2023-02-09 19:18:06 +00:00
|
|
|
|
#!/bin/bash
|
|
|
|
|
|
|
|
|
|
red='\033[0;31m'
|
|
|
|
|
green='\033[0;32m'
|
|
|
|
|
yellow='\033[0;33m'
|
|
|
|
|
plain='\033[0m'
|
|
|
|
|
|
|
|
|
|
#Add some basic function here
|
|
|
|
|
function LOGD() {
|
|
|
|
|
echo -e "${yellow}[DEG] $* ${plain}"
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
function LOGE() {
|
|
|
|
|
echo -e "${red}[ERR] $* ${plain}"
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
function LOGI() {
|
|
|
|
|
echo -e "${green}[INF] $* ${plain}"
|
|
|
|
|
}
|
2023-04-18 05:51:21 +00:00
|
|
|
|
|
2023-02-09 19:18:06 +00:00
|
|
|
|
# check root
|
2024-03-10 14:29:24 +00:00
|
|
|
|
[[ $EUID -ne 0 ]] && LOGE "错误:您必须是 root 用户才能运行此脚本! \n" && exit 1
|
2023-02-09 19:18:06 +00:00
|
|
|
|
|
2023-03-07 22:34:07 +00:00
|
|
|
|
# Check OS and set release variable
|
2023-03-11 15:05:35 +00:00
|
|
|
|
if [[ -f /etc/os-release ]]; then
|
|
|
|
|
source /etc/os-release
|
|
|
|
|
release=$ID
|
|
|
|
|
elif [[ -f /usr/lib/os-release ]]; then
|
|
|
|
|
source /usr/lib/os-release
|
|
|
|
|
release=$ID
|
2023-02-09 19:18:06 +00:00
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "检查系统操作系统失败,请联系作者!" >&2
|
2023-03-07 22:34:07 +00:00
|
|
|
|
exit 1
|
2023-02-09 19:18:06 +00:00
|
|
|
|
fi
|
|
|
|
|
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "操作系统版本是: $release"
|
2023-03-07 22:34:07 +00:00
|
|
|
|
|
2023-02-09 19:18:06 +00:00
|
|
|
|
os_version=""
|
2023-03-11 15:05:35 +00:00
|
|
|
|
os_version=$(grep -i version_id /etc/os-release | cut -d \" -f2 | cut -d . -f1)
|
2023-02-09 19:18:06 +00:00
|
|
|
|
|
2023-03-11 15:38:43 +00:00
|
|
|
|
if [[ "${release}" == "centos" ]]; then
|
2023-03-11 15:05:35 +00:00
|
|
|
|
if [[ ${os_version} -lt 8 ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red} 请使用 CentOS 8 或更高版本 ${plain}\n" && exit 1
|
2023-03-11 15:05:35 +00:00
|
|
|
|
fi
|
2023-05-13 15:36:16 +00:00
|
|
|
|
elif [[ "${release}" == "ubuntu" ]]; then
|
2023-03-11 15:05:35 +00:00
|
|
|
|
if [[ ${os_version} -lt 20 ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red}请使用 Ubuntu 20 或更高版本! ${plain}\n" && exit 1
|
2023-03-11 15:05:35 +00:00
|
|
|
|
fi
|
2023-03-11 15:38:43 +00:00
|
|
|
|
elif [[ "${release}" == "fedora" ]]; then
|
2023-03-11 15:05:35 +00:00
|
|
|
|
if [[ ${os_version} -lt 36 ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red}请使用 Fedora 36 或更高版本! ${plain}\n" && exit 1
|
2023-03-11 15:05:35 +00:00
|
|
|
|
fi
|
2023-03-11 15:38:43 +00:00
|
|
|
|
elif [[ "${release}" == "debian" ]]; then
|
2024-01-12 08:15:46 +00:00
|
|
|
|
if [[ ${os_version} -lt 11 ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red} 请使用 Debian 11 或更高版本 ${plain}\n" && exit 1
|
2023-03-11 15:05:35 +00:00
|
|
|
|
fi
|
2023-12-23 08:56:56 +00:00
|
|
|
|
elif [[ "${release}" == "almalinux" ]]; then
|
|
|
|
|
if [[ ${os_version} -lt 9 ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red} 请使用 Almalinux 9 或更高版本 ${plain}\n" && exit 1
|
2023-12-23 08:56:56 +00:00
|
|
|
|
fi
|
2024-01-12 08:15:46 +00:00
|
|
|
|
elif [[ "${release}" == "rocky" ]]; then
|
|
|
|
|
if [[ ${os_version} -lt 9 ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red} 请使用 Rockylinux 9 或更高版本 ${plain}\n" && exit 1
|
2024-01-12 08:15:46 +00:00
|
|
|
|
fi
|
2023-08-08 18:48:00 +00:00
|
|
|
|
elif [[ "${release}" == "arch" ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "你的操作系统是 ArchLinux"
|
2023-12-19 10:27:04 +00:00
|
|
|
|
elif [[ "${release}" == "manjaro" ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "您的操作系统是 Manjaro"
|
2023-12-19 10:27:04 +00:00
|
|
|
|
elif [[ "${release}" == "armbian" ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "您的操作系统是 Armbian"
|
2023-03-11 15:05:35 +00:00
|
|
|
|
fi
|
2023-03-07 22:34:07 +00:00
|
|
|
|
|
2023-07-18 10:24:28 +00:00
|
|
|
|
# Declare Variables
|
|
|
|
|
log_folder="${XUI_LOG_FOLDER:=/var/log}"
|
|
|
|
|
iplimit_log_path="${log_folder}/3xipl.log"
|
|
|
|
|
iplimit_banned_log_path="${log_folder}/3xipl-banned.log"
|
|
|
|
|
|
2023-02-09 19:18:06 +00:00
|
|
|
|
confirm() {
|
|
|
|
|
if [[ $# > 1 ]]; then
|
2023-04-21 15:33:23 +00:00
|
|
|
|
echo && read -p "$1 [Default $2]: " temp
|
2023-04-29 21:27:15 +00:00
|
|
|
|
if [[ "${temp}" == "" ]]; then
|
2023-02-09 19:18:06 +00:00
|
|
|
|
temp=$2
|
|
|
|
|
fi
|
|
|
|
|
else
|
|
|
|
|
read -p "$1 [y/n]: " temp
|
|
|
|
|
fi
|
2023-04-29 21:27:15 +00:00
|
|
|
|
if [[ "${temp}" == "y" || "${temp}" == "Y" ]]; then
|
2023-02-09 19:18:06 +00:00
|
|
|
|
return 0
|
|
|
|
|
else
|
|
|
|
|
return 1
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
confirm_restart() {
|
2024-03-10 14:29:24 +00:00
|
|
|
|
confirm "重新启动面板,注意:重新启动面板也会重新启动 xray" "y"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
if [[ $? == 0 ]]; then
|
|
|
|
|
restart
|
|
|
|
|
else
|
|
|
|
|
show_menu
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
before_show_menu() {
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo && echo -n -e "${yellow}按回车键返回主菜单: ${plain}" && read temp
|
2023-02-09 19:18:06 +00:00
|
|
|
|
show_menu
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
install() {
|
2023-03-11 15:05:35 +00:00
|
|
|
|
bash <(curl -Ls https://raw.githubusercontent.com/MHSanaei/3x-ui/main/install.sh)
|
2023-02-09 19:18:06 +00:00
|
|
|
|
if [[ $? == 0 ]]; then
|
|
|
|
|
if [[ $# == 0 ]]; then
|
|
|
|
|
start
|
|
|
|
|
else
|
|
|
|
|
start 0
|
|
|
|
|
fi
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
update() {
|
2024-03-10 14:29:24 +00:00
|
|
|
|
confirm "此功能将强制重新安装最新版本,并且不会丢失数据。是否要继续?" "y"
|
2023-04-24 13:25:29 +00:00
|
|
|
|
if [[ $? != 0 ]]; then
|
|
|
|
|
LOGE "Cancelled"
|
|
|
|
|
if [[ $# == 0 ]]; then
|
|
|
|
|
before_show_menu
|
2023-04-21 15:30:14 +00:00
|
|
|
|
fi
|
2023-04-24 13:25:29 +00:00
|
|
|
|
return 0
|
|
|
|
|
fi
|
2024-03-10 14:29:24 +00:00
|
|
|
|
bash <(curl -Ls https://raw.githubusercontent.com/jiulingyun/3x-ui/tree/dev/install.sh)
|
2023-04-24 13:25:29 +00:00
|
|
|
|
if [[ $? == 0 ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "更新完成,面板已自动重启"
|
2023-04-24 13:25:29 +00:00
|
|
|
|
exit 0
|
2023-02-09 19:18:06 +00:00
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
2023-12-23 14:28:11 +00:00
|
|
|
|
custom_version() {
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "输入面板版本(如 2.0.0):"
|
2023-12-23 14:28:11 +00:00
|
|
|
|
read panel_version
|
|
|
|
|
|
|
|
|
|
if [ -z "$panel_version" ]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "面板版本不能为空。退出。"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
exit 1
|
2023-12-23 14:28:11 +00:00
|
|
|
|
fi
|
|
|
|
|
|
2024-03-10 14:29:24 +00:00
|
|
|
|
download_link="https://raw.githubusercontent.com/jiulingyun/3x-ui/tree/dev/install.sh"
|
2023-12-23 14:28:11 +00:00
|
|
|
|
|
|
|
|
|
# Use the entered panel version in the download link
|
|
|
|
|
install_command="bash <(curl -Ls $download_link) v$panel_version"
|
|
|
|
|
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "下载和安装面板版本 $panel_version..."
