iPhone緊急警示提示xx公安局提醒youtube是詐騙網站
請問是什麼情況
#2211
-
背景最近用iPhone看youtube app的時候,突然間來了個緊急警示提示 配置參數網絡拓扑客戶端{
"log": {
"loglevel": "warning",
"error": "/var/log/xray/error.log",
"access": "/var/log/xray/access.log",
"dnsLog": false
},
"inbounds": [
{
"tag": "all-in",
"port": 12345,
"protocol": "dokodemo-door",
"settings": {
"network": "tcp,udp",
"followRedirect": true
},
"sniffing": {
"enabled": true,
"destOverride": ["http", "tls", "quic"]
},
"streamSettings": {
"sockopt": {
"tproxy": "tproxy"
}
}
},
{
"tag": "socks-in",
"port": 10808,
"protocol": "socks",
"sniffing": {
"enabled": true,
"destOverride": ["http", "tls", "quic"]
},
"settings": {
"auth": "noauth",
"udp": true
}
}
],
"outbounds": [
{
"tag": "direct",
"protocol": "freedom",
"settings": {
"domainStrategy": "UseIP"
},
"streamSettings": {
"sockopt": {
"mark": 255
}
}
},
{
"tag": "proxy",
"protocol": "vmess",
"settings": {
"vnext": [
{
"address": "vpn.domain",
"port": 19191,
"users": [
{
"id": "xxxxxx-xxxx-xxxx-xxxx-xxxx",
"alterId": 0,
"encryption": "auto"
}
]
}
]
},
"streamSettings": {
"network": "tcp",
"security": "none",
"sockopt": {
"mark": 255
}
}
},
{
"tag": "block",
"protocol": "blackhole",
"settings": {
"response": {
"type": "http"
}
}
},
{
"tag": "dns-out",
"protocol": "dns",
"streamSettings": {
"sockopt": {
"mark": 255
}
}
}
],
"dns": {
"hosts": {
"domain:googleapis.cn": "googleapis.com",
"dns.google": "8.8.8.8",
"doh.pub": "120.53.53.53",
"dns.alidns.com": "223.5.5.5"
},
"servers": [
"https://dns.google/dns-query",
{
"address": "https://doh.pub/dns-query",
"domains": ["geosite:cn", "vpn.domain"],
"skipFallback": true
},
{
"address": "https://dns.alidns.com/dns-query",
"domains": ["geosite:cn", "vpn.domain"],
"skipFallback": true
}
]
},
"routing": {
"domainMatcher": "mph",
"domainStrategy": "IPIfNonMatch",
"rules": [
{
"type": "field",
"domain": ["geosite:category-ads-all"],
"outboundTag": "block"
},
{
"type": "field",
"inboundTag": ["all-in"],
"port": 123,
"network": "udp",
"outboundTag": "direct"
},
{
"type": "field",
"inboundTag": ["all-in"],
"port": 53,
"network": "udp",
"outboundTag": "dns-out"
},
{
"type": "field",
"ip": ["223.5.5.5"],
"outboundTag": "direct"
},
{
"type": "field",
"outboundTag": "direct",
"protocol": ["bittorrent"]
},
{
"type": "field",
"ip": ["geoip:private", "geoip:cn"],
"outboundTag": "direct"
},
{
"type": "field",
"domain": ["geosite:cn"],
"outboundTag": "direct"
},
{
"type": "field",
"inboundTag": ["socks-in"],
"outboundTag": "proxy"
},
{
"type": "field",
"ip": ["1.1.1.1", "8.8.8.8"],
"outboundTag": "proxy"
},
{
"type": "field",
"ip": ["geoip:telegram"],
"outboundTag": "proxy"
},
{
"type": "field",
"domain": [
"geosite:geolocation-!cn",
"domain:googleapis.cn",
"dns.google"
],
"outboundTag": "proxy"
},
{
"type": "field",
"domain": [
"joinpeertube.org",
"myunidays.com"
],
"outboundTag": "proxy"
}
]
}
} 基本按照 透明代理(TProxy)配置教程 操作,使用 nftables 伺服器使用 猜想
|
Beta Was this translation helpful? Give feedback.
Replies: 8 comments 25 replies
-
目前暫時改成代理優先的策略,並且vpn域名改成ip,觀察一段時間看看 |
Beta Was this translation helpful? Give feedback.
-
使用谷歌的DNS应该更安全 |
Beta Was this translation helpful? Give feedback.
-
报 YouTube 似乎是新情况,今天 Project X 群里有两张安卓的截图:https://t.me/projectXray/2476790 ,https://t.me/projectXray/2476819 分析你的情况:
|
Beta Was this translation helpful? Give feedback.
-
我看你是在路由器上建立代理 額外補充兩點 iphone如果開啟背景app自動整理,當你關閉wifi(連著代理),切換成行動服務(無代理)的時候,youtube app可能會發起查詢,這時候行動isp就可以把這個信息上報給條子,然後你就會收到條子的訊息 以及,即使你關閉背景app自動整理,然後在代理關閉後才關閉youtube app,這種情況也有可能會產生洩漏,關閉youtube app一定要在關閉代理之前執行 |
Beta Was this translation helpful? Give feedback.
-
没见过iPhone会这样,请问 |
Beta Was this translation helpful? Give feedback.
-
如楼上所说,我感觉问题可能还是出在非A/AAAA的DNS泄露上 毕竟如果没有曾经泄露过连接信息(即使有,我个人感觉也不太可能用来单独追踪你,因为,毕竟,有点大材小用了)的话,DNS是成本最低且效果最好的能知道你在访问什么网站的(SNI/Host之类的仅限于HTTP(S)请求,某种意义上来说不如检测DNS请求来的全面) 建议,如果是装在路由器/网关上,配合其他DNS分流软件(比如SmartDNS之类的)使用比较好 |
Beta Was this translation helpful? Give feedback.
-
如果真的是非A/AAAA查詢洩漏,我有個疑問是為什麼YouTube app要進行非A/AAAA查詢?因為沒必要使用非A/AAAA查詢,即使YouTube app使用quic需要進行傳送,需要用非A/AAAA查詢的情況下也不會導致洩漏 非A/AAAA查詢會導致洩漏,但是我給出的猜想是YouTube app是非A/AAAA查詢造成洩漏的概率很低 |
Beta Was this translation helpful? Give feedback.
-
我想到一个可能性,你客户端设置的第一个outbound不应该填freedom啊, |
Beta Was this translation helpful? Give feedback.
报 YouTube 似乎是新情况,今天 Project X 群里有两张安卓的截图:https://t.me/projectXray/2476790 ,https://t.me/projectXray/2476819
两张安卓的截图
分析你的情况: