mirror of
https://github.com/3proxy/3proxy.git
synced 2026-08-13 12:19:17 +08:00
Compare commits
6 Commits
da085cab0d
...
06e425faa2
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
06e425faa2 | ||
|
|
7eba73fc8f | ||
|
|
122ca26249 | ||
|
|
6369fe966e | ||
|
|
cb27ca5223 | ||
|
|
ccdecfd832 |
2
.github/workflows/c-cpp-Windows.yml
vendored
2
.github/workflows/c-cpp-Windows.yml
vendored
@ -39,5 +39,5 @@ jobs:
|
|||||||
cd "D:/a/3proxy/3proxy"
|
cd "D:/a/3proxy/3proxy"
|
||||||
set "LIB=%LIB%;c:/vcpkg/installed/x64-windows-static/lib;c:/vcpkg/installed/x64-windows/lib"
|
set "LIB=%LIB%;c:/vcpkg/installed/x64-windows-static/lib;c:/vcpkg/installed/x64-windows/lib"
|
||||||
set "INCLUDE=%INCLUDE%;c:/vcpkg/installed/x64-windows-static/include;c:/vcpkg/installed/x64-windows/include"
|
set "INCLUDE=%INCLUDE%;c:/vcpkg/installed/x64-windows-static/include;c:/vcpkg/installed/x64-windows/include"
|
||||||
nmake /F Makefile.msvc WOLFSSL=1
|
nmake /F Makefile.msvc WOLFSSL=1 || exit /b 1
|
||||||
nmake /F Makefile.msvc clean
|
nmake /F Makefile.msvc clean
|
||||||
|
|||||||
1
.gitignore
vendored
1
.gitignore
vendored
@ -272,3 +272,4 @@ bin/3proxy_tlspr
|
|||||||
bin/3proxy_udppm
|
bin/3proxy_udppm
|
||||||
build*/*
|
build*/*
|
||||||
testcerts/
|
testcerts/
|
||||||
|
/.claude
|
||||||
|
|||||||
49
CHANGELOG
49
CHANGELOG
@ -1,25 +1,28 @@
|
|||||||
3proxy-0.9.7 Released July, 4 2026
|
3proxy-0.9.8 Released August, 7 2026
|
||||||
|
|
||||||
+ PCRE2 and SSL/TLS code moved from plugins into main 3proxy binary; dynamic linking with ssl/pcre by default, STATIC/LIBSTATIC options for static linking
|
!! Fix: use-after-free on the ftp:// request path in HTTP proxy, a request buffer reallocation left a stale pointer; heap corruption, requires authenticated access
|
||||||
+ Unix sockets support for parent proxies, tcppm, internal listeners and -i option; abstract (fileless) unix sockets on Linux
|
!! Fix: buffer overflow in radsend() with an oversized request hostname; RADIUS is experimental, log radius or auth radius with fakeresolve is required to reach it
|
||||||
+ ssl_client_mode = 3 to use 'secure' parent types: https, tcps, socks5s, connect+s, etc.
