืœ 8.8.8.8. ื›ืœ ืžื™ืจ ื”ืึธื‘ืŸ ืฆื• ื˜ืึธืŸ ืื™ื– ืงืึทื ืคื™ื’ื™ืขืจ ื ืขื˜ืคื™ืœื˜ืขืจ (ื™ืคึผื˜ืึทื‘ืœืขืก) ืื•ืŸ DHCP ื›ึผืœืœื™ื ืคึฟืึทืจ ืึทืจื•ื™ืกื’ืขื‘ืŸ ื•ื•ืขื ื“ื˜.

8. ื™ื ืกื˜ืึทืœื™ืจืŸ ื“ื™ iptables-persistent ืื•ืŸ dhcpd ืคึผืขืงืœ

root@debian9:~# apt-get install iptables-persistent isc-dhcp-server

9. ืจืขื“ืึทื’ื™ืจืŸ ื“ื™ ื“ื”ืงืคึผื“ ืกื˜ืึทืจื˜ืึทืคึผ ื˜ืขืงืข
root@debian9:~# nano /etc/dhcp/dhcpd.conf

dhcpd.conf# dhcpd.conf
#
# ืžื•ืกื˜ืขืจ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข ืคึฟืึทืจ ISC dhcpd
#

# ืึธืคึผืฆื™ืข ื“ืขืคึฟื™ื ื™ืฆื™ืข ืคึผืจืึธืกื˜ ืคึฟืึทืจ ืึทืœืข ื’ืขืฉื˜ื™ืฆื˜ ื ืขื˜ื•ื•ืึธืจืงืก ...
ืึธืคึผืฆื™ืข ืคืขืœื“ ื ืึธืžืขืŸ "example.org";
ืึธืคึผืฆื™ืข ืคืขืœื“ ื ืึธืžืขืŸ ืกืขืจื•ื•ืขืจืก ns1.example.org, ns2.example.org;

ืคืขืœื™ืงื™ื™ึทื˜-ื“ื™ื ื’ืขืŸ-ืฆื™ื™ึทื˜ 600;
ืžืึทืงืก-ื“ื™ื ื’ืขืŸ-ืฆื™ื™ื˜ 7200;

ddns-update-style ื’ืึธืจื ื™ื˜;

# ืื•ื™ื‘ ื“ืขืจ DHCP ืกืขืจื•ื•ืขืจ ืื™ื– ื“ืขืจ ื‘ืึทืึทืžื˜ืขืจ DHCP ืกืขืจื•ื•ืขืจ ืคึฟืึทืจ ื“ื™ ื”ื™ื’ืข
# ื ืขืฅ, ื“ื™ ืึทื˜ืึธืจืึทื˜ื™ื™ื˜ื™ื•ื• ื“ื™ืจืขืงื˜ื™ื•ื• ื–ืึธืœ ื–ื™ื™ืŸ ืึทื ืงืึทืžืขื ื˜ืึทื“.

ืึทื˜ืึธืจืึทื˜ื™ื™ื˜ื™ื•ื•;

# ื ื‘ื™ืกืœ ืึทื ื“ืขืจืฉ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืคึฟืึทืจ ืึทืŸ ื™ื ืขืจืœืขืš ืกื•ื‘ื ืขื˜.
ืกื•ื‘ื ืขื˜ 192.168.201.0 ื ืขื˜ืžืึทืกืง 255.255.255.0 {
ืงื™ื™ื˜ 192.168.201.10 192.168.201.250;
ืึธืคึผืฆื™ืข ืคืขืœื“ ื ืึธืžืขืŸ ืกืขืจื•ื•ืขืจืก 192.168.201.254;
ืึธืคึผืฆื™ืข ืจืึธื•ื˜ืขืจืก 192.168.201.254;
ืึธืคึผืฆื™ืข ื‘ืจืึธื“ืงืึทืกื˜-ืึทื“ืจืขืก 192.168.201.255;
ืคืขืœื™ืงื™ื™ึทื˜-ื“ื™ื ื’ืขืŸ-ืฆื™ื™ึทื˜ 600;
ืžืึทืงืก-ื“ื™ื ื’ืขืŸ-ืฆื™ื™ื˜ 7200;
}

11. ืจืขื‘ืึธืึธื˜ ืื•ืŸ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ื“ื™ื ืกื˜ ืื•ื™ืฃ ืคึผืึธืจื˜ 67
root@debian9:~# reboot
root@debian9:~# netstat -nlp