|
2023-12-23 14:28:11 +00:00
|
|
|
|
eval $install_command
|
|
|
|
|
}
|
|
|
|
|
|
2024-02-17 16:23:02 +00:00
|
|
|
|
# Function to handle the deletion of the script file
|
|
|
|
|
delete_script() {
|
|
|
|
|
rm "$0" # Remove the script file itself
|
|
|
|
|
exit 1
|
|
|
|
|
}
|
|
|
|
|
|
2023-02-09 19:18:06 +00:00
|
|
|
|
uninstall() {
|
2024-03-10 14:29:24 +00:00
|
|
|
|
confirm "您确定要卸载面板吗?Xray也将卸载!" "n"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
if [[ $? != 0 ]]; then
|
|
|
|
|
if [[ $# == 0 ]]; then
|
|
|
|
|
show_menu
|
|
|
|
|
fi
|
|
|
|
|
return 0
|
|
|
|
|
fi
|
|
|
|
|
systemctl stop x-ui
|
|
|
|
|
systemctl disable x-ui
|
|
|
|
|
rm /etc/systemd/system/x-ui.service -f
|
|
|
|
|
systemctl daemon-reload
|
|
|
|
|
systemctl reset-failed
|
|
|
|
|
rm /etc/x-ui/ -rf
|
|
|
|
|
rm /usr/local/x-ui/ -rf
|
|
|
|
|
|
|
|
|
|
echo ""
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "已成功卸载。\n"
|
|
|
|
|
echo "如果需要再次安装此面板,可以使用以下命令:"
|
|
|
|
|
echo -e "${green}bash <(curl -Ls https://raw.githubusercontent.com/jiulingyun/3x-ui/tree/dev/install.sh)${plain}"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
echo ""
|
2024-02-17 16:23:02 +00:00
|
|
|
|
# Trap the SIGTERM signal
|
|
|
|
|
trap delete_script SIGTERM
|
|
|
|
|
delete_script
|
2023-02-09 19:18:06 +00:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
reset_user() {
|
2024-03-10 14:29:24 +00:00
|
|
|
|
confirm "您确定要重置面板的用户名和密码吗?" "n"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
if [[ $? != 0 ]]; then
|
|
|
|
|
if [[ $# == 0 ]]; then
|
|
|
|
|
show_menu
|
|
|
|
|
fi
|
|
|
|
|
return 0
|
|
|
|
|
fi
|
2024-03-10 14:29:24 +00:00
|
|
|
|
read -rp "请设置登录用户名[默认为随机用户名]: " config_account
|
2023-04-21 15:30:14 +00:00
|
|
|
|
[[ -z $config_account ]] && config_account=$(date +%s%N | md5sum | cut -c 1-8)
|
2024-03-10 14:29:24 +00:00
|
|
|
|
read -rp "请设置登录密码[默认为随机密码]: " config_password
|
2023-04-21 15:30:14 +00:00
|
|
|
|
[[ -z $config_password ]] && config_password=$(date +%s%N | md5sum | cut -c 1-8)
|
|
|
|
|
/usr/local/x-ui/x-ui setting -username ${config_account} -password ${config_password} >/dev/null 2>&1
|
|
|
|
|
/usr/local/x-ui/x-ui setting -remove_secret >/dev/null 2>&1
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "面板登录用户名已重置为: ${green} ${config_account} ${plain}"
|
|
|
|
|
echo -e "面板登录密码已重置为: ${green} ${config_password} ${plain}"
|
|
|
|
|
echo -e "${yellow} 面板登录密钥令牌已禁用 ${plain}"
|
|
|
|
|
echo -e "${green} 请使用新的登录用户名和密码访问 X-UI 面板。 ${plain}"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
confirm_restart
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
reset_config() {
|
2024-03-10 14:29:24 +00:00
|
|
|
|
confirm "您确定要重置所有面板设置吗,帐户数据不会丢失,用户名和密码不会更改" "n"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
if [[ $? != 0 ]]; then
|
|
|
|
|
if [[ $# == 0 ]]; then
|
|
|
|
|
show_menu
|
|
|
|
|
fi
|
|
|
|
|
return 0
|
|
|
|
|
fi
|
|
|
|
|
/usr/local/x-ui/x-ui setting -reset
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "所有面板设置均已重置为默认值,请立即重启面板,并使用默认的 ${green}2053${plain} 端口访问 web 面板"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
confirm_restart
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
check_config() {
|
|
|
|
|
info=$(/usr/local/x-ui/x-ui setting -show true)
|
|
|
|
|
if [[ $? != 0 ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "获取当前设置错误,请检查日志"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
show_menu
|
|
|
|
|
fi
|
|
|
|
|
LOGI "${info}"
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
set_port() {
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo && echo -n -e "输入端口号[1-65535]: " && read port
|
2023-02-09 19:18:06 +00:00
|
|
|
|
if [[ -z "${port}" ]]; then
|
|
|
|
|
LOGD "Cancelled"
|
|
|
|
|
before_show_menu
|
|
|
|
|
else
|
|
|
|
|
/usr/local/x-ui/x-ui setting -port ${port}
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "端口已设置,请立即重启面板,并使用新端口 ${green}${port}${plain} to access web panel"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
confirm_restart
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
start() {
|
|
|
|
|
check_status
|
|
|
|
|
if [[ $? == 0 ]]; then
|
|
|
|
|
echo ""
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "面板正在运行,无需重启,如需重启请选择重启"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
else
|
|
|
|
|
systemctl start x-ui
|
|
|
|
|
sleep 2
|
|
|
|
|
check_status
|
|
|
|
|
if [[ $? == 0 ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "x-ui 启动成功"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "面板启动失败,可能是因为启动时间超过两秒,请稍后查看日志信息"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
fi
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
if [[ $# == 0 ]]; then
|
|
|
|
|
before_show_menu
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
stop() {
|
|
|
|
|
check_status
|
|
|
|
|
if [[ $? == 1 ]]; then
|
|
|
|
|
echo ""
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "面板停止了,无需再次停止!"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
else
|
|
|
|
|
systemctl stop x-ui
|
|
|
|
|
sleep 2
|
|
|
|
|
check_status
|
|
|
|
|
if [[ $? == 1 ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "X-UI 和 Xray 已成功停止"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "面板停止失败,可能是因为停止时间超过两秒,请稍后查看日志信息!"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
fi
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
if [[ $# == 0 ]]; then
|
|
|
|
|
before_show_menu
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
restart() {
|
|
|
|
|
systemctl restart x-ui
|
|
|
|
|
sleep 2
|
|
|
|
|
check_status
|
|
|
|
|
if [[ $? == 0 ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "x-ui 和 xray 已成功重新启动"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "面板重启失败,可能是因为启动时间超过两秒,请稍后查看日志信息"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
fi
|
|
|
|
|
if [[ $# == 0 ]]; then
|
|
|
|
|
before_show_menu
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
status() {
|
|
|
|
|
systemctl status x-ui -l
|
|
|
|
|
if [[ $# == 0 ]]; then
|
|
|
|
|
before_show_menu
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
enable() {
|
|
|
|
|
systemctl enable x-ui
|
|
|
|
|
if [[ $? == 0 ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "x-ui 成功设置开机自启"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "x-ui 设置开启自启失败"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
if [[ $# == 0 ]]; then
|
|
|
|
|
before_show_menu
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
disable() {
|
|
|
|
|
systemctl disable x-ui
|
|
|
|
|
if [[ $? == 0 ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "x-ui 开机自启已成功取消"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "x-ui 开启自启取消失败"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
if [[ $# == 0 ]]; then
|
|
|
|
|
before_show_menu
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
show_log() {
|
|
|
|
|
journalctl -u x-ui.service -e --no-pager -f
|
|
|
|
|
if [[ $# == 0 ]]; then
|
|
|
|
|
before_show_menu
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
2023-09-04 23:50:09 +00:00
|
|
|
|
show_banlog() {
|
2024-01-20 13:58:44 +00:00
|
|
|
|
if test -f "${iplimit_banned_log_path}"; then
|
|
|
|
|
if [[ -s "${iplimit_banned_log_path}" ]]; then
|
|
|
|
|
cat ${iplimit_banned_log_path}
|
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red}日志文件为空。${plain}\n"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
fi
|
2023-09-04 23:50:09 +00:00
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red}未找到日志文件。请先安装 Fail2ban 和 IP Limit。${plain}\n"
|
2023-09-04 23:50:09 +00:00
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
2024-02-21 12:46:45 +00:00
|
|
|
|
bbr_menu() {
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${green}\t1.${plain} 启用 BBR"
|
|
|
|
|
echo -e "${green}\t2.${plain} 禁用 BBR"
|
|
|
|
|
echo -e "${green}\t0.${plain} 返回主菜单"
|
|
|
|
|
read -p "选择一个选项: " choice
|
2024-02-21 12:46:45 +00:00
|
|
|
|
case "$choice" in
|
|
|
|
|
0)
|
|
|
|
|
show_menu
|
|
|
|
|
;;
|
|
|
|
|
1)
|
|
|
|
|
enable_bbr
|
|
|