|
!! Fix: buffer overflow in smtpp when relaying AUTH LOGIN credentials to a server which offers AUTH PLAIN only; requires authorised access to smtpp
|
||||||
+ New authcache types: cacheacl, dstaddr, dstport, dsthost, dstoper, srvaddr, srvport; authcache is now configurable per service
|
!! Fix: out-of-bounds read in tlspr on a malformed TLS ClientHello
|
||||||
+ Hashtables for password lists and authcache, faster password lookups
|
!! Fix: LDAP injection and unsafe counter file names in LdapPlugin; the plugin is unsupported and is not built with 3proxy
|
||||||
+ 3proxy_crypt: new internal password hashing replacing mycrypt
|
!! Fix: password and hash comparison in strong authentication is constant-time now
|
||||||
+ udppm switched to hashtables and supports multiple connections
|
!! Fix: bounds validation and match/depth limits in pcre filters
|
||||||
+ SOCKSv5 UDP parent support; -Ne/-Ni NAT options
|
+ imapp: IMAPv4 proxy added, supports LOGIN command, AUTH PLAIN and AUTH LOGIN
|
||||||
+ Docker images for more platforms, signed; DLLs signed; public cert added to build
|
+ STARTTLS support for smtpp, pop3p, imapp and tlspr, on both client and server side; -x option to disable
|
||||||
+ Grace sleep and linger on connection close; correctly process half-closed connections
|
+ wolfSSL is supported as an alternative TLS backend, WOLFSSL_CHECK=true selects it (wolfSSL must be built with --enable-opensslextra)
|
||||||
+ Allow setting internal/external network namespaces on Linux
|
+ Chunked Transfer-Encoding from client is supported by HTTP proxy
|
||||||
- icqpr/OSCAR code removed
|
+ dnspr: -F option added, fake resolve to redirect traffic
|
||||||
! Fix: invalid error in SSL server handshake could break service state
|
+ ucrt64 build support; static libraries support in Makefile.win
|
||||||
! Fix: invalid offset in datafilters
|
+ minimal and busybox Docker images switched to musl + wolfSSL
|
||||||
! Fix: invalid socket in poll() could break sockmap() on Windows
|
- splice() support is not built by default anymore, it is slower than the read/write path for most traffic; add -DWITHSPLICE to build it
|
||||||
! Fix: deadlock in ftppr
|
! Fix: hashtable item was added with wrong index on table grow; with large username/password tables it could cause a single record to be missing
|
||||||
! Fix: crash on standalone services
|
! Fix: race conditions; stack overflow on FreeBSD
|
||||||
! Fix: non-initialized mutex crash under Windows
|
! Fix: generated certificates are X.509 v3 with basicConstraints CA:FALSE and extendedKeyUsage serverAuth, required by Apple TLS stack and by Chrome on macOS/iOS
|
||||||
! Fix: socks v5 parent with no auth
|
! Fix: dnspr was broken since udppm rewrite
|
||||||
! Fix: hanging connections in sockmap; unneeded poll in sockmap
|
! Fix: short cleartext passwords failed authentication
|
||||||
! Fix: symbols collision with OpenSSL could lead to crash
|
! Fix: parent negotiation after sending PROXY protocol header
|
||||||
! Fix: compatibility with older SSL versions and older Windows (7 and below)
|
! Fix: maxchild dropped to 100 on config reload if not set explicitly
|
||||||
|
! Fix: getrandom() is not used with glibc below 2.25
|
||||||
|
! Fix: IPV6_BOUND_IF definition for legacy MacOS
|
||||||
|
! Fix: cmake build, arm64 Docker build, Makefile.win with UCRT
|
||||||
! Multiple minor bugfixes and code cleanup
|
! Multiple minor bugfixes and code cleanup
|
||||||
|
|||||||
@ -1,25 +1,28 @@
|
|||||||
3proxy-0.9.7 Вышел 4 Июля 2026
|
3proxy-0.9.8 Вышел 7 Августа 2026
|
||||||
|
|
||||||
+ Код PCRE2 и SSL/TLS перенесён из плагинов в основной бинарный файл 3proxy; по умолчанию динамическое связывание с ssl/pcre, опции STATIC/LIBSTATIC для статического связывания
|
!! Исправление: use-after-free на пути обработки запроса ftp:// в HTTP-прокси, перевыделение буфера запроса оставляло устаревший указатель; повреждение кучи, требуется аутентифицированный доступ
|
||||||
+ Поддержка unix-сокетов для родительских прокси, tcppm, внутренних слушателей и опции -i; абстрактные (безфайловые) unix-сокеты в Linux
|
!! Исправление: переполнение буфера в radsend() при слишком длинном имени хоста в запросе; RADIUS является экспериментальным, для достижения кода необходимы log radius или auth radius в сочетании с fakeresolve
|
||||||
+ ssl_client_mode = 3 для использования «безопасных» типов родителя: https, tcps, socks5s, connect+s и т.д.