ื ืขื˜ืกื˜ืึทื˜ ืงืœืึธืฅืึทืงื˜ื™ื•ื• ืื™ื ื˜ืขืจื ืขื˜ ืงืึทื ืขืงืฉืึทื ื– (ื‘ืœื•ื™ื– ืกืขืจื•ื•ืขืจืก)
ืคึผืจืึธื˜ืึธ ืจืขื•ื•-ืง ืฉื™ืงืŸ-ืง ืœืืงืืœืข ืึทื“ืจืขืก ืคืจืขืžื“ ืึทื“ืจืขืก ืฉื˜ืึทื˜ PID / ืคึผืจืึธื’ืจืึทื ื ืึธืžืขืŸ
ื˜ืงืคึผ 0 0 0.0.0.0:22 0.0.0.0:* ื”ืขืจืŸ 389/ืฉื“
tcp 0 0 0.0.0.0:888 0.0.0.0:* ื”ืขืจืŸ 310/3ืคึผืจืึธืงืกื™
tcp6 0 0 :::22 :::* ื”ืขืจืŸ 389/ืฉื“
ื•ื“ืคึผ 0 0 0.0.0.0:20364 0.0.0.0:* 393/dhcpd
ื•ื“ืคึผ 0 0 0.0.0.0:53 0.0.0.0:* 310/3ืคึผืจืึธืงืกื™
ื•ื“ืคึผ 0 0 0.0.0.0:67 0.0.0.0:* 393/dhcpd
ื•ื“ืคึผ 0 0 0.0.0.0:68 0.0.0.0:* 405/ื“ื”ืงืœื™ืขื ื˜
udp6 0 0 :::31728 :::* 393/dhcpd
ืจื•ื™ 0 0 0.0.0.0:1 0.0.0.0:* 393/ื“ื”ืงืคึผื“

12. ืึทืœืข ื•ื•ืึธืก ื‘ืœื™ื™ื‘ื˜ ืื™ื– ืฆื• ืจื™ื“ืขืจืขืงื˜ ืึทืœืข ื˜ืงืคึผ ืจื™ืงื•ื•ืขืก ืฆื• ืคึผืึธืจื˜ 888 ืื•ืŸ ืจืึทื˜ืขื•ื•ืขืŸ ื“ื™ ื”ืขืจืฉืŸ ืื™ืŸ iptables

root@debian9:~# iptables -t nat -A PREROUTING -s 192.168.201.0/24 -p tcp -j REDIRECT --to-ports 888

root@debian9:~# iptables-save > /etc/iptables/rules.v4

13. ืฆื• ื™ืงืกืคึผืึทื ื“ ื“ื™ ืงืึทื ืึทืœ ื‘ืึทื ื“ื•ื•ื™ื“ื˜, ืื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ืขื˜ืœืขื›ืข ืคืจืืงืกื™ ืกืขืจื•ื•ืขืจืก ืื™ืŸ ืึทืžืึธืœ. ื“ื™ ื’ืึทื ืฅ ืžื•ื–ืŸ ื–ื™ื™ืŸ 1000. ื ื™ื• ืงืึทื ืขืงืฉืึทื ื– ื–ืขื ืขืŸ ื’ืขื’ืจื™ื ื“ืขื˜ ืžื™ื˜ ืึท ืžืึทืฉืžืึธืขืก ืคื•ืŸ 0.2, 0.2, 0.2, 0.2, 0,1, 0,1 ืฆื• ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ืคึผืจืึทืงืกื™ ืกืขืจื•ื•ืขืจืก.

ื‘ืึทืžืขืจืงื•ื ื’: ืื•ื™ื‘ ืžื™ืจ ื”ืึธื‘ืŸ ืึท ื•ื•ืขื‘ ืคืจืืงืกื™, ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ืกืึทืงืก 5 ืžื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืฉืจื™ื™ึทื‘ืŸ ืงืึธื ื ืขืงื˜, ืื•ื™ื‘ ืกืึทืงืก 4, ืกืึธืงืก 4 (ืกืึธืงืงืก 4 ื˜ื•ื˜ ื ื™ืฉื˜ ืฉื˜ื™ืฆืŸ ืœืึธื’ื™ืŸ / ืคึผืึทืจืึธืœ ืึทื•ื˜ื”ืึธืจื™ื–ืึทื˜ื™ืึธืŸ!)

ื‘ื™ื™ึทืฉืคึผื™ืœ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืคื•ืŸ ื˜ืจืึทื ืกืคึผืขืจืึทื ื˜ ืคืจืืงืกื™ ืกืขืจื•ื•ืขืจ ื ื•ืž 2ื“ื™ื™ืžืึทืŸ
pidfile /home/joke/proxy/3proxy.pid
nserver 8.8.8.8
nscache 65536
maxconn 500
ื˜ื™ื™ืžืึทื•ืฅ 1 5 30 60 180 1800 16 60
ืงืœืึธืฅ /home/joke/proxy/logs/3proxy.log D
ืœืึธื’ืคืึธืจืžืึทื˜ "- +_ืœ% ื˜.%. % ื .% ืคึผ % E % ื• % C: % c % ืจ: % ืจ % ืึธ % ืื™ืš % ื” % ื”"
ื“ืจื™ื™ืขืŸ 3
ื’ืœื™ื™ึทืš
ืึทื•ื˜ื” ื™ืคึผืึธื ืœื™
dnspr
ืœืึธื–ืŸ *

ืคืึธื˜ืขืจ 200 ืกืึทืงืก5 IP_ADDRESS_EXTERNAL_PROXY#1 3128 ื˜ืขืกื˜ืขืจ 1234
ืคืึธื˜ืขืจ 200 ืกืึทืงืก5 IP_ADDRESS_EXTERNAL_PROXY#2 3128 ื˜ืขืกื˜ืขืจ 1234
ืคืึธื˜ืขืจ 200 ืกืึทืงืก5 IP_ADDRESS_EXTERNAL_PROXY#3 3128 ื˜ืขืกื˜ืขืจ 1234
ืคืึธื˜ืขืจ 200 ืกืึทืงืก5 IP_ADDRESS_EXTERNAL_PROXY#4 3128 ื˜ืขืกื˜ืขืจ 1234
ืคืึธื˜ืขืจ 100 ืกืึทืงืก5 IP_ADDRESS_EXTERNAL_PROXY#5 3128 ื˜ืขืกื˜ืขืจ 1234
ืคืึธื˜ืขืจ 100 ืกืึทืงืก5 IP_ADDRESS_EXTERNAL_PROXY#6 3128 ื˜ืขืกื˜ืขืจ 1234

ืคึผืœื•ื’ื™ืŸ /opt/proxy/3proxy-0.8.12/src/TransparentPlugin.ld.so transparent_plugin
tcppm -i0.0.0.0 888 127.0.0.1 11111

ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื•ืŸ ืœื•ื™ืคืŸ NAT + ื˜ืจืึทื ืกืคึผืึทืจืขื ื˜ ืคึผืจืึธืงืกื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ

ืื™ืŸ ื“ืขื ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ, ืžื™ืจ ื•ื•ืขืœืŸ ื ื•ืฆืŸ ื“ื™ ื’ืขื•ื•ื™ื™ื ื˜ืœืขืš NAT ืžืขืงืึทื ื™ื–ืึทื ืžื™ื˜ ืกืขืœืขืงื˜ื™ื•ื• ืึธื“ืขืจ ืคื•ืœ ื˜ืจืึทื ืกืคึผืขืจืึทื ื˜ ืคึผืจืึทืงืกื™ื™ื ื’ ืคื•ืŸ ื™ื—ื™ื“ ืึทื“ืจืขืกืขืก ืึธื“ืขืจ ืกื•ื‘ื ืขืฅ. ืื™ื ืขืจืœืขื›ืขืจ ื ืขืฅ ื ื™ืฆืขืจืก ื•ื•ืขืœืŸ ืึทืจื‘ืขื˜ืŸ ืžื™ื˜ ื–ื™ื›ืขืจ ื‘ืึทื“ื™ื ื•ื ื’ืก / ืกื•ื‘ื ืขืฅ ืึธืŸ ืืคื™ืœื• ืจื™ืึทืœื™ื™ื–ื™ื ื’ ืึทื– ื–ื™ื™ ืึทืจื‘ืขื˜ืŸ ื“ื•ืจืš ืึท ืคืจืืงืกื™. ืึทืœืข ื”ื˜ื˜ืคึผืก ืงืึทื ืขืงืฉืึทื ื– ืึทืจื‘ืขื˜ ื’ื•ื˜, ืงื™ื™ืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ื“ืึทืจืคึฟืŸ ืฆื• ื–ื™ื™ืŸ ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ / ืจื™ืคึผืœื™ื™ืกื˜.

