العودة إلى التحديثات
New releaseAug 9, 2026

chisel v1.12.0-rc3

نفق TCP/UDP سريع عبر HTTP مع تشفير SSH، يدعم إعادة توجيه المنافذ العكسية، ووكيل SOCKS5، والمصادقة من العميل لاختراق الشبكة بأمان وتجاوز جدران الحماية.

مشاركة

Chisel

GoDoc CI

Chisel هو نفق TCP/UDP سريع، يُنقل عبر HTTP، ومؤمَّن عبر SSH. ملف تنفيذي واحد يشمل العميل والخادم معًا. مكتوب بلغة Go (golang). Chisel مفيد بشكل أساسي لاختراق جدران الحماية، كما يمكن استخدامه لتوفير نقطة نهاية آمنة لشبكتك.

overview

جدول المحتويات

الميزات

  • سهل الاستخدام
  • أداء عالٍ*
  • اتصالات مشفرة باستخدام بروتوكول SSH (عبر crypto/ssh)
  • اتصالات موثَّقة؛ اتصالات عملاء موثَّقة عبر ملف إعدادات المستخدمين، واتصالات خوادم موثَّقة عبر مطابقة بصمة الإصبع.
  • إعادة اتصال تلقائية للعميل مع تراجع أسي (قابل للضبط عبر --min/max-retry-interval)؛ تنتهي مهلة حزم البقاء على قيد الحياة، لذلك يتم اكتشاف الاتصالات الميتة بصمت (نوم/استيقاظ، انتهاء مهلة NAT، إعادة تشغيل الخادم) وإعادة إنشائها
  • يمكن للعملاء إنشاء نقاط نهاية نفق متعددة عبر اتصال TCP واحد
  • يمكن للعملاء اختياريًا المرور عبر وكلاء SOCKS أو HTTP CONNECT
  • إعادة توجيه المنافذ العكسية (تمر الاتصالات عبر الخادم وتخرج من العميل)
  • يمكن للخادم اختياريًا أن يعمل كـ وكيل عكسي
  • يسمح الخادم اختياريًا باتصالات SOCKS5 (انظر الدليل أدناه)
  • يسمح العملاء اختياريًا باتصالات SOCKS5 من منفذ مُعاد توجيهه عكسيًا
  • اتصالات العميل عبر stdio التي تدعم ssh -o ProxyCommand لتوفير SSH عبر HTTP

التثبيت

الملفات الثنائية

Releases Releases

انظر أحدث إصدار أو قم بتنزيله وتثبيته الآن باستخدام curl https://i.jpillora.com/chisel! | bash

تم بناء الملفات الثنائية بأحدث إصدار من Go، والذي يحدد الحد الأدنى لإصدارات أنظمة التشغيل: Windows 10 / Server 2016، macOS 12، نواة Linux 3.2، FreeBSD 12.2. للأنظمة الأقدم (مثل Windows 7)، استخدم الإصدار v1.8.1 أو إصدارات أقدم.

Docker

Docker Pulls Image Size```sh docker run --rm -it jpillora/chisel --help

الصور متعددة البنى (multi-arch) وتُنشر على كل من Docker Hub (`jpillora/chisel`) وسجل حاويات GitHub (`ghcr.io/jpillora/chisel`).

### فيدورا

الحزمة تتم صيانتها من قبل مجتمع فيدورا. إذا واجهت مشكلات متعلقة باستخدام حزمة RPM، فيرجى استخدام [متتبع المشكلات](https://bugzilla.redhat.com/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&classification=Fedora&component=chisel&list_id=11614537&product=Fedora&product=Fedora%20EPEL) هذا.```sh
sudo dnf -y install chisel