|
|
;;
|
|
|
|
|
2)
|
|
|
|
|
disable_bbr
|
|
|
|
|
;;
|
2024-03-10 14:29:24 +00:00
|
|
|
|
*) echo "无效选择" ;;
|
2024-02-21 12:46:45 +00:00
|
|
|
|
esac
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
disable_bbr() {
|
|
|
|
|
|
|
|
|
|
if ! grep -q "net.core.default_qdisc=fq" /etc/sysctl.conf || ! grep -q "net.ipv4.tcp_congestion_control=bbr" /etc/sysctl.conf; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${yellow}BBR 当前未启用。${plain}"
|
2024-02-21 12:46:45 +00:00
|
|
|
|
exit 0
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
# Replace BBR with CUBIC configurations
|
|
|
|
|
sed -i 's/net.core.default_qdisc=fq/net.core.default_qdisc=pfifo_fast/' /etc/sysctl.conf
|
|
|
|
|
sed -i 's/net.ipv4.tcp_congestion_control=bbr/net.ipv4.tcp_congestion_control=cubic/' /etc/sysctl.conf
|
|
|
|
|
|
|
|
|
|
# Apply changes
|
|
|
|
|
sysctl -p
|
|
|
|
|
|
|
|
|
|
# Verify that BBR is replaced with CUBIC
|
|
|
|
|
if [[ $(sysctl net.ipv4.tcp_congestion_control | awk '{print $3}') == "cubic" ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${green}BBR 已成功替换为 CUBIC。${plain}"
|
2024-02-21 12:46:45 +00:00
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red}无法将 BBR 替换为 CUBIC。请检查您的系统配置。${plain}"
|
2024-02-21 12:46:45 +00:00
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
2023-03-07 22:34:07 +00:00
|
|
|
|
enable_bbr() {
|
2023-04-18 05:51:21 +00:00
|
|
|
|
if grep -q "net.core.default_qdisc=fq" /etc/sysctl.conf && grep -q "net.ipv4.tcp_congestion_control=bbr" /etc/sysctl.conf; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${green}BBR 已启用!${plain}"
|
2023-04-18 05:51:21 +00:00
|
|
|
|
exit 0
|
|
|
|
|
fi
|
2023-02-09 19:18:06 +00:00
|
|
|
|
|
2023-04-18 05:51:21 +00:00
|
|
|
|
# Check the OS and install necessary packages
|
2023-07-01 12:26:43 +00:00
|
|
|
|
case "${release}" in
|
2024-01-20 13:58:44 +00:00
|
|
|
|
ubuntu | debian)
|
|
|
|
|
apt-get update && apt-get install -yqq --no-install-recommends ca-certificates
|
|
|
|
|
;;
|
|
|
|
|
centos | almalinux | rocky)
|
|
|
|
|
yum -y update && yum -y install ca-certificates
|
|
|
|
|
;;
|
|
|
|
|
fedora)
|
|
|
|
|
dnf -y update && dnf -y install ca-certificates
|
|
|
|
|
;;
|
|
|
|
|
*)
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red}不支持的操作系统。请检查脚本并手动安装必要的软件包。${plain}\n"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
exit 1
|
|
|
|
|
;;
|
2023-07-01 12:26:43 +00:00
|
|
|
|
esac
|
2023-03-07 22:34:07 +00:00
|
|
|
|
|
2023-04-18 05:51:21 +00:00
|
|
|
|
# Enable BBR
|
2023-07-01 12:26:43 +00:00
|
|
|
|
echo "net.core.default_qdisc=fq" | tee -a /etc/sysctl.conf
|
|
|
|
|
echo "net.ipv4.tcp_congestion_control=bbr" | tee -a /etc/sysctl.conf
|
2023-03-07 22:34:07 +00:00
|
|
|
|
|
2023-04-18 05:51:21 +00:00
|
|
|
|
# Apply changes
|
2023-07-01 12:26:43 +00:00
|
|
|
|
sysctl -p
|
2023-02-09 19:18:06 +00:00
|
|
|
|
|
2023-04-18 05:51:21 +00:00
|
|
|
|
# Verify that BBR is enabled
|
|
|
|
|
if [[ $(sysctl net.ipv4.tcp_congestion_control | awk '{print $3}') == "bbr" ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${green}BBR 已成功启用。${plain}"
|
2023-04-18 05:51:21 +00:00
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red}无法启用 BBR。请检查您的系统配置。${plain}"
|
2023-04-18 05:51:21 +00:00
|
|
|
|
fi
|
2023-02-09 19:18:06 +00:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
update_shell() {
|
2024-03-10 14:29:24 +00:00
|
|
|
|
wget -O /usr/bin/x-ui -N --no-check-certificate https://github.com/jiulingyun/3x-ui/tree/dev/x-ui.sh
|
2023-02-09 19:18:06 +00:00
|
|
|
|
if [[ $? != 0 ]]; then
|
|
|
|
|
echo ""
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "下载脚本失败,请检查机器是否可以连接Github"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
before_show_menu
|
|
|
|
|
else
|
|
|
|
|
chmod +x /usr/bin/x-ui
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "升级脚本成功,请重新运行脚本" && exit 0
|
2023-02-09 19:18:06 +00:00
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
# 0: running, 1: not running, 2: not installed
|
|
|
|
|
check_status() {
|
|
|
|
|
if [[ ! -f /etc/systemd/system/x-ui.service ]]; then
|
|
|
|
|
return 2
|
|
|
|
|
fi
|
|
|
|
|
temp=$(systemctl status x-ui | grep Active | awk '{print $3}' | cut -d "(" -f2 | cut -d ")" -f1)
|
2023-04-29 21:27:15 +00:00
|
|
|
|
if [[ "${temp}" == "running" ]]; then
|
2023-02-09 19:18:06 +00:00
|
|
|
|
return 0
|
|
|
|
|
else
|
|
|
|
|
return 1
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
check_enabled() {
|
|
|
|
|
temp=$(systemctl is-enabled x-ui)
|
2023-04-29 21:27:15 +00:00
|
|
|
|
if [[ "${temp}" == "enabled" ]]; then
|
2023-02-09 19:18:06 +00:00
|
|
|
|
return 0
|
|
|
|
|
else
|
|
|
|
|
return 1
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
check_uninstall() {
|
|
|
|
|
check_status
|
|
|
|
|
if [[ $? != 2 ]]; then
|
|
|
|
|
echo ""
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "面板已安装,请不要重新安装"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
if [[ $# == 0 ]]; then
|
|
|
|
|
before_show_menu
|
|
|
|
|
fi
|
|
|
|
|
return 1
|
|
|
|
|
else
|
|
|
|
|
return 0
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
check_install() {
|
|
|
|
|
check_status
|
|
|
|
|
if [[ $? == 2 ]]; then
|
|
|
|
|
echo ""
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "请先安装面板"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
if [[ $# == 0 ]]; then
|
|
|
|
|
before_show_menu
|
|
|
|
|
fi
|
|
|
|
|
return 1
|
|
|
|
|
else
|
|
|
|
|
return 0
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
show_status() {
|
|
|
|
|
check_status
|
|
|
|
|
case $? in
|
|
|
|
|
0)
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "面板状态: ${green}运行中${plain}"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
show_enable_status
|
|
|
|
|
;;
|
|
|
|
|
1)
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "面板状态: ${yellow}未运行${plain}"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
show_enable_status
|
|
|
|
|
;;
|
|
|
|
|
2)
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "面板状态: ${red}未安装${plain}"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
;;
|
|
|
|
|
esac
|
|
|
|
|
show_xray_status
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
show_enable_status() {
|
|
|
|
|
check_enabled
|
|
|
|
|
if [[ $? == 0 ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "开机自启: ${green}Yes${plain}"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "开机自启: ${red}No${plain}"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
check_xray_status() {
|
|
|
|
|
count=$(ps -ef | grep "xray-linux" | grep -v "grep" | wc -l)
|
|
|
|
|
if [[ count -ne 0 ]]; then
|
|
|
|
|
return 0
|
|
|
|
|
else
|
|
|
|
|
return 1
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
show_xray_status() {
|
|
|
|
|
check_xray_status
|
|
|
|
|
if [[ $? == 0 ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "xray 状态: ${green}运行中${plain}"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "xray 状态: ${red}未运行${plain}"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
2024-02-07 17:53:11 +00:00
|
|
|
|
firewall_menu() {
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${green}\t1.${plain} 安装防火墙并打开端口"
|
|
|
|
|
echo -e "${green}\t2.${plain} 允许列表"
|
|
|
|
|
echo -e "${green}\t3.${plain} 从列表中删除端口"
|
|
|
|
|
echo -e "${green}\t4.${plain} 禁用防火墙"
|
|
|
|
|
echo -e "${green}\t0.${plain} 返回主菜单"
|
|
|
|
|
read -p "选择一个选项: " choice
|
2024-02-07 17:53:11 +00:00
|
|
|
|
case "$choice" in
|
|
|
|
|
0)
|
|
|
|
|
show_menu
|
|
|
|
|
;;
|
|
|
|
|
1)
|
|
|
|
|
open_ports
|
|
|
|
|
;;
|
|
|
|
|
2)
|
|
|
|
|
sudo ufw status
|
|
|
|
|
;;
|
|
|
|
|
3)
|
|
|
|
|
delete_ports
|
|
|
|
|
;;
|
|
|
|
|
4)
|
|
|
|
|
sudo ufw disable
|
|
|
|
|
;;
|
2024-03-10 14:29:24 +00:00
|
|
|
|
*) echo "无效选择" ;;
|
2024-02-07 17:53:11 +00:00
|
|
|
|
esac
|
|
|
|
|
}
|
|
|
|
|
|
2023-04-02 14:42:00 +00:00
|
|
|
|
open_ports() {
|
2023-05-13 15:36:16 +00:00
|
|
|
|
if ! command -v ufw &>/dev/null; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "未安装 UFW 防火墙。正在安装..."
|
2023-07-01 12:26:43 +00:00
|
|
|
|
apt-get update
|
|
|
|
|
apt-get install -y ufw
|
2023-04-02 14:42:00 +00:00
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "已安装 UFW 防火墙"
|
2023-04-02 14:42:00 +00:00
|
|
|
|
fi
|
|
|
|
|
|
2023-04-18 05:51:21 +00:00
|
|
|
|
# Check if the firewall is inactive
|
2023-07-01 12:26:43 +00:00
|
|
|
|
if ufw status | grep -q "Status: active"; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "防火墙已处于活动状态"
|
2023-04-18 05:51:21 +00:00
|
|
|
|
else
|
|
|
|
|
# Open the necessary ports
|
2023-07-01 12:26:43 +00:00
|
|
|
|
ufw allow ssh
|
|
|
|
|
ufw allow http
|
|
|
|
|
ufw allow https
|
|
|
|
|
ufw allow 2053/tcp
|
2023-04-18 05:51:21 +00:00
|
|
|
|
|
|
|
|
|
# Enable the firewall
|
2023-07-01 12:26:43 +00:00
|
|
|
|
ufw --force enable
|
2023-04-18 05:51:21 +00:00
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
# Prompt the user to enter a list of ports
|
2024-03-10 14:29:24 +00:00
|
|
|
|
read -p "输入要打开的端口(例如 80,443,2053 或范围 400-500): " ports
|
2023-04-18 05:51:21 +00:00
|
|
|
|
|
|
|
|
|
# Check if the input is valid
|
|
|
|
|
if ! [[ $ports =~ ^([0-9]+|[0-9]+-[0-9]+)(,([0-9]+|[0-9]+-[0-9]+))*$ ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "错误:输入无效。请输入以逗号分隔的端口列表或端口范围(例如 80,443,2053 或 400-500)。" >&2
|
2023-05-13 15:36:16 +00:00
|
|
|
|
exit 1
|
2023-04-18 05:51:21 +00:00
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
# Open the specified ports using ufw
|
2023-05-13 15:36:16 +00:00
|
|
|
|
IFS=',' read -ra PORT_LIST <<<"$ports"
|
2023-04-18 05:51:21 +00:00
|
|
|
|
for port in "${PORT_LIST[@]}"; do
|
|
|
|
|
if [[ $port == *-* ]]; then
|
2023-05-13 15:36:16 +00:00
|
|
|
|
# Split the range into start and end ports
|
|
|
|
|
start_port=$(echo $port | cut -d'-' -f1)
|
|
|
|
|
end_port=$(echo $port | cut -d'-' -f2)
|
|
|
|
|
# Loop through the range and open each port
|
|
|
|
|
for ((i = start_port; i <= end_port; i++)); do
|
2023-07-01 12:26:43 +00:00
|
|
|
|
ufw allow $i
|
2023-05-13 15:36:16 +00:00
|
|
|
|
done
|
2023-04-18 05:51:21 +00:00
|
|
|
|
else
|
2023-07-01 12:26:43 +00:00
|
|
|
|
ufw allow "$port"
|
2023-04-18 05:51:21 +00:00
|
|
|
|
fi
|
|
|
|
|
done
|
2023-04-02 14:42:00 +00:00
|
|
|
|
|
2023-04-18 05:51:21 +00:00
|
|
|
|
# Confirm that the ports are open
|
2023-07-01 12:26:43 +00:00
|
|
|
|
ufw status | grep $ports
|
2023-04-18 05:51:21 +00:00
|
|
|
|
}
|
2023-04-02 14:42:00 +00:00
|
|
|
|
|
2024-02-07 17:53:11 +00:00
|
|
|
|
delete_ports() {
|
|
|
|
|
# Prompt the user to enter the ports they want to delete
|
2024-03-10 14:29:24 +00:00
|
|
|
|
read -p "输入要删除的端口(例如 80,443,2053 或范围 400-500):" ports
|
2024-02-07 17:53:11 +00:00
|
|
|
|
|
|
|
|
|
# Check if the input is valid
|
|
|
|
|
if ! [[ $ports =~ ^([0-9]+|[0-9]+-[0-9]+)(,([0-9]+|[0-9]+-[0-9]+))*$ ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "错误:输入无效。请输入以逗号分隔的端口列表或端口范围(例如 80,443,2053 或 400-500)。" >&2
|
2024-02-07 17:53:11 +00:00
|
|
|
|
exit 1
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
# Delete the specified ports using ufw
|
|
|
|
|
IFS=',' read -ra PORT_LIST <<<"$ports"
|
|
|
|
|
for port in "${PORT_LIST[@]}"; do
|
|
|
|
|
if [[ $port == *-* ]]; then
|
|
|
|
|
# Split the range into start and end ports
|
|
|
|
|
start_port=$(echo $port | cut -d'-' -f1)
|
|
|
|
|
end_port=$(echo $port | cut -d'-' -f2)
|
|
|
|
|
# Loop through the range and delete each port
|
|
|
|
|
for ((i = start_port; i <= end_port; i++)); do
|
|
|
|
|
ufw delete allow $i
|
|
|
|
|
done
|
|
|
|
|
else
|
|
|
|
|
ufw delete allow "$port"
|
|
|
|
|
fi
|
|
|
|
|
done
|
|
|
|
|
|
|
|
|
|
# Confirm that the ports are deleted
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "删除了指定的端口:"
|
2024-02-07 17:53:11 +00:00
|
|
|
|
ufw status | grep $ports
|
|
|
|
|
}
|
|
|
|
|
|
2023-04-18 05:51:21 +00:00
|
|
|
|
update_geo() {
|
|
|
|
|
local defaultBinFolder="/usr/local/x-ui/bin"
|
2024-03-10 14:29:24 +00:00
|
|
|
|
read -p "请输入 x-ui bin 文件夹路径。默认值留空。(默认值:'${defaultBinFolder}')" binFolder
|
2023-04-18 05:51:21 +00:00
|
|
|
|
binFolder=${binFolder:-${defaultBinFolder}}
|
|
|
|
|
if [[ ! -d ${binFolder} ]]; then
|
|
|
|
|
LOGE "Folder ${binFolder} not exists!"
|
|
|
|
|
LOGI "making bin folder: ${binFolder}..."
|
|
|
|
|
mkdir -p ${binFolder}
|
|
|
|
|
fi
|
2023-04-02 14:42:00 +00:00
|
|
|
|
|
|
|
|
|
systemctl stop x-ui
|
2023-04-18 05:51:21 +00:00
|
|
|
|
cd ${binFolder}
|
2023-12-19 09:38:37 +00:00
|
|
|
|
rm -f geoip.dat geosite.dat geoip_IR.dat geosite_IR.dat geoip_VN.dat geosite_VN.dat
|
2023-04-02 14:42:00 +00:00
|
|
|
|
wget -N https://github.com/Loyalsoldier/v2ray-rules-dat/releases/latest/download/geoip.dat
|
|
|
|
|
wget -N https://github.com/Loyalsoldier/v2ray-rules-dat/releases/latest/download/geosite.dat
|
2023-10-18 09:52:07 +00:00
|
|
|
|
wget -O geoip_IR.dat -N https://github.com/chocolate4u/Iran-v2ray-rules/releases/latest/download/geoip.dat
|
|
|
|
|
wget -O geosite_IR.dat -N https://github.com/chocolate4u/Iran-v2ray-rules/releases/latest/download/geosite.dat
|
2023-12-19 09:38:37 +00:00
|
|
|
|
wget -O geoip_VN.dat https://github.com/vuong2023/vn-v2ray-rules/releases/latest/download/geoip.dat
|
|
|
|
|
wget -O geosite_VN.dat https://github.com/vuong2023/vn-v2ray-rules/releases/latest/download/geosite.dat
|
2023-04-02 14:42:00 +00:00
|
|
|
|
systemctl start x-ui
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${green}Geosite.dat + Geoip.dat + geoip_IR.dat + geosite_IR.dat已在bin文件夹中成功更新'${binfolder}'!${plain}"
|
2023-04-18 05:51:21 +00:00
|
|
|
|
before_show_menu
|
2023-04-02 14:42:00 +00:00
|
|
|
|
}
|
|
|
|
|
|
2023-02-15 18:57:42 +00:00
|
|
|
|
install_acme() {
|
|
|
|
|
cd ~
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "安装 证书工具..."
|
2023-02-15 18:57:42 +00:00
|
|
|
|
curl https://get.acme.sh | sh
|
|
|
|
|
if [ $? -ne 0 ]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "安装 证书工具 失败"
|
2023-02-15 18:57:42 +00:00
|
|
|
|
return 1
|
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "安装 证书工具 成功"
|
2023-02-15 18:57:42 +00:00
|
|
|
|
fi
|
|
|
|
|
return 0
|
|
|
|
|
}
|
|
|
|
|
|
2023-05-22 23:04:36 +00:00
|
|
|
|
ssl_cert_issue_main() {
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${green}\t1.${plain} 获取 SSL"
|
|
|
|
|
echo -e "${green}\t2.${plain} 撤回"
|
|
|
|
|
echo -e "${green}\t3.${plain} 强制续期"
|
|
|
|
|
echo -e "${green}\t0.${plain} 返回主菜单"
|
|
|
|
|
read -p "根据需要选择操作步骤:" choice
|
2023-05-22 23:04:36 +00:00
|
|
|
|
case "$choice" in
|
2024-01-20 13:58:44 +00:00
|
|
|
|
0)
|
|
|
|
|
show_menu
|
|
|
|
|
;;
|
|
|
|
|
1)
|
|
|
|
|
ssl_cert_issue
|
|
|
|
|
;;
|
|
|
|
|
2)
|
|
|
|
|
local domain=""
|
2024-03-10 14:29:24 +00:00
|
|
|
|
read -p "请输入您的域名以吊销证书:" domain
|
2024-01-20 13:58:44 +00:00
|
|
|
|
~/.acme.sh/acme.sh --revoke -d ${domain}
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "证书已吊销"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
;;
|
|
|
|
|
3)
|
|
|
|
|
local domain=""
|
2024-03-10 14:29:24 +00:00
|
|
|
|
read -p "请输入您的域名以强制续订SSL证书:" domain
|
2024-01-20 13:58:44 +00:00
|
|
|
|
~/.acme.sh/acme.sh --renew -d ${domain} --force
|
|
|
|
|
;;
|
2024-03-10 14:29:24 +00:00
|
|
|
|
*) echo "无效选择" ;;
|
2023-05-22 23:04:36 +00:00
|
|
|
|
esac
|
|
|
|
|
}
|
|
|
|
|
|
2023-04-29 21:27:15 +00:00
|
|
|
|
ssl_cert_issue() {
|
2023-07-01 12:26:43 +00:00
|
|
|
|
# check for acme.sh first
|
2023-02-20 17:29:55 +00:00
|
|
|
|
if ! command -v ~/.acme.sh/acme.sh &>/dev/null; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "acme.sh 无法找到。正在安装..."
|
2023-02-20 17:29:55 +00:00
|
|
|
|
install_acme
|
|
|
|
|
if [ $? -ne 0 ]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "安装 证书工具 失败,请查看日志"
|
2023-02-20 17:29:55 +00:00
|
|
|
|
exit 1
|
|
|
|
|
fi
|
2023-02-15 18:57:42 +00:00
|
|
|
|
fi
|
2023-07-01 12:26:43 +00:00
|
|
|
|
# install socat second
|
|
|
|
|
case "${release}" in
|
2024-01-20 13:58:44 +00:00
|
|
|
|
ubuntu | debian | armbian)
|
|
|
|
|
apt update && apt install socat -y
|
|
|
|
|
;;
|
|
|
|
|
centos | almalinux | rocky)
|
|
|
|
|
yum -y update && yum -y install socat
|
|
|
|
|
;;
|
|
|
|
|
fedora)
|
|
|
|
|
dnf -y update && dnf -y install socat
|
|
|
|
|
;;
|
|
|
|
|
*)
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red}不支持的操作系统。请检查脚本并手动安装必要的软件包。${plain}\n"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
exit 1
|
|
|
|
|
;;
|
2023-07-01 12:26:43 +00:00
|
|
|
|
esac
|
2023-02-15 18:57:42 +00:00
|
|
|
|
if [ $? -ne 0 ]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "安装 socat 失败,请检查日志"
|
2023-02-15 18:57:42 +00:00
|
|
|
|
exit 1
|
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "安装 socat 成功..."
|
2023-02-15 18:57:42 +00:00
|
|
|
|
fi
|
2023-04-02 17:31:08 +00:00
|
|
|
|
|
2023-07-01 12:26:43 +00:00
|
|
|
|
# get the domain here,and we need verify it
|
2023-02-15 18:57:42 +00:00
|
|
|
|
local domain=""
|
2024-03-10 14:29:24 +00:00
|
|
|
|
read -p "请输入您的域名:" domain
|
|
|
|
|
LOGD "你的域名是:${domain},检查一下..."
|
2023-07-01 12:26:43 +00:00
|
|
|
|
# here we need to judge whether there exists cert already
|
2023-02-15 18:57:42 +00:00
|
|
|
|
local currentCert=$(~/.acme.sh/acme.sh --list | tail -1 | awk '{print $1}')
|
2023-05-22 23:04:36 +00:00
|
|
|
|
|
2023-02-15 18:57:42 +00:00
|
|
|
|
if [ ${currentCert} == ${domain} ]; then
|
|
|
|
|
local certInfo=$(~/.acme.sh/acme.sh --list)
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "系统这里已经有证书,不能再次颁发,当前证书详情:"
|
2023-02-15 18:57:42 +00:00
|
|
|
|
LOGI "$certInfo"
|
2023-05-22 23:45:34 +00:00
|
|
|
|
exit 1
|
2023-02-15 18:57:42 +00:00
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "您的域现在已准备好颁发证书..."
|
2023-02-15 18:57:42 +00:00
|
|
|
|
fi
|
2023-05-13 15:36:16 +00:00
|
|
|
|
|
2023-07-01 12:26:43 +00:00
|
|
|
|
# create a directory for install cert
|
2023-05-13 15:36:16 +00:00
|
|
|
|
certPath="/root/cert/${domain}"
|
|
|
|
|
if [ ! -d "$certPath" ]; then
|
|
|
|
|
mkdir -p "$certPath"
|
|
|
|
|
else
|
|
|
|
|
rm -rf "$certPath"
|
|
|
|
|
mkdir -p "$certPath"
|
|
|
|
|
fi
|
|
|
|
|
|
2023-07-01 12:26:43 +00:00
|
|
|
|
# get needed port here
|
2023-02-15 18:57:42 +00:00
|
|
|
|
local WebPort=80
|
2024-03-10 14:29:24 +00:00
|
|
|
|
read -p "请选择您使用的端口,默认为 80 端口:" WebPort
|
2023-02-15 18:57:42 +00:00
|
|
|
|
if [[ ${WebPort} -gt 65535 || ${WebPort} -lt 1 ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "您的输入 ${WebPort} 无效,将使用默认端口"
|
2023-02-15 18:57:42 +00:00
|
|
|
|
fi
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "将使用 端口:${WebPort} 颁发证书,请确保此端口已打开..."
|
2023-07-01 12:26:43 +00:00
|
|
|
|
# NOTE:This should be handled by user
|
|
|
|
|
# open the port and kill the occupied progress
|
2023-02-15 18:57:42 +00:00
|
|
|
|
~/.acme.sh/acme.sh --set-default-ca --server letsencrypt
|
|
|
|
|
~/.acme.sh/acme.sh --issue -d ${domain} --standalone --httpport ${WebPort}
|
|
|
|
|
if [ $? -ne 0 ]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "申请证书失败,请检查日志"
|
2023-02-15 18:57:42 +00:00
|
|
|
|
rm -rf ~/.acme.sh/${domain}
|
|
|
|
|
exit 1
|
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "颁发证书成功,安装证书..."
|
2023-02-15 18:57:42 +00:00
|
|
|
|
fi
|
2023-07-01 12:26:43 +00:00
|
|
|
|
# install cert
|
2023-04-02 17:31:08 +00:00
|
|
|
|
~/.acme.sh/acme.sh --installcert -d ${domain} \
|
|
|
|
|
--key-file /root/cert/${domain}/privkey.pem \
|
|
|
|
|
--fullchain-file /root/cert/${domain}/fullchain.pem
|
2023-02-15 18:57:42 +00:00
|
|
|
|
|
|
|
|
|
if [ $? -ne 0 ]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "安装证书失败,退出"
|
2023-02-15 18:57:42 +00:00
|
|
|
|
rm -rf ~/.acme.sh/${domain}
|
|
|
|
|
exit 1
|
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "安装证书成功,启用自动续订..."
|
2023-02-15 18:57:42 +00:00
|
|
|
|
fi
|
|
|
|
|
|
2023-05-13 15:36:16 +00:00
|
|
|
|
~/.acme.sh/acme.sh --upgrade --auto-upgrade
|
|
|
|
|
if [ $? -ne 0 ]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "自动续订失败,证书详细信息:"
|
2023-05-13 15:36:16 +00:00
|
|
|
|
ls -lah cert/*
|
|
|
|
|
chmod 755 $certPath/*
|
|
|
|
|
exit 1
|
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "自动续订成功,证书详细信息:"
|
2023-05-13 15:36:16 +00:00
|
|
|
|
ls -lah cert/*
|
|
|
|
|
chmod 755 $certPath/*
|
|
|
|
|
fi
|
|
|
|
|
}
|
2023-04-18 05:51:21 +00:00
|
|
|
|
|
2023-08-08 21:22:40 +00:00
|
|
|
|
ssl_cert_issue_CF() {
|
|
|
|
|
echo -E ""
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGD "******使用说明******"
|
|
|
|
|
LOGI "此 Acme 脚本需要以下数据:"
|
|
|
|
|
LOGI "1.Cloudflare注册的邮箱"
|
|
|
|
|
LOGI "2.Cloudflare 全球 API 密钥"
|
|
|
|
|
LOGI "3.Cloudflare 已将 dns 解析到当前服务器的域名"
|
|
|
|
|
LOGI "4.该脚本适用于证书。默认安装路径为 /root/cert "
|
|
|
|
|
confirm "确认继续?[y/n]" "y"
|
2023-08-08 21:22:40 +00:00
|
|
|
|
if [ $? -eq 0 ]; then
|
|
|
|
|
# check for acme.sh first
|
|
|
|
|
if ! command -v ~/.acme.sh/acme.sh &>/dev/null; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "acme.sh 无法找到。正在安装中..."
|
2023-08-08 21:22:40 +00:00
|
|
|
|
install_acme
|
|
|
|
|
if [ $? -ne 0 ]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "安装 acme.sh 失败,请查看日志"
|
2023-08-08 21:22:40 +00:00
|
|
|
|
exit 1
|
|
|
|
|
fi
|
|
|
|
|
fi
|
|
|
|
|
CF_Domain=""
|
|
|
|
|
CF_GlobalKey=""
|
|
|
|
|
CF_AccountEmail=""
|
|
|
|
|
certPath=/root/cert
|
|
|
|
|
if [ ! -d "$certPath" ]; then
|
|
|
|
|
mkdir $certPath
|
|
|
|
|
else
|
|
|
|
|
rm -rf $certPath
|
|
|
|
|
mkdir $certPath
|
|
|
|
|
fi
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGD "请设置域名:"
|
|
|
|
|
read -p "在此输入您的域名:" CF_Domain
|
|
|
|
|
LOGD "您的域名设置为:${CF_Domain}"
|
|
|
|
|
LOGD "请设置 API 密钥:"
|
|
|
|
|
read -p "在此处输入您的密钥:" CF_GlobalKey
|
|
|
|
|
LOGD "您的 API 密钥是:${CF_GlobalKey}"
|
|
|
|
|
LOGD "请设置邮箱:"
|
|
|
|
|
read -p "在此输入您的邮箱:" CF_AccountEmail
|
|
|
|
|
LOGD "您注册的电子邮件地址是:${CF_AccountEmail}"
|
2023-08-08 21:22:40 +00:00
|
|
|
|
~/.acme.sh/acme.sh --set-default-ca --server letsencrypt
|
|
|
|
|
if [ $? -ne 0 ]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "默认 CA,Lets'Encrypt 失败,脚本退出..."
|
2023-08-08 21:22:40 +00:00
|
|
|
|
exit 1
|
|
|
|
|
fi
|
|
|
|
|
export CF_Key="${CF_GlobalKey}"
|
|
|
|
|
export CF_Email=${CF_AccountEmail}
|
|
|
|
|
~/.acme.sh/acme.sh --issue --dns dns_cf -d ${CF_Domain} -d *.${CF_Domain} --log
|
|
|
|
|
if [ $? -ne 0 ]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "证书颁发失败,脚本正在退出..."
|
2023-08-08 21:22:40 +00:00
|
|
|
|
exit 1
|
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "证书已成功颁发,正在安装..."
|
2023-08-08 21:22:40 +00:00
|
|
|
|
fi
|
|
|
|
|
~/.acme.sh/acme.sh --installcert -d ${CF_Domain} -d *.${CF_Domain} --ca-file /root/cert/ca.cer \
|
2024-01-20 13:58:44 +00:00
|
|
|
|
--cert-file /root/cert/${CF_Domain}.cer --key-file /root/cert/${CF_Domain}.key \
|
|
|
|
|
--fullchain-file /root/cert/fullchain.cer
|
2023-08-08 21:22:40 +00:00
|
|
|
|
if [ $? -ne 0 ]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "证书安装失败,脚本正在退出..."