|
!! Исправление: переполнение буфера в smtpp при передаче учётных данных AUTH LOGIN серверу, поддерживающему только AUTH PLAIN; требуется авторизованный доступ к smtpp
|
||||||
+ Новые типы authcache: cacheacl, dstaddr, dstport, dsthost, dstoper, srvaddr, srvport; authcache настраивается для каждого сервиса
|
!! Исправление: чтение за границами буфера в tlspr при некорректном TLS ClientHello
|
||||||
+ Хеш-таблицы для списков паролей и authcache, более быстрый поиск паролей
|
!! Исправление: LDAP-инъекция и небезопасные имена файлов счётчиков в LdapPlugin; плагин не поддерживается и не собирается вместе с 3proxy
|
||||||
+ 3proxy_crypt: новое внутреннее хеширование паролей, заменяющее mycrypt
|
!! Исправление: сравнение паролей и хешей в strong-аутентификации теперь выполняется за постоянное время
|
||||||
+ udppm переведён на хеш-таблицы и поддерживает множество соединений
|
!! Исправление: проверка границ и ограничения match/depth в pcre-фильтрах
|
||||||
+ Поддержка UDP-родителя для SOCKSv5; опции NAT -Ne/-Ni
|
+ imapp: добавлен IMAPv4-прокси, поддерживаются команда LOGIN, AUTH PLAIN и AUTH LOGIN
|
||||||
+ Docker-образы для большего числа платформ, подписанные; подписанные DLL; публичный сертификат добавлен в сборку
|
+ Поддержка STARTTLS для smtpp, pop3p, imapp и tlspr, как со стороны клиента, так и со стороны сервера; опция -x для отключения
|
||||||
+ Grace sleep и linger при закрытии соединения; корректная обработка полузакрытых соединений
|
+ wolfSSL поддерживается как альтернативный TLS-бэкенд, выбирается через WOLFSSL_CHECK=true (wolfSSL должен быть собран с --enable-opensslextra)
|
||||||
+ Разрешено задавать внутренние/внешние сетевые пространства имён (network namespaces) в Linux
|
+ HTTP-прокси поддерживает Transfer-Encoding: chunked от клиента
|
||||||
- Код icqpr/OSCAR удалён
|
+ dnspr: добавлена опция -F, фиктивное разрешение имён для перенаправления трафика
|
||||||
! Исправление: некорректная ошибка в SSL server handshake могла ломать состояние сервиса
|
+ Поддержка сборки ucrt64; поддержка статических библиотек в Makefile.win
|
||||||
! Исправление: некорректное смещение в datafilters
|
+ Docker-образы minimal и busybox переведены на musl + wolfSSL
|
||||||
! Исправление: некорректный сокет в poll() мог ломать sockmap() в Windows
|
- Поддержка splice() больше не собирается по умолчанию, она медленнее пути read/write для большинства видов трафика; для сборки добавьте -DWITHSPLICE
|
||||||
! Исправление: взаимоблокировка (deadlock) в ftppr
|
! Исправление: элемент хеш-таблицы добавлялся с неверным индексом при росте таблицы; на больших таблицах пользователей/паролей это могло приводить к отсутствию одной записи
|
||||||
! Исправление: падение на standalone-сервисах
|
! Исправление: состояния гонки; переполнение стека во FreeBSD
|
||||||
! Исправление: падение из-за неинициализированного mutex в Windows
|
! Исправление: генерируемые сертификаты имеют формат X.509 v3 с basicConstraints CA:FALSE и extendedKeyUsage serverAuth, что требуется TLS-стеком Apple и Chrome в macOS/iOS
|
||||||
! Исправление: родитель socks v5 без аутентификации
|
! Исправление: dnspr был сломан со времён переписывания udppm
|
||||||
! Исправление: зависающие соединения в sockmap; лишний poll в sockmap
|
! Исправление: короткие пароли в открытом виде не проходили аутентификацию
|
||||||