المصدر```sh

$ go install github.com/jpillora/chisel@latest

## العرض التوضيحي

يمكنك تشغيل خادم العرض التوضيحي الخاص بك في دقائق (اختفت نسخة Heroku التجريبية القديمة مع الطبقة المجانية لـ Heroku). يقوم [`example/fly.toml`](https://github.com/jpillora/chisel/blob/master/example/fly.toml) بنشر خادم `chisel server` هذا إلى الحصة المجانية لـ [fly.io](https://fly.io):```sh
$ chisel server --port $PORT --backend http://example.com
# listens on $PORT, proxies normal web requests to http://example.com

قم بنشره باستخدام fly launch --copy-config من دليل example/، ثم أنشئ نفقًا إلى أي خدمة تعمل بجانب الخادم، على سبيل المثال:```sh $ chisel client https://.fly.dev 3000

connects to your chisel server,

tunnels your localhost:3000 to the server's localhost:3000

زيارة رابط تطبيقك في المتصفح تصل إلى الوكيل الخلفي الافتراضي للخادم وتعرض نسخة من [example.com](http://example.com).

## الاستخدام

<!-- اعرض نصوص المساعدة هذه يدويًا،
  أو استخدم https://github.com/jpillora/md-tmpl
    مع $ md-tmpl -w README.md -->

<!--tmpl,code=plain:echo "$ chisel --help" && go run main.go --help | sed 's#0.0.0-src (go1\..*)#X.Y.Z#' -->``` plain 
$ chisel --help

  Usage: chisel [command] [--help]

  Version: X.Y.Z

  Commands:
    server - runs chisel in server mode
    client - runs chisel in client mode

  Read more:
    https://github.com/jpillora/chisel

``` plain

$ chisel server --help

Usage: chisel server [options]

Options:

--host, Defines the HTTP listening host – the network interface
(defaults the environment variable HOST and falls back to 0.0.0.0).

--port, -p, Defines the HTTP listening port (defaults to the environment
variable PORT and falls back to port 8080).

--key, (deprecated use --keygen and --keyfile instead)
An optional string to seed the generation of a ECDSA public
and private key pair. All communications will be secured using this
key pair. Share the subsequent fingerprint with clients to enable detection
of man-in-the-middle attacks (defaults to the CHISEL_KEY environment
variable, otherwise a new key is generate each run).

--keygen, A path to write a newly generated PEM-encoded SSH private key file.
If users depend on your --key fingerprint, you may also include your --key to
output your existing key. Use - (dash) to output the generated key to stdout.

--keyfile, An optional path to a PEM-encoded SSH private key. When
this flag is set, the --key option is ignored, and the provided private key
is used to secure all communications. (defaults to the CHISEL_KEY_FILE
environment variable). Since ECDSA keys are short, you may also set keyfile
to the inline key string itself, exactly as printed by --keygen (a base64
string with a "ck-" prefix); no extra base64 encoding is needed.

--authfile, An optional path to a users.json file. This file should
be an object with users defined like:
  {
    "<user:pass>": ["<addr-regex>","<addr-regex>"]
  }
when <user> connects, their <pass> will be verified and then
each of the remote addresses will be compared against the list
of address regular expressions for a match. Patterns are NOT
anchored by default: "10.0.0.1:80" also matches
"210.0.0.1:8080", and "." matches any character. Anchor your
patterns, e.g. "^10\.0\.0\.1:80$". The empty string ""
matches every address. Addresses will
always come in the form "<remote-host>:<remote-port>" for normal remotes,
"R:<local-interface>:<local-port>" for reverse port forwarding
remotes, and "socks" for SOCKS5 proxy access. Note that SOCKS5
access previously bypassed this list; existing authfiles which
should allow SOCKS5 must add an entry matching "socks" (the
empty wildcard "" matches everything, including "socks"). This
file will be automatically reloaded on change. Reloads apply
to new connections and to new tunnels of connected clients;
established tunnels are not interrupted.

--auth, An optional string representing a single user with full
access, in the form of <user:pass>. It is equivalent to creating an
authfile with {"<user:pass>": [""]}. If unset, it will use the
environment variable AUTH.

الفئات