|
2023-08-08 21:22:40 +00:00
|
|
|
|
exit 1
|
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "证书安装成功,开启自动更新..."
|
2023-08-08 21:22:40 +00:00
|
|
|
|
fi
|
|
|
|
|
~/.acme.sh/acme.sh --upgrade --auto-upgrade
|
|
|
|
|
if [ $? -ne 0 ]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "自动更新设置失败,脚本正在退出..."
|
2023-08-08 21:22:40 +00:00
|
|
|
|
ls -lah cert
|
|
|
|
|
chmod 755 $certPath
|
|
|
|
|
exit 1
|
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGI "证书已安装并开启自动续期,具体信息如下"
|
2023-08-08 21:22:40 +00:00
|
|
|
|
ls -lah cert
|
|
|
|
|
chmod 755 $certPath
|
|
|
|
|
fi
|
|
|
|
|
else
|
|
|
|
|
show_menu
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
2023-06-24 21:37:34 +00:00
|
|
|
|
warp_cloudflare() {
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${green}\t1.${plain} 安装 WARP socks5 代理"
|
|
|
|
|
echo -e "${green}\t2.${plain} 账户类型 (free, plus, team)"
|
|
|
|
|
echo -e "${green}\t3.${plain} 打开/关闭 WireProxy"
|
|
|
|
|
echo -e "${green}\t4.${plain} 卸载 WARP"
|
|
|
|
|
echo -e "${green}\t0.${plain} 返回主菜单"
|
|
|
|
|
read -p "根据需要选择操作步骤:" choice
|
2023-06-24 21:37:34 +00:00
|
|
|
|
case "$choice" in
|
2024-01-20 13:58:44 +00:00
|
|
|
|
0)
|
|
|
|
|
show_menu
|
|
|
|
|
;;
|
|
|
|
|
1)
|
|
|
|
|
bash <(curl -sSL https://raw.githubusercontent.com/hamid-gh98/x-ui-scripts/main/install_warp_proxy.sh)
|
|
|
|
|
;;
|
|
|
|
|
2)
|
|
|
|
|
warp a
|
|
|
|
|
;;
|
|
|
|
|
3)
|
|
|
|
|
warp y
|
|
|
|
|
;;
|
|
|
|
|
4)
|
|
|
|
|
warp u
|
|
|
|
|
;;
|
2024-03-10 14:29:24 +00:00
|
|
|
|
*) echo "无效选择" ;;
|
2023-06-24 21:37:34 +00:00
|
|
|
|
esac
|
2023-04-03 15:52:23 +00:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
run_speedtest() {
|
|
|
|
|
# Check if Speedtest is already installed
|
2024-01-20 13:58:44 +00:00
|
|
|
|
if ! command -v speedtest &>/dev/null; then
|
2023-04-03 15:52:23 +00:00
|
|
|
|
# If not installed, install it
|
2023-05-22 23:13:15 +00:00
|
|
|
|
local pkg_manager=""
|
|
|
|
|
local speedtest_install_script=""
|
2024-01-20 13:58:44 +00:00
|
|
|
|
|
|
|
|
|
if command -v dnf &>/dev/null; then
|
2023-05-22 23:13:15 +00:00
|
|
|
|
pkg_manager="dnf"
|
|
|
|
|
speedtest_install_script="https://packagecloud.io/install/repositories/ookla/speedtest-cli/script.rpm.sh"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
elif command -v yum &>/dev/null; then
|
2023-05-22 23:13:15 +00:00
|
|
|
|
pkg_manager="yum"
|
|
|
|
|
speedtest_install_script="https://packagecloud.io/install/repositories/ookla/speedtest-cli/script.rpm.sh"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
elif command -v apt-get &>/dev/null; then
|
2023-05-22 23:13:15 +00:00
|
|
|
|
pkg_manager="apt-get"
|
|
|
|
|
speedtest_install_script="https://packagecloud.io/install/repositories/ookla/speedtest-cli/script.deb.sh"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
elif command -v apt &>/dev/null; then
|
2023-05-22 23:13:15 +00:00
|
|
|
|
pkg_manager="apt"
|
|
|
|
|
speedtest_install_script="https://packagecloud.io/install/repositories/ookla/speedtest-cli/script.deb.sh"
|
|
|
|
|
fi
|
2024-01-20 13:58:44 +00:00
|
|
|
|
|
2023-05-22 23:13:15 +00:00
|
|
|
|
if [[ -z $pkg_manager ]]; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "错误:找不到包管理器。您可能需要手动安装 Speedtest。"
|
2023-04-03 20:30:29 +00:00
|
|
|
|
return 1
|
2023-05-22 23:13:15 +00:00
|
|
|
|
else
|
2023-07-01 12:26:43 +00:00
|
|
|
|
curl -s $speedtest_install_script | bash
|
|
|
|
|
$pkg_manager install -y speedtest
|
2023-04-03 20:30:29 +00:00
|
|
|
|
fi
|
2023-04-03 15:52:23 +00:00
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
# Run Speedtest
|
|
|
|
|
speedtest
|
|
|
|
|
}
|
|
|
|
|
|
2023-07-18 10:24:28 +00:00
|
|
|
|
create_iplimit_jails() {
|
2024-02-27 10:02:25 +00:00
|
|
|
|
# Use default bantime if not passed => 15 minutes
|
|
|
|
|
local bantime="${1:-15}"
|
2024-01-20 12:19:34 +00:00
|
|
|
|
|
2024-01-20 16:41:58 +00:00
|
|
|
|
# Uncomment 'allowipv6 = auto' in fail2ban.conf
|
2024-01-20 12:19:34 +00:00
|
|
|
|
sed -i 's/#allowipv6 = auto/allowipv6 = auto/g' /etc/fail2ban/fail2ban.conf
|
2023-07-18 10:24:28 +00:00
|
|
|
|
|
2024-03-05 13:39:20 +00:00
|
|
|
|
#On Debian 12+ fail2ban's default backend should be changed to systemd
|
|
|
|
|
if [[ "${release}" == "debian" && ${os_version} -ge 12 ]]; then
|
|
|
|
|
sed -i '0,/action =/s/backend = auto/backend = systemd/' /etc/fail2ban/jail.conf
|
|
|
|
|
fi
|
|
|
|
|
|
2023-07-18 10:24:28 +00:00
|
|
|
|
cat << EOF > /etc/fail2ban/jail.d/3x-ipl.conf
|
|
|
|
|
[3x-ipl]
|
|
|
|
|
enabled=true
|
2024-03-05 13:39:20 +00:00
|
|
|
|
backend=auto
|
2023-07-18 10:24:28 +00:00
|
|
|
|
filter=3x-ipl
|
|
|
|
|
action=3x-ipl
|
|
|
|
|
logpath=${iplimit_log_path}
|
2024-02-27 10:02:25 +00:00
|
|
|
|
maxretry=2
|
|
|
|
|
findtime=32
|
2023-07-18 10:24:28 +00:00
|
|
|
|
bantime=${bantime}m
|
|
|
|
|
EOF
|
|
|
|
|
|
|
|
|
|
cat << EOF > /etc/fail2ban/filter.d/3x-ipl.conf
|
|
|
|
|
[Definition]
|
|
|
|
|
datepattern = ^%%Y/%%m/%%d %%H:%%M:%%S
|
|
|
|
|
failregex = \[LIMIT_IP\]\s*Email\s*=\s*<F-USER>.+</F-USER>\s*\|\|\s*SRC\s*=\s*<ADDR>
|
|
|
|
|
ignoreregex =
|
|
|
|
|
EOF
|
|
|
|
|
|
|
|
|
|
cat << EOF > /etc/fail2ban/action.d/3x-ipl.conf
|
|
|
|
|
[INCLUDES]
|
2024-02-27 10:02:25 +00:00
|
|
|
|
before = iptables-allports.conf
|
2023-07-18 10:24:28 +00:00
|
|
|
|
|
|
|
|
|
[Definition]
|
|
|
|
|
actionstart = <iptables> -N f2b-<name>
|
|
|
|
|
<iptables> -A f2b-<name> -j <returntype>
|
|
|
|
|
<iptables> -I <chain> -p <protocol> -j f2b-<name>
|
|
|
|
|
|
|
|
|
|
actionstop = <iptables> -D <chain> -p <protocol> -j f2b-<name>
|
|
|
|
|
<actionflush>
|
|
|
|
|
<iptables> -X f2b-<name>
|
|
|
|
|
|
|
|
|
|
actioncheck = <iptables> -n -L <chain> | grep -q 'f2b-<name>[ \t]'
|
|
|
|
|
|
|
|
|
|
actionban = <iptables> -I f2b-<name> 1 -s <ip> -j <blocktype>
|
|
|
|
|
echo "\$(date +"%%Y/%%m/%%d %%H:%%M:%%S") BAN [Email] = <F-USER> [IP] = <ip> banned for <bantime> seconds." >> ${iplimit_banned_log_path}
|
|
|
|
|
|
|
|
|
|
actionunban = <iptables> -D f2b-<name> -s <ip> -j <blocktype>
|
|
|
|
|
echo "\$(date +"%%Y/%%m/%%d %%H:%%M:%%S") UNBAN [Email] = <F-USER> [IP] = <ip> unbanned." >> ${iplimit_banned_log_path}
|
|
|
|
|
|
|
|
|
|
[Init]
|
|
|
|
|
EOF
|
|
|
|
|
|
2024-01-20 16:41:58 +00:00
|
|
|
|
echo -e "${green}Ip Limit jail files created with a bantime of ${bantime} minutes.${plain}"
|
2023-07-18 10:24:28 +00:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
iplimit_remove_conflicts() {
|
|
|
|
|
local jail_files=(
|
|
|
|
|
/etc/fail2ban/jail.conf
|
|
|
|
|
/etc/fail2ban/jail.local
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
for file in "${jail_files[@]}"; do
|
|
|
|
|
# Check for [3x-ipl] config in jail file then remove it
|
|
|
|
|
if test -f "${file}" && grep -qw '3x-ipl' ${file}; then
|
|
|
|
|
sed -i "/\[3x-ipl\]/,/^$/d" ${file}
|
|
|
|
|
echo -e "${yellow}Removing conflicts of [3x-ipl] in jail (${file})!${plain}\n"
|
|
|
|
|
fi
|
|
|
|
|
done
|
|
|
|
|
}
|
|
|
|
|
|
2023-06-24 20:36:18 +00:00
|
|
|
|
iplimit_main() {