! Исправление: конфликт символов с OpenSSL мог приводить к падению
|
! Исправление: согласование с родителем после отправки заголовка PROXY protocol
|
||||||
! Исправление: совместимость со старыми версиями SSL и старыми версиями Windows (7 и ниже)
|
! Исправление: maxchild сбрасывался в 100 при перезагрузке конфигурации, если не задан явно
|
||||||
|
! Исправление: getrandom() не используется с glibc ниже 2.25
|
||||||
|
! Исправление: определение IPV6_BOUND_IF для устаревших версий MacOS
|
||||||
|
! Исправление: сборка cmake, сборка Docker для arm64, Makefile.win с UCRT
|
||||||
! Множество мелких исправлений и очистка кода
|
! Множество мелких исправлений и очистка кода
|
||||||
|
|||||||
@ -29,7 +29,7 @@ RUN TAG=$(curl -s https://api.github.com/repos/wolfSSL/wolfssl/releases/latest \
|
|||||||
mkdir /src && tar -xzf /tmp/w.tar.gz -C /src --strip-components=1 && \
|
mkdir /src && tar -xzf /tmp/w.tar.gz -C /src --strip-components=1 && \
|
||||||
cd /src && \
|
cd /src && \
|
||||||
autoreconf -i && \
|
autoreconf -i && \
|
||||||
./configure --enable-opensslextra --enable-opensslall --enable-certgen \
|
./configure --enable-opensslextra --enable-certgen \
|
||||||
--enable-tls13 --enable-sni --enable-session-ticket \
|
--enable-tls13 --enable-sni --enable-session-ticket \
|
||||||
--enable-static --disable-shared --prefix=/usr/local && \
|
--enable-static --disable-shared --prefix=/usr/local && \
|
||||||
make -j$(nproc) && make install
|
make -j$(nproc) && make install
|
||||||
|
|||||||
@ -35,7 +35,7 @@ RUN TAG=$(curl -s https://api.github.com/repos/wolfSSL/wolfssl/releases/latest \
|
|||||||
mkdir /src && tar -xzf /tmp/w.tar.gz -C /src --strip-components=1 && \
|
mkdir /src && tar -xzf /tmp/w.tar.gz -C /src --strip-components=1 && \
|
||||||
cd /src && \
|
cd /src && \
|
||||||
autoreconf -i && \
|
autoreconf -i && \
|
||||||
./configure --enable-opensslextra --enable-opensslall --enable-certgen \
|
./configure --enable-opensslextra --enable-certgen \
|
||||||
--enable-tls13 --enable-sni --enable-session-ticket \
|
--enable-tls13 --enable-sni --enable-session-ticket \
|
||||||
--enable-static --disable-shared --prefix=/usr/local && \
|
--enable-static --disable-shared --prefix=/usr/local && \
|
||||||
make -j$(nproc) && make install
|
make -j$(nproc) && make install
|
||||||
|
|||||||
@ -104,7 +104,7 @@ INSTALL_OBJS = bin/3proxy \
|
|||||||
bin/$(CRYPT_PREFIX)crypt \
|
bin/$(CRYPT_PREFIX)crypt \
|
||||||
bin/$(PREFIX)ftppr \
|
bin/$(PREFIX)ftppr \
|
||||||
bin/$(PREFIX)imapp \
|
bin/$(PREFIX)imapp \
|
||||||
bin/$(PREFIX)pop3p \
|
bin/$(PREFIX)pop3p \
|
||||||
bin/$(PREFIX)proxy \
|
bin/$(PREFIX)proxy \
|
||||||
bin/$(PREFIX)smtpp \
|
bin/$(PREFIX)smtpp \
|
||||||
bin/$(PREFIX)socks \
|
bin/$(PREFIX)socks \
|
||||||
|
|||||||
@ -18,6 +18,9 @@ https://github.com/3proxy/3proxy/releases
|
|||||||
https://hub.docker.com/r/3proxy/3proxy
|
https://hub.docker.com/r/3proxy/3proxy
|
||||||
https://github.com/3proxy/3proxy/pkgs/container/3proxy
|
https://github.com/3proxy/3proxy/pkgs/container/3proxy
|
||||||
|
|
||||||
|
> [!TIP]
|
||||||
|
> An alternative Docker image (community-maintained) with support for configuration through environment variables and a ready-to-use Helm chart for Kubernetes can be found here: [tarampampam/3proxy-docker](https://github.com/tarampampam/3proxy-docker).