ืขืจืฉื˜ืขืจ, ืœืึธื–ืŸ ืื•ื ื“ื– ื‘ืึทืฉืœื™ืกืŸ ื•ื•ืึธืก ืกื•ื‘ื ืขืฅ / ื‘ืึทื“ื™ื ื•ื ื’ืก ืžื™ืจ ื•ื•ื™ืœืŸ ืฆื• ืคึผืจืึทืงืกื™. ืœืึธืžื™ืจ ื™ื‘ืขืจื ืขืžืขืŸ ืึทื– ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืคึผืจืึทืงืกื™ื– ื–ืขื ืขืŸ ืœื™ื’ืŸ ื•ื•ื• ืึท ืกืขืจื•ื•ื™ืก ื•ื•ื™ pandora.com ืึทืคึผืขืจื™ื™ืฅ. ืื™ืฆื˜ ืขืก ื‘ืœื™ื™ื‘ื˜ ืฆื• ื‘ืึทืฉื˜ื™ืžืขืŸ ื–ื™ื™ึทืŸ ืกื•ื‘ื ืขืฅ / ื•ื•ืขื ื“ื˜.

1. ืคึผื™ื ื’

root@debian9:~# ping pandora.com
PING pandora.com (208.85.40.20) 56 (84) ื‘ื™ื˜ืขืก ืคื•ืŸ ื“ืึทื˜ืŸ.

2. ื˜ื™ืคึผ BGP 208.85.40.20 ืื™ืŸ Google

ื–ืืœ ืก ื’ื™ื™ืŸ ืฆื• ื“ื™ ืคึผืœืึทืฅ bgp.he.net/net/208.85.40.0/24#_netinfo
ืขืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื–ืขืŸ ืึทื– ื“ื™ ืกื•ื‘ื ืขื˜ ืื™ืš ื‘ื™ืŸ ืงื•ืงืŸ ืคึฟืึทืจ ืื™ื– AS40428 Pandora Media, Inc

bgp.he.net/net/208.85.40.0/24#_netinfo

ืขืคืŸ v4 ืคึผืจืขืคื™ืงืก

bgp.he.net/AS40428#_prefixes

ื“ืึธ ื–ืขื ืขืŸ ื“ื™ ืคืืจืœืื ื’ื˜ ืกื•ื‘ื ืขืฅ!

199.116.161.0/24
199.116.162.0/24
199.116.164.0/23
199.116.164.0/24
199.116.165.0/24
208.85.40.0/24
208.85.41.0/24
208.85.42.0/23
208.85.42.0/24
208.85.43.0/24
208.85.44.0/24
208.85.46.0/23
208.85.46.0/24
208.85.47.0/24

3. ืฆื• ืจืขื“ื•ืฆื™ืจืŸ ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ืกื•ื‘ื ืขืฅ, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ืึทื’ื’ืจืขื’ืึทื˜ื™ืึธืŸ. ื’ื™ื™ืŸ ืฆื• ื“ื™ ืคึผืœืึทืฅ ip-calculator.ru/aggregate ืื•ืŸ ื ืึธื›ืžืึทื›ืŸ ืื•ื ื“ื–ืขืจ ืจืฉื™ืžื” ื“ืึธืจื˜. ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜ - 6 ืกื•ื‘ื ืขืฅ ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ 14.

199.116.161.0/24
199.116.162.0/24
199.116.164.0/23
208.85.40.0/22
208.85.44.0/24
208.85.46.0/23

4. ืงืœืึธืจ ื™ืคึผื˜ืึทื‘ืœืขืก ื›ึผืœืœื™ื

root@debian9:~# iptables -F
root@debian9:~# iptables -X
root@debian9:~# iptables -t nat -F
root@debian9:~# iptables -t nat -X

ื’ืขื‘ืŸ ื“ื™ ืคืึธืจื•ื™ืก ืื•ืŸ NAT ืžืขืงืึทื ื™ื–ืึทื

root@debian9:~# echo 1 > /proc/sys/net/ipv4/ip_forward
root@debian9:~# iptables -A FORWARD -i enp0s3 -o enp0s8 -j ACCEPT
root@debian9:~# iptables -A FORWARD -i enp0s8 -o enp0s3 -j ACCEPT
root@debian9:~# iptables -t nat -A POSTROUTING -o enp0s3 -s 192.168.201.0/24 -j MASQUERADE

