نفق TCP/UDP سريع عبر HTTP مع تشفير SSH، يدعم إعادة توجيه المنافذ العكسية، ووكيل SOCKS5، والمصادقة من العميل لاختراق الشبكة بأمان وتجاوز جدران الحماية.
Chisel هو نفق TCP/UDP سريع، يُنقل عبر HTTP، ومؤمَّن عبر SSH. ملف تنفيذي واحد يشمل العميل والخادم معًا. مكتوب بلغة Go (golang). Chisel مفيد بشكل أساسي لاختراق جدران الحماية، كما يمكن استخدامه لتوفير نقطة نهاية آمنة لشبكتك.

crypto/ssh)--min/max-retry-interval)؛ تنتهي مهلة حزم البقاء على قيد الحياة، لذلك يتم اكتشاف الاتصالات الميتة بصمت (نوم/استيقاظ، انتهاء مهلة NAT، إعادة تشغيل الخادم) وإعادة إنشائهاssh -o ProxyCommand لتوفير SSH عبر HTTPانظر أحدث إصدار أو قم بتنزيله وتثبيته الآن باستخدام curl https://i.jpillora.com/chisel! | bash
تم بناء الملفات الثنائية بأحدث إصدار من Go، والذي يحدد الحد الأدنى لإصدارات أنظمة التشغيل: Windows 10 / Server 2016، macOS 12، نواة Linux 3.2، FreeBSD 12.2. للأنظمة الأقدم (مثل Windows 7)، استخدم الإصدار v1.8.1 أو إصدارات أقدم.
```sh
docker run --rm -it jpillora/chisel --help
الصور متعددة البنى (multi-arch) وتُنشر على كل من Docker Hub (`jpillora/chisel`) وسجل حاويات GitHub (`ghcr.io/jpillora/chisel`).
### فيدورا
الحزمة تتم صيانتها من قبل مجتمع فيدورا. إذا واجهت مشكلات متعلقة باستخدام حزمة RPM، فيرجى استخدام [متتبع المشكلات](https://bugzilla.redhat.com/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&classification=Fedora&component=chisel&list_id=11614537&product=Fedora&product=Fedora%20EPEL) هذا.```sh
sudo dnf -y install chisel
$ go install github.com/jpillora/chisel@latest
## العرض التوضيحي
يمكنك تشغيل خادم العرض التوضيحي الخاص بك في دقائق (اختفت نسخة Heroku التجريبية القديمة مع الطبقة المجانية لـ Heroku). يقوم [`example/fly.toml`](https://github.com/jpillora/chisel/blob/master/example/fly.toml) بنشر خادم `chisel server` هذا إلى الحصة المجانية لـ [fly.io](https://fly.io):```sh
$ chisel server --port $PORT --backend http://example.com
# listens on $PORT, proxies normal web requests to http://example.com
قم بنشره باستخدام fly launch --copy-config من دليل example/، ثم أنشئ نفقًا إلى أي خدمة تعمل بجانب الخادم، على سبيل المثال:```sh
$ chisel client https://.fly.dev 3000
زيارة رابط تطبيقك في المتصفح تصل إلى الوكيل الخلفي الافتراضي للخادم وتعرض نسخة من [example.com](http://example.com).
## الاستخدام
<!-- اعرض نصوص المساعدة هذه يدويًا،
أو استخدم https://github.com/jpillora/md-tmpl
مع $ md-tmpl -w README.md -->
<!--tmpl,code=plain:echo "$ chisel --help" && go run main.go --help | sed 's#0.0.0-src (go1\..*)#X.Y.Z#' -->``` plain
$ chisel --help
Usage: chisel [command] [--help]
Version: X.Y.Z
Commands:
server - runs chisel in server mode
client - runs chisel in client mode
Read more:
https://github.com/jpillora/chisel
``` plain
$ chisel server --help
Usage: chisel server [options]
Options:
--host, Defines the HTTP listening host – the network interface
(defaults the environment variable HOST and falls back to 0.0.0.0).
--port, -p, Defines the HTTP listening port (defaults to the environment
variable PORT and falls back to port 8080).
--key, (deprecated use --keygen and --keyfile instead)
An optional string to seed the generation of a ECDSA public
and private key pair. All communications will be secured using this
key pair. Share the subsequent fingerprint with clients to enable detection
of man-in-the-middle attacks (defaults to the CHISEL_KEY environment
variable, otherwise a new key is generate each run).
--keygen, A path to write a newly generated PEM-encoded SSH private key file.
If users depend on your --key fingerprint, you may also include your --key to
output your existing key. Use - (dash) to output the generated key to stdout.
--keyfile, An optional path to a PEM-encoded SSH private key. When
this flag is set, the --key option is ignored, and the provided private key
is used to secure all communications. (defaults to the CHISEL_KEY_FILE
environment variable). Since ECDSA keys are short, you may also set keyfile
to the inline key string itself, exactly as printed by --keygen (a base64
string with a "ck-" prefix); no extra base64 encoding is needed.
--authfile, An optional path to a users.json file. This file should
be an object with users defined like:
{
"<user:pass>": ["<addr-regex>","<addr-regex>"]
}
when <user> connects, their <pass> will be verified and then
each of the remote addresses will be compared against the list
of address regular expressions for a match. Patterns are NOT
anchored by default: "10.0.0.1:80" also matches
"210.0.0.1:8080", and "." matches any character. Anchor your
patterns, e.g. "^10\.0\.0\.1:80$". The empty string ""
matches every address. Addresses will
always come in the form "<remote-host>:<remote-port>" for normal remotes,
"R:<local-interface>:<local-port>" for reverse port forwarding
remotes, and "socks" for SOCKS5 proxy access. Note that SOCKS5
access previously bypassed this list; existing authfiles which
should allow SOCKS5 must add an entry matching "socks" (the
empty wildcard "" matches everything, including "socks"). This
file will be automatically reloaded on change. Reloads apply
to new connections and to new tunnels of connected clients;
established tunnels are not interrupted.
--auth, An optional string representing a single user with full
access, in the form of <user:pass>. It is equivalent to creating an
authfile with {"<user:pass>": [""]}. If unset, it will use the
environment variable AUTH.