|
||||||
|
|
||||||
### Archive of old versions
|
### Archive of old versions
|
||||||
|
|
||||||
https://github.com/z3APA3A/3proxy-archive
|
https://github.com/z3APA3A/3proxy-archive
|
||||||
|
|||||||
14
SECURITY.md
Normal file
14
SECURITY.md
Normal file
@ -0,0 +1,14 @@
|
|||||||
|
# Security Policy
|
||||||
|
|
||||||
|
## Supported Versions
|
||||||
|
|
||||||
|
| Version | Supported |
|
||||||
|
| ------- | ------------------ |
|
||||||
|
| 0.9.8 | :white_check_mark: |
|
||||||
|
| < 0.9.8 | :x: |
|
||||||
|
|
||||||
|
## Reporting a Vulnerability
|
||||||
|
|
||||||
|
Report to 3proxy@3proxy.org or via [GitHub security reporting](https://github.com/3proxy/3proxy/security)
|
||||||
|
|
||||||
|
For High/Critical patched version is released within 2 weeks
|
||||||
6
debian/changelog
vendored
6
debian/changelog
vendored
@ -1,3 +1,9 @@
|
|||||||
|
3proxy (0.9.8-1) buster; urgency=medium
|
||||||
|
|
||||||
|
*3proxy 0.9.8 initial build
|
||||||
|
|
||||||
|
-- z3APA3A <3apa3a@3proxy.org> Fri, 07 Aug 2026 17:44:30 +0300
|
||||||
|
|
||||||
3proxy (0.9.7-1) buster; urgency=medium
|
3proxy (0.9.7-1) buster; urgency=medium
|
||||||
|
|
||||||
*3proxy 0.9.7 initial build
|
*3proxy 0.9.7 initial build
|
||||||
|
|||||||
26
doc/changelog/0/9/8
Normal file
26
doc/changelog/0/9/8
Normal file
@ -0,0 +1,26 @@
|
|||||||
|
!! Fix: use-after-free on the ftp:// request path in HTTP proxy, a request buffer reallocation left a stale pointer; heap corruption, requires authenticated access
|
||||||
|
!! Fix: buffer overflow in radsend() with an oversized request hostname; RADIUS is experimental, log radius or auth radius with fakeresolve is required to reach it
|
||||||
|
!! Fix: buffer overflow in smtpp when relaying AUTH LOGIN credentials to a server which offers AUTH PLAIN only; requires authorised access to smtpp
|
||||||
|
!! Fix: out-of-bounds read in tlspr on a malformed TLS ClientHello
|
||||||
|
!! Fix: LDAP injection and unsafe counter file names in LdapPlugin; the plugin is unsupported and is not built with 3proxy
|
||||||
|
!! Fix: password and hash comparison in strong authentication is constant-time now
|
||||||
|
!! Fix: bounds validation and match/depth limits in pcre filters
|
||||||
|
+ imapp: IMAPv4 proxy added, supports LOGIN command, AUTH PLAIN and AUTH LOGIN
|
||||||
|
+ STARTTLS support for smtpp, pop3p, imapp and tlspr, on both client and server side; -x option to disable
|
||||||
|
+ wolfSSL is supported as an alternative TLS backend, WOLFSSL_CHECK=true selects it (wolfSSL must be built with --enable-opensslextra)
|
||||||
|
+ Chunked Transfer-Encoding from client is supported by HTTP proxy
|
||||||
|
+ dnspr: -F option added, fake resolve to redirect traffic
|
||||||
|
+ ucrt64 build support; static libraries support in Makefile.win
|
||||||
|
+ minimal and busybox Docker images switched to musl + wolfSSL
|
||||||
|