ืฆื• ืขื ืฉื•ืจ ืึทื– ืคืึธืจื•ื™ืก ืื™ื– ืขื ื™ื™ื‘ืึทืœื“ ืคึผืขืจืžืึทื ืึทื ื˜ืœื™ ื ืึธืš ืึท ืจืขื‘ืึธืึธื˜, ืœืึธื–ืŸ ืื•ื ื“ื– ื˜ื•ื™ืฉืŸ ื“ื™ ื˜ืขืงืข

root@debian9:~# nano /etc/sysctl.conf

ืื•ืŸ ื ืขื ืึทื•ื•ืขืง ื“ื™ ืฉื•ืจื”

net.ipv4.ip_forward = 1

Ctrl + X ืฆื• ืจืึทื˜ืขื•ื•ืขืŸ ื“ื™ ื˜ืขืงืข

5. ืžื™ืจ ื™ื™ึทื ื•ื•ื™ืงืœืขืŸ pandora.com ืกื•ื‘ื ืขืฅ ืื™ืŸ ืึท ืคืจืืงืกื™

root@debian9:~# iptables -t nat -A PREROUTING -s 192.168.201.0/24 -d 199.116.161.0/24,199.116.162.0/24,199.116.164.0/23,208.85.40.0/22,208.85.44.0/24,208.85.46.0/23 -p tcp -j REDIRECT --to-ports 888

6. ืœืึธืžื™ืจ ื”ืึทืœื˜ืŸ ื“ื™ ื›ึผืœืœื™ื

root@debian9:~# iptables-save > /etc/iptables/rules.v4

ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื•ืŸ ืœื•ื™ืคืŸ ื“ื™ ื˜ืจืึทื ืกืคึผืึทืจืขื ื˜ ืคึผืจืึธืงืกื™ ื“ื•ืจืš ืจืึทื•ื˜ืขืจ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ

ืื™ืŸ ื“ืขื ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ, ื“ื™ ื˜ืจืึทื ืกืคึผืขืจืึทื ื˜ ืคืจืืงืกื™ ืกืขืจื•ื•ืขืจ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืคึผื™ืกื™ ืึธื“ืขืจ ืึท ื•ื•ื™ืจื˜ื•ืึทืœ ืžืึทืฉื™ืŸ ื”ื™ื ื˜ืขืจ ืึท ื”ื™ื™ื / ืคึฟื™ืจืžืข ืจืึทื•ื˜ืขืจ. ืขืก ืื™ื– ื’ืขื ื•ื’ ืฆื• ืคืึทืจืฉืจื™ื™ึทื‘ืŸ ืกื˜ืึทื˜ื™ืง ืจื•ืฅ ืื•ื™ืฃ ื“ื™ ืจืึทื•ื˜ืขืจ ืึธื“ืขืจ ื“ื™ื•ื•ื™ื™ืกืึทื– ืื•ืŸ ื“ื™ ื’ืื ืฆืข ืกื•ื‘ื ืขื˜ ื•ื•ืขื˜ ื ื•ืฆืŸ ืึท ืคึผืจืึทืงืกื™ ืึธืŸ ื“ื™ ื ื•ื™ื˜ ืคึฟืึทืจ ื ืึธืš ืกืขื˜ื˜ื™ื ื’ืก.

ื•ื•ื™ื›ื˜ื™ืง! ืขืก ืื™ื– ื ื™ื™ื˜ื™ืง ืึทื– ืื•ื ื“ื–ืขืจ ื’ื™ื™ื˜ื•ื•ื™ื™ ื ืขืžื˜ ืึท ืกื˜ืึทื˜ื™ืง IP ืคื•ืŸ ื“ื™ ืจืึทื•ื˜ืขืจ, ืึธื“ืขืจ ืื™ื– ืงืึทื ืคื™ื’ื™ืขืจื“ ืฆื• ื–ื™ื™ืŸ ืกื˜ืึทื˜ื™ืง ื–ื™ืš.

1. ืงืึทื ืคื™ื’ื™ืขืจ ืึท ืกื˜ืึทื˜ื™ืง ื’ื™ื™ื˜ื•ื•ื™ื™ ืึทื“ืจืขืก (enp0s3 ืึทื“ืึทืคึผื˜ืขืจ)

root@debian9:~# nano /etc/network/interfaces

/etc/network/interfaces ื˜ืขืงืข# ื“ืขืจ ื˜ืขืงืข ื‘ืืฉืจื™ื™ื‘ื˜ ื“ื™ ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ื‘ื ื™ืžืฆื ืื•ื™ืฃ ื“ื™ื™ืŸ ืกื™ืกื˜ืขื
# ืื•ืŸ ื•ื•ื™ ืฆื• ืึทืงื˜ืึทื•ื•ื™ื™ื˜ ื–ื™ื™. ืคึฟืึทืจ ืžืขืจ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข, ื–ืขืŸ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– (5).