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "\n${green}\t1.${plain} 安装 Fail2ban 并配置 IP 限制"
|
|
|
|
|
echo -e "${green}\t2.${plain} 更改禁令持续时间"
|
|
|
|
|
echo -e "${green}\t3.${plain} 取消对所有IP的禁止"
|
|
|
|
|
echo -e "${green}\t4.${plain} 检查日志"
|
|
|
|
|
echo -e "${green}\t5.${plain} fail2ban 状态"
|
|
|
|
|
echo -e "${green}\t6.${plain} 卸载 IP 限制"
|
|
|
|
|
echo -e "${green}\t0.${plain} 返回主菜单"
|
|
|
|
|
read -p "根据需要选择操作步骤:" choice
|
2023-06-24 20:36:18 +00:00
|
|
|
|
case "$choice" in
|
2024-01-20 13:58:44 +00:00
|
|
|
|
0)
|
|
|
|
|
show_menu
|
|
|
|
|
;;
|
|
|
|
|
1)
|
2024-03-10 14:29:24 +00:00
|
|
|
|
confirm "继续安装Fail2ban和IP Limit?" "y"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
if [[ $? == 0 ]]; then
|
|
|
|
|
install_iplimit
|
|
|
|
|
else
|
|
|
|
|
iplimit_main
|
|
|
|
|
fi
|
|
|
|
|
;;
|
|
|
|
|
2)
|
2024-03-10 14:29:24 +00:00
|
|
|
|
read -rp "请输入新的封禁持续时间(分钟数)[默认 30]: " NUM
|
2024-01-20 13:58:44 +00:00
|
|
|
|
if [[ $NUM =~ ^[0-9]+$ ]]; then
|
|
|
|
|
create_iplimit_jails ${NUM}
|
|
|
|
|
systemctl restart fail2ban
|
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red}${NUM} 不是一个数字!请再试一次。${plain}"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
fi
|
|
|
|
|
iplimit_main
|
|
|
|
|
;;
|
|
|
|
|
3)
|
2024-03-10 14:29:24 +00:00
|
|
|
|
confirm "继续从 IP 限制中解禁所有人?" "y"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
if [[ $? == 0 ]]; then
|
|
|
|
|
fail2ban-client reload --restart --unban 3x-ipl
|
2024-01-21 01:15:17 +00:00
|
|
|
|
truncate -s 0 "${iplimit_banned_log_path}"
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${green}所有用户成功解禁。${plain}"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
iplimit_main
|
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${yellow}取消.${plain}"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
fi
|
|
|
|
|
iplimit_main
|
|
|
|
|
;;
|
|
|
|
|
4)
|
|
|
|
|
show_banlog
|
|
|
|
|
;;
|
|
|
|
|
5)
|
|
|
|
|
service fail2ban status
|
|
|
|
|
;;
|
2023-07-19 11:36:55 +00:00
|
|
|
|
|
2024-01-20 13:58:44 +00:00
|
|
|
|
6)
|
|
|
|
|
remove_iplimit
|
|
|
|
|
;;
|
2024-03-10 14:29:24 +00:00
|
|
|
|
*) echo "无效选择" ;;
|
2023-06-24 20:36:18 +00:00
|
|
|
|
esac
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
install_iplimit() {
|
|
|
|
|
if ! command -v fail2ban-client &>/dev/null; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${green}未安装 Fail2ban。正在安装...!${plain}\n"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
|
2023-06-24 20:36:18 +00:00
|
|
|
|
# Check the OS and install necessary packages
|
|
|
|
|
case "${release}" in
|
2024-01-20 13:58:44 +00:00
|
|
|
|
ubuntu | debian)
|
2024-01-21 00:30:58 +00:00
|
|
|
|
apt update && apt install fail2ban -y
|
2024-01-20 13:58:44 +00:00
|
|
|
|
;;
|
|
|
|
|
centos | almalinux | rocky)
|
|
|
|
|
yum update -y && yum install epel-release -y
|
|
|
|
|
yum -y install fail2ban
|
|
|
|
|
;;
|
|
|
|
|
fedora)
|
|
|
|
|
dnf -y update && dnf -y install fail2ban
|
|
|
|
|
;;
|
|
|
|
|
*)
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red}不支持的操作系统。请检查脚本并手动安装必要的软件包。${plain}\n"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
exit 1
|
|
|
|
|
;;
|
2023-06-24 20:36:18 +00:00
|
|
|
|
esac
|
2024-01-19 14:58:09 +00:00
|
|
|
|
|
|
|
|
|
if ! command -v fail2ban-client &>/dev/null; then
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red}Fail2ban 安装失败。${plain}\n"
|
2024-01-19 14:58:09 +00:00
|
|
|
|
exit 1
|
|
|
|
|
fi
|
|
|
|
|
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${green}Fail2ban 安装成功!${plain}\n"
|
2023-06-24 20:36:18 +00:00
|
|
|
|
else
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${yellow}已安装 Fail2ban。${plain}\n"
|
2023-06-24 20:36:18 +00:00
|
|
|
|
fi
|
|
|
|
|
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${green}正在配置 IP 限制...${plain}\n"
|
2023-06-24 20:36:18 +00:00
|
|
|
|
|
2023-07-18 10:24:28 +00:00
|
|
|
|
# make sure there's no conflict for jail files
|
|
|
|
|
iplimit_remove_conflicts
|
2023-06-24 20:36:18 +00:00
|
|
|
|
|
2023-07-18 10:24:28 +00:00
|
|
|
|
# Check if log file exists
|
|
|
|
|
if ! test -f "${iplimit_banned_log_path}"; then
|
|
|
|
|
touch ${iplimit_banned_log_path}
|
2023-06-24 20:36:18 +00:00
|
|
|
|
fi
|
|
|
|
|
|
2023-07-18 10:24:28 +00:00
|
|
|
|
# Check if service log file exists so fail2ban won't return error
|
|
|
|
|
if ! test -f "${iplimit_log_path}"; then
|
|
|
|
|
touch ${iplimit_log_path}
|
2023-06-24 20:36:18 +00:00
|
|
|
|
fi
|
|
|
|
|
|
2023-07-18 10:24:28 +00:00
|
|
|
|
# Create the iplimit jail files
|
|
|
|
|
# we didn't pass the bantime here to use the default value
|
|
|
|
|
create_iplimit_jails
|
2023-06-24 20:36:18 +00:00
|
|
|
|
|
2023-07-01 12:26:43 +00:00
|
|
|
|
# Launching fail2ban
|
|
|
|
|
if ! systemctl is-active --quiet fail2ban; then
|
|
|
|
|
systemctl start fail2ban
|
2024-01-20 13:08:54 +00:00
|
|
|
|
systemctl enable fail2ban
|
2023-06-24 20:36:18 +00:00
|
|
|
|
else
|
|
|
|
|
systemctl restart fail2ban
|
|
|
|
|
fi
|
2023-07-01 12:26:43 +00:00
|
|
|
|
systemctl enable fail2ban
|
2023-06-24 20:36:18 +00:00
|
|
|
|
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${green}IP Limit 安装并配置成功!${plain}\n"
|
2023-06-24 20:36:18 +00:00
|
|
|
|
before_show_menu
|
|
|
|
|
}
|
|
|
|
|
|
2024-01-20 13:58:44 +00:00
|
|
|
|
remove_iplimit() {
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${green}\t1.${plain} 仅删除 IP 限制配置"
|
|
|
|
|
echo -e "${green}\t2.${plain} 卸载 Fail2ban 和 IP Limit"
|
|
|
|
|
echo -e "${green}\t0.${plain} 终止"
|
|
|
|
|
read -p "根据需要选择操作步骤: " num
|
2023-06-24 20:36:18 +00:00
|
|
|
|
case "$num" in
|
2024-01-20 13:58:44 +00:00
|
|
|
|
1)
|
|
|
|
|
rm -f /etc/fail2ban/filter.d/3x-ipl.conf
|
|
|
|
|
rm -f /etc/fail2ban/action.d/3x-ipl.conf
|
|
|
|
|
rm -f /etc/fail2ban/jail.d/3x-ipl.conf
|
|
|
|
|
systemctl restart fail2ban
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${green}IP Limit已成功删除!${plain}\n"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
before_show_menu
|
|
|
|
|
;;
|
|
|
|
|
2)
|
|
|
|
|
rm -rf /etc/fail2ban
|
|
|
|
|
systemctl stop fail2ban
|
|
|
|
|
case "${release}" in
|
|
|
|
|
ubuntu | debian)
|
|
|
|
|
apt-get remove -y fail2ban
|
|
|
|
|
apt-get purge -y fail2ban -y
|
|
|
|
|
apt-get autoremove -y
|
|
|
|
|
;;
|
|
|
|
|
centos | almalinux | rocky)
|
|
|
|
|
yum remove fail2ban -y
|
|
|
|
|
yum autoremove -y
|
|
|
|
|
;;
|
|
|
|
|
fedora)
|
|
|
|
|
dnf remove fail2ban -y
|
|
|
|
|
dnf autoremove -y
|
|
|
|
|
;;
|
|
|
|
|
*)
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red}不支持的操作系统。请手动卸载 Fail2ban。${plain}\n"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
exit 1
|
|
|
|
|
;;
|
|
|
|
|
esac
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${green}Fail2ban 和 IP Limit已成功删除!${plain}\n"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
before_show_menu
|
|
|
|
|
;;
|
|
|
|
|
0)
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${yellow}取消.${plain}\n"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
iplimit_main
|
|
|
|
|
;;
|
|
|
|
|
*)
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "${red}无效的选项。请选择一个有效数字${plain}\n"
|
2024-01-20 13:58:44 +00:00
|
|
|
|
remove_iplimit
|
|
|
|
|
;;
|
2023-06-24 20:36:18 +00:00
|
|
|
|
esac
|
|
|
|
|
}
|
2023-06-08 12:38:08 +00:00
|
|
|
|
|
2023-02-09 19:18:06 +00:00
|
|
|
|
show_usage() {
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo "X-UI 控件菜单: "
|
2023-02-09 19:18:06 +00:00
|
|
|
|
echo "------------------------------------------"
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo -e "x-ui - 进入控制菜单"
|
|
|
|
|
echo -e "x-ui start - 启动 x-ui "
|
|
|
|
|
echo -e "x-ui stop - 停止 x-ui "
|
|
|
|
|
echo -e "x-ui restart - 重启 x-ui "
|
|
|
|
|
echo -e "x-ui status - 显示 x-ui 状态"
|
|
|
|
|
echo -e "x-ui enable - 设置 x-ui 开机自启"
|
|
|
|
|
echo -e "x-ui disable - 禁用 x-ui 开启自启"
|
|
|
|
|
echo -e "x-ui log - 查看 x-ui 日志"
|
|
|
|
|
echo -e "x-ui banlog - 查看 Fail2ban 封禁日志"
|
|
|
|
|
echo -e "x-ui update - 更新 x-ui "
|
|
|
|
|
echo -e "x-ui install - 安装 x-ui "
|
|
|
|
|
echo -e "x-ui uninstall - 卸载 x-ui "
|
2023-02-09 19:18:06 +00:00
|
|
|
|
echo "------------------------------------------"
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
show_menu() {
|
|
|
|
|
echo -e "
|
2024-03-10 14:29:24 +00:00
|
|
|
|
${green}3X-ui 面板管理脚本${plain}
|
|
|
|
|
${green}0.${plain} 退出脚本
|
2023-02-09 19:18:06 +00:00
|
|
|
|
————————————————
|
2024-03-10 14:29:24 +00:00
|
|
|
|
${green}1.${plain} 安装
|
|
|
|
|
${green}2.${plain} 更新
|
|
|
|
|
${green}3.${plain} 自定义版本
|
|
|
|
|
${green}4.${plain} 卸载
|
2023-02-09 19:18:06 +00:00
|
|
|
|
————————————————
|
2024-03-10 14:29:24 +00:00
|
|
|
|
${green}5.${plain} 重置用户名 & 密码 & 密钥令牌
|
|
|
|
|
${green}6.${plain} 重置设置
|
|
|
|
|
${green}7.${plain} 更改端口
|
|
|
|
|
${green}8.${plain} 查看当前设置
|
2023-02-09 19:18:06 +00:00
|
|
|
|
————————————————
|
2024-03-10 14:29:24 +00:00
|
|
|
|
${green}9.${plain} 启动
|
|
|
|
|
${green}10.${plain} 停止
|
|
|
|
|
${green}11.${plain} 重启
|
|
|
|
|
${green}12.${plain} 查看状态
|
|
|
|
|
${green}13.${plain} 查看日志
|
2023-02-09 19:18:06 +00:00
|
|
|
|
————————————————
|
2024-03-10 14:29:24 +00:00
|
|
|
|
${green}14.${plain} 设置开启自启
|
|
|
|
|
${green}15.${plain} 禁用开机自启
|
2023-02-09 19:18:06 +00:00
|
|
|
|
————————————————
|
2024-03-10 14:29:24 +00:00
|
|
|
|
${green}16.${plain} SSL证书管理
|
|
|
|
|
${green}17.${plain} Cloudflare SSL证书
|
|
|
|
|
${green}18.${plain} IP Limit 管理
|
|
|
|
|
${green}19.${plain} WARP 管理
|
|
|
|
|
${green}20.${plain} Firewall 管理
|
2023-06-24 21:37:34 +00:00
|
|
|
|
————————————————
|
2024-03-10 14:29:24 +00:00
|
|
|
|
${green}21.${plain} 启用 BBR
|
|
|
|
|
${green}22.${plain} 更新 Geo 文件
|
|
|
|
|
${green}23.${plain} Ookla测速
|
2023-07-01 12:26:43 +00:00
|
|
|
|
"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
show_status
|
2024-03-10 14:29:24 +00:00
|
|
|
|
echo && read -p "请输入您的选择 [0-23]:" num
|
2023-02-09 19:18:06 +00:00
|
|
|
|
|
|
|
|
|
case "${num}" in
|
|
|
|
|
0)
|
|
|
|
|
exit 0
|
|
|
|
|
;;
|
|
|
|
|
1)
|
|
|
|
|
check_uninstall && install
|
|
|
|
|
;;
|
|
|
|
|
2)
|
|
|
|
|
check_install && update
|
|
|
|
|
;;
|
|
|
|
|
3)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
check_install && custom_version
|
2023-02-09 19:18:06 +00:00
|
|
|
|
;;
|
|
|
|
|
4)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
check_install && uninstall
|
2023-02-09 19:18:06 +00:00
|
|
|
|
;;
|
|
|
|
|
5)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
check_install && reset_user
|
2023-02-09 19:18:06 +00:00
|
|
|
|
;;
|
|
|
|
|
6)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
check_install && reset_config
|
2023-02-09 19:18:06 +00:00
|
|
|
|
;;
|
|
|
|
|
7)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
check_install && set_port
|
2023-02-09 19:18:06 +00:00
|
|
|
|
;;
|
|
|
|
|
8)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
check_install && check_config
|
2023-02-09 19:18:06 +00:00
|
|
|
|
;;
|
|
|
|
|
9)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
check_install && start
|
2023-02-09 19:18:06 +00:00
|
|
|
|
;;
|
|
|
|
|
10)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
check_install && stop
|
2023-02-09 19:18:06 +00:00
|
|
|
|
;;
|
|
|
|
|
11)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
check_install && restart
|
2023-02-09 19:18:06 +00:00
|
|
|
|
;;
|
|
|
|
|
12)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
check_install && status
|
2023-02-09 19:18:06 +00:00
|
|
|
|
;;
|
|
|
|
|
13)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
check_install && show_log
|
2023-02-09 19:18:06 +00:00
|
|
|
|
;;
|
|
|
|
|
14)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
check_install && enable
|
2023-02-09 19:18:06 +00:00
|
|
|
|
;;
|
|
|
|
|
15)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
check_install && disable
|
2023-02-09 19:18:06 +00:00
|
|
|
|
;;
|
|
|
|
|
16)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
ssl_cert_issue_main
|
2023-02-09 19:18:06 +00:00
|
|
|
|
;;
|
2023-04-02 14:42:00 +00:00
|
|
|
|
17)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
ssl_cert_issue_CF
|
2023-04-02 14:42:00 +00:00
|
|
|
|
;;
|
|
|
|
|
18)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
iplimit_main
|
2023-04-02 14:42:00 +00:00
|
|
|
|
;;
|
2023-04-03 15:52:23 +00:00
|
|
|
|
19)
|
2023-12-23 14:28:11 +00:00
|
|
|
|
warp_cloudflare
|
2023-04-03 15:52:23 +00:00
|
|
|
|
;;
|
2023-05-13 15:36:16 +00:00
|
|
|
|
20)
|
2024-02-07 17:53:11 +00:00
|
|
|
|
firewall_menu
|
2023-08-08 21:22:40 +00:00
|
|
|
|
;;
|
2024-01-27 09:26:10 +00:00
|
|
|
|
21)
|
2024-02-21 12:46:45 +00:00
|
|
|
|
bbr_menu
|
2023-12-23 14:28:11 +00:00
|
|
|
|
;;
|
2024-01-27 09:26:10 +00:00
|
|
|
|
22)
|
2024-02-07 17:53:11 +00:00
|
|
|
|
update_geo
|
2024-01-01 20:09:21 +00:00
|
|
|
|
;;
|
2024-01-27 09:26:10 +00:00
|
|
|
|
23)
|
2023-06-24 21:37:34 +00:00
|
|
|
|
run_speedtest
|
2024-01-20 13:58:44 +00:00
|
|
|
|
;;
|
2023-02-09 19:18:06 +00:00
|
|
|
|
*)
|
2024-03-10 14:29:24 +00:00
|
|
|
|
LOGE "请输入正确的号码 [0-23]"
|
2023-02-09 19:18:06 +00:00
|
|
|
|
;;
|
|
|
|
|
esac
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if [[ $# > 0 ]]; then
|
|
|
|
|
case $1 in
|
|
|
|
|
"start")
|
|
|
|
|
check_install 0 && start 0
|
|
|
|
|
;;
|
|
|
|
|
"stop")
|
|
|
|
|
check_install 0 && stop 0
|
|
|
|
|
;;
|
|
|
|
|
"restart")
|
|
|
|
|
check_install 0 && restart 0
|
|
|
|
|
;;
|
|
|
|
|
"status")
|
|
|
|
|
check_install 0 && status 0
|
|
|
|
|
;;
|
|
|
|
|
"enable")
|
|
|
|
|
check_install 0 && enable 0
|
|
|
|
|
;;
|
|
|
|
|
"disable")
|
|
|
|
|
check_install 0 && disable 0
|
|
|
|
|
;;
|
|
|
|
|
"log")
|
|
|
|
|
check_install 0 && show_log 0
|
|
|
|
|
;;
|
2023-09-04 23:50:09 +00:00
|
|
|
|
"banlog")
|
|
|
|
|
check_install 0 && show_banlog 0
|
|
|
|
|
;;
|
2023-02-09 19:18:06 +00:00
|
|
|
|
"update")
|
|
|
|
|
check_install 0 && update 0
|
|
|
|
|
;;
|
|
|
|
|
"install")
|
|
|
|
|
check_uninstall 0 && install 0
|
|
|
|
|
;;
|
|
|
|
|
"uninstall")
|
|
|
|
|
check_install 0 && uninstall 0
|
|
|
|
|
;;
|
|
|
|
|
*) show_usage ;;
|
|
|
|
|
esac
|
|
|
|
|
else
|
|
|
|
|
show_menu
|
|
|
|
|
fi
|