- splice() support is not built by default anymore, it is slower than the read/write path for most traffic; add -DWITHSPLICE to build it
|
||||||
|
! Fix: hashtable item was added with wrong index on table grow; with large username/password tables it could cause a single record to be missing
|
||||||
|
! Fix: race conditions; stack overflow on FreeBSD
|
||||||
|
! Fix: generated certificates are X.509 v3 with basicConstraints CA:FALSE and extendedKeyUsage serverAuth, required by Apple TLS stack and by Chrome on macOS/iOS
|
||||||
|
! Fix: dnspr was broken since udppm rewrite
|
||||||
|
! Fix: short cleartext passwords failed authentication
|
||||||
|
! Fix: parent negotiation after sending PROXY protocol header
|
||||||
|
! Fix: maxchild dropped to 100 on config reload if not set explicitly
|
||||||
|
! Fix: getrandom() is not used with glibc below 2.25
|
||||||
|
! Fix: IPV6_BOUND_IF definition for legacy MacOS
|
||||||
|
! Fix: cmake build, arm64 Docker build, Makefile.win with UCRT
|
||||||
|
! Multiple minor bugfixes and code cleanup
|
||||||
@ -1,5 +1,5 @@
|
|||||||
Name: 3proxy
|
Name: 3proxy
|
||||||
Version: 0.9.7
|
Version: 0.9.8
|
||||||
Release: 1%{?dist}
|
Release: 1%{?dist}
|
||||||
Summary: 3proxy tiny proxy server
|
Summary: 3proxy tiny proxy server
|
||||||
License: GPL/LGPL/Apache/BSD
|
License: GPL/LGPL/Apache/BSD
|
||||||
@ -34,6 +34,7 @@ make clean
|
|||||||
/bin/3proxy
|
/bin/3proxy
|
||||||
/bin/3proxy_crypt
|
/bin/3proxy_crypt
|
||||||
/bin/3proxy_ftppr
|
/bin/3proxy_ftppr
|
||||||
|
/bin/3proxy_imapp
|
||||||
/bin/3proxy_pop3p
|
/bin/3proxy_pop3p
|
||||||
/bin/3proxy_proxy
|
/bin/3proxy_proxy
|
||||||
/bin/3proxy_smtpp
|
/bin/3proxy_smtpp
|
||||||
|
|||||||
@ -27,6 +27,10 @@
|
|||||||
#define WINAPI
|
#define WINAPI
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
|
#if defined(WITH_WOLFSSL) && !defined(SSL_set_mode)
|
||||||
|
#define SSL_set_mode(ssl,op) ((void)0)
|
||||||
|
#endif
|
||||||
|
|
||||||
#ifndef isnumber
|
#ifndef isnumber
|
||||||
#define isnumber(i_n_arg) ((i_n_arg>='0')&&(i_n_arg<='9'))
|
#define isnumber(i_n_arg) ((i_n_arg>='0')&&(i_n_arg<='9'))
|
||||||
#endif
|
#endif
|
||||||
|
|||||||
@ -1,14 +1,14 @@
|
|||||||
#ifndef VERSION
|
#ifndef VERSION
|
||||||
#define VERSION "3proxy-0.9.7"
|
#define VERSION "3proxy-0.9.8"
|
||||||
#endif
|
#endif
|
||||||
#ifndef BUILDDATE
|
#ifndef BUILDDATE
|
||||||
#define BUILDDATE ""
|
#define BUILDDATE ""
|
||||||
#endif
|
#endif
|
||||||
#define MAJOR3PROXY 0
|
#define MAJOR3PROXY 0
|
||||||
#define SUBMAJOR3PROXY 9
|
#define SUBMAJOR3PROXY 9
|
||||||
#define MINOR3PROXY 7
|
#define MINOR3PROXY 8
|
||||||
#define SUBMINOR3PROXY 0
|
#define SUBMINOR3PROXY 0
|
||||||
#define RELEASE3PROXY "3proxy-0.9.7(" BUILDDATE ")\0"
|
#define RELEASE3PROXY "3proxy-0.9.8(" BUILDDATE ")\0"
|
||||||
#ifndef YEAR3PROXY
|
#ifndef YEAR3PROXY
|
||||||
#define YEAR3PROXY "2026"
|
#define YEAR3PROXY "2026"
|
||||||
#endif
|
#endif
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user