ืžืงื•ืจ /etc/network/interfaces.d/*

# ื“ื™ ืœื•ืคึผื‘ืึทืงืง ื ืขืฅ ืฆื•ื‘ื™ื ื“
ืžืึทืฉื™ืŸ ืขืก
ืื•ื™ื‘ ืขืก ืื™ื– ื ื™ืฉื˜ ืึท ืœื•ืคึผื‘ืึทืงืง

# ื“ื™ ืขืจืฉื˜ื™ืง ื ืขืฅ ืฆื•ื‘ื™ื ื“
ืœืึธื–ืŸ-ื”ืึธื˜ืคึผืœื•ื’ ืขื ืคึผ0ืก3
iface enp0s3 ื™ื ืขื˜ ืกื˜ืึทื˜ื™ืง
ืึทื“ืจืขืก 192.168.23.2
ื ืขื˜ืžืึทืกืง 255.255.255.0
ื˜ื•ื™ืขืจ 192.168.23.254

# ื“ื™ ืฆื•ื•ื™ื™ื˜ื™ืง ื ืขืฅ ืฆื•ื‘ื™ื ื“
ืœืึธื–ืŸ-ื”ืึธื˜ืคึผืœื•ื’ ืขื ืคึผ0ืก8
iface enp0s8 ื™ื ืขื˜ ืกื˜ืึทื˜ื™ืง
ืึทื“ืจืขืก 192.168.201.254
ื ืขื˜ืžืึทืกืง 255.255.255.0

2. ืœืึธื–ืŸ ื“ืขื•ื•ื™ืกืขืก ืคึฟื•ืŸ ื“ื™ 192.168.23.0/24 ืกื•ื‘ื ืขื˜ ืฆื• ื ื•ืฆืŸ ืคึผืจืึทืงืกื™ื™ื ื’

root@debian9:~# iptables -t nat -A PREROUTING -s 192.168.23.0/24 -d 199.116.161.0/24,199.116.162.0/24,199.116.164.0/23,208.85.40.0/22,208.85.44.0/24,208.85.46.0/23 -p tcp -j REDIRECT --to-ports 888

3. ืœืึธืžื™ืจ ื”ืึทืœื˜ืŸ ื“ื™ ื›ึผืœืœื™ื
root@debian9:~# iptables-save > /etc/iptables/rules.v4

4. ื–ืืœ ืก ืจืขื’ื™ืกื˜ืจื™ืจืŸ ืกื•ื‘ื ืขืฅ ืื•ื™ืฃ ื“ื™ ืจืึทื•ื˜ืขืจ

ืจืึธื•ื˜ืขืจ ื ืขืฅ ืจืฉื™ืžื”ืงืกื ื•ืžืงืก ืงืกื ื•ืžืงืก ืงืกื ื•ืžืงืก
ืงืกื ื•ืžืงืก ืงืกื ื•ืžืงืก ืงืกื ื•ืžืงืก
ืงืกื ื•ืžืงืก ืงืกื ื•ืžืงืก ืงืกื ื•ืžืงืก
ืงืกื ื•ืžืงืก ืงืกื ื•ืžืงืก ืงืกื ื•ืžืงืก
ืงืกื ื•ืžืงืก ืงืกื ื•ืžืงืก ืงืกื ื•ืžืงืก
ืงืกื ื•ืžืงืก ืงืกื ื•ืžืงืก ืงืกื ื•ืžืงืก

ืžืึทื˜ืขืจื™ืึทืœืก / ืจืขืกื•ืจืกืŸ ื’ืขื ื™ืฆื˜

1. ืึทืคื™ืฉืึทืœ ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ ืคื•ืŸ ื“ื™ 3ืคึผืจืึธืงืกื™ ืคึผืจืึธื’ืจืึทื 3proxy.ru

2. ื™ื ืกื˜ืจืึทืงืฉืึทื ื– ืคึฟืึทืจ ื™ื ืกื˜ืึธืœื™ื ื’ 3proxy ืคึฟื•ืŸ ืžืงื•ืจ www.ekzorchik.ru/2015/02/how-to-take-your-socks-proxy

3. 3ืคึผืจืึธืงืกื™ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ืฆื•ื•ื™ื™ึทื’ ืื•ื™ืฃ ื’ื™ื˜ื”ื•ื‘ github.com/z3APA3A/3proxy/issues/274

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’