Skip to content

ShadowsocksR — sing-box ​

sing-box 没有 ShadowsocksR 实现。shadowsocksr 类型会被识别以便现有配置能够解析,但任何 shadowsocksr 出站(或入站)都会在启动时报错。下方的选项结构仅供迁移此类配置时参考。

出站 ​

type: "shadowsocksr":

字段类型默认值允许值描述
methodstring(required)aes-256-cfb | aes-128-ctr | chacha20-ietf | rc4-md5 | <other SSR ciphers>SSR 加密算法。可接受集合是历史 SSR 加密目录 —— RC4、AES-CFB、AES-CTR、ChaCha20 等。现代 AEAD 加密属于常规 Shadowsocks 出站。
passwordstring(required)<string>服务端密码。
obfsstring(unset)plain | http_simple | http_post | random_head | tls1.2_ticket_auth混淆插件。plain 无混淆;http_simple 与 http_post 发出伪造 HTTP 请求;tls1.2_ticket_auth 模拟 TLS 复用。
obfs_paramstring(unset)<string>插件参数。对 HTTP obfs 而言是 Host 头。
protocolstringoriginorigin | auth_aes128_md5 | auth_aes128_sha1 | auth_sha1_v4 | auth_chain_a | auth_chain_b协议层插件。origin 无插件;auth_* 家族每包带鉴权。
protocol_paramstring(unset)<string>协议层参数。许多插件用作用户数或限速提示。
networkNetworkList(tcp+udp)tcp | udp | 限定为仅 TCP 或仅 UDP。

源码: option/shadowsocksr.go:3-13 · 锚定版本 v1.14.2 (af6e64c)

内嵌 DialerOptions 与 ServerOptions。

示例 ​

带 HTTP obfs 的纯 SSR:

json
{
  "outbounds": [
    {
      "type": "shadowsocksr",
      "tag": "ssr-out",
      "server": "example.com",
      "server_port": 443,
      "method": "aes-256-cfb",
      "password": "<password>",
      "obfs": "http_simple",
      "obfs_param": "www.bing.com",
      "protocol": "auth_chain_a",
      "protocol_param": "32"
    }
  ]
}

TLS-ticket-auth obfs:

json
{
  "outbounds": [
    {
      "type": "shadowsocksr",
      "server": "example.com",
      "server_port": 443,
      "method": "chacha20-ietf",
      "password": "<password>",
      "obfs": "tls1.2_ticket_auth",
      "obfs_param": "www.bing.com",
      "protocol": "auth_chain_b"
    }
  ]
}

说明 ​

  • shadowsocksr 出站只是一个占位实现:其选项会被解析,但创建时总是失败(include/registry.go:170-179)。请改用 mihomo 的 ssr 代理,或把服务端迁移到 Shadowsocks 等现代协议。
  • method、obfs、protocol 接受的字符串是历史 SSR 目录。「现代」Shadowsocks 加密(AEAD、2022-blake3-*)应放在 Shadowsocks 出站。
  • auth_chain_* 协议插件是今天仍在活跃使用的;旧的 auth_aes128_* 与 auth_sha1_v4 变体因 2018 年发现的重放攻击类漏洞已不安全。

跨内核说明 ​

  • Xray-core 不支持 SSR。参见 SSR — Xray-core。
  • mihomo 使用 cipher(而非 method)以及参数字段的 kebab-case 形式(obfs-param、protocol-param)。参见 SSR — mihomo。

源码: option/shadowsocksr.go:3-13 · v1.14.2 (af6e64c)

由 Argsment 出品的 Core Tutorial