Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
synapse — Synapse:用 Python/Twisted 编写的 Matrix 家庭服务器。 | Kitploit
工具/GitHubGitHub/matrix-org/synapse
身份验证与授权加密/解密工具网络安全隐私保护身份与访问管理 (IAM)API 安全Archived
GitHubmatrix-org/synapse

synapse

Synapse:用 Python/Twisted 编写的 Matrix 家庭服务器。

查看仓库
12.1k2.1k272年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
网站

========================================================================= Synapse |support| |development| |documentation| |license| |pypi| |python|

Synapse 现已积极维护于 element-hq/synapse <https://github.com/element-hq/synapse>_

Synapse 是一个开源的 Matrix <https://matrix.org/>_ 家服务器,由 Matrix.org 基金会从 2019 年到 2023 年开发。Matrix.org 基金会无法继续维护 Synapse,其 由 Element 继续开发 <https://github.com/element-hq/synapse>;此外,您可以选择 其他 Matrix 家服务器 <https://matrix.org/ecosystem/servers/>。

更多信息请参阅 《Synapse 和 Dendrite 的未来》博客文章 <https://matrix.org/blog/2023/11/06/future-of-synapse-dendrite/>_。

=========================================================================

简而言之,Matrix 是互联网上通信的开放标准,支持联邦、加密和 VoIP。Matrix.org 对 Matrix 项目目标 <https://matrix.org/docs/guides/introduction>_ 有更多说明,正式规范 <https://spec.matrix.org/>_ 描述了技术细节。

.. contents::

安装与配置

Synapse 文档描述了 如何安装 Synapse <https://matrix-org.github.io/synapse/latest/setup/installation.html>。我们推荐使用 Docker 镜像 <https://matrix-org.github.io/synapse/latest/setup/installation.html#docker-images-and-ansible-playbooks> 或 Matrix.org 提供的 Debian 软件包 <https://matrix-org.github.io/synapse/latest/setup/installation.html#matrixorg-packages>_。

.. _federation:

Synapse 具有多种 配置选项 <https://matrix-org.github.io/synapse/latest/usage/configuration/config_documentation.html>_ 可在安装后用于自定义其行为。 关于 如何在此处配置 Synapse 以进行联邦 <https://matrix-org.github.io/synapse/latest/federate.html>_ 还有更多详细信息。

.. _reverse-proxy:

将反向代理与 Synapse 一起使用

建议在 Synapse 前放置反向代理,例如 nginx <https://nginx.org/en/docs/http/ngx_http_proxy_module.html>、 Apache <https://httpd.apache.org/docs/current/mod/mod_proxy_http.html>、 Caddy <https://caddyserver.com/docs/quick-starts/reverse-proxy>、 HAProxy <https://www.haproxy.org/> 或 relayd <https://man.openbsd.org/relayd.8>。这样做的一个好处是,您可以向 Matrix 客户端暴露默认的 https 端口(443),而无需以 root 权限运行 Synapse。 有关配置反向代理的信息,请参阅 反向代理文档 <https://matrix-org.github.io/synapse/latest/reverse_proxy.html>。

升级现有 Synapse 实例

升级 Synapse 的说明位于 升级说明_ 中。 请查看这些说明,因为对于某些版本的 Synapse,升级可能需要额外的步骤。

.. _升级说明: https://matrix-org.github.io/synapse/develop/upgrade.html

平台依赖项

Synapse 使用许多平台依赖项,例如 Python 和 PostgreSQL,并力求遵循上游支持的版本。有关更多详细信息,请参阅 弃用策略 <https://matrix-org.github.io/synapse/latest/deprecation_policy.html>_。

安全注意事项

Matrix 在某些 API 中提供原始的用户提供数据——特别是 内容存储库端点_。

.. _内容存储库端点: https://matrix.org/docs/spec/client_server/latest.html#get-matrix-media-r0-download-servername-mediaid

虽然我们做出合理努力来缓解 XSS 攻击(例如,通过使用 CSP_),但 Matrix 家服务器不应托管在托管其他 Web 应用程序的域名上。这尤其适用于与 Matrix Web 客户端以及其他敏感应用程序(如 Webmail)共享域名。有关更多信息,请参阅 https://developer.github.com/changes/2014-04-25-user-content-security。

.. _CSP: https://github.com/matrix-org/synapse/pull/1021

理想情况下,家服务器不仅应位于不同的子域,而且应位于完全不同的 注册域(也称为顶级站点或 eTLD+1)。这是因为只要两个应用程序共享同一个注册域,某些攻击 仍然可能发生。

.. _注册域: https://tools.ietf.org/html/draft-ietf-httpbis-rfc6265bis-03#section-2.3

.. _某些攻击: https://en.wikipedia.org/wiki/Session_fixation#Attacks_using_cross-subdomain_cookie

用一个例子说明:如果您的 Element Web 或其他敏感 Web 应用程序托管在 A.example1.com 上,理想情况下您应该将 Synapse 托管在 example2.com 上。托管在 B.example1.com 上可以提供一定程度的保护,因此在某些情况下也是可以接受的。但是,您不应将 Synapse 托管在 A.example1.com 上。

请注意,以上所有内容仅涉及 Synapse 的 public_baseurl 设置中使用的域。特别是,它与该服务器上托管的 MXID 中提及的域无关。

遵循此建议可确保即使 Synapse 中发现 XSS,对其他应用程序的影响也将最小。

测试新安装

尝试新 Synapse 安装的最简单方法是通过 Web 客户端连接到它。

除非您在本地机器上运行 Synapse 的测试实例,否则通常需要启用 TLS 支持才能成功从客户端连接:请参阅 TLS 证书 <https://matrix-org.github.io/synapse/latest/setup/installation.html#tls-certificates>_。

一个简单的入门方法是通过 Element 登录或注册,分别访问 https://app.element.io/#/login 或 https://app.element.io/#/register。 您需要将登录的服务器从 matrix.org 更改,并指定家服务器 URL 为 https://<server_name>:8448 (如果使用反向代理,则为 https://<server_name>)。 如果您更喜欢使用其他客户端,请参阅我们的 客户端分类 <https://matrix.org/ecosystem/clients/>_。

如果一切顺利,您至少应该能够登录、创建房间并开始发送消息。

.. _client-user-reg:

从客户端注册新用户

默认情况下,通过 Matrix 客户端注册新用户是禁用的。要启用它:

  1. 在 注册配置部分 <https://matrix-org.github.io/synapse/latest/usage/configuration/config_documentation.html#registration>_ 中将 homeserver.yaml 中的 enable_registration: true 设置为 true。

  2. 然后或者:

    a. 设置 CAPTCHA <https://matrix-org.github.io/synapse/latest/CAPTCHA_SETUP.html>_,或者 b. 在 homeserver.yaml 中设置 enable_registration_without_verification: true。

我们强烈建议使用 CAPTCHA,特别是如果您的家服务器暴露在公共互联网上。如果没有它,任何人都可以自由地在您的家服务器上注册帐户。攻击者可以利用这一点创建垃圾机器人,针对 Matrix 联邦的其他部分。

您的新用户名将由 server_name 的一部分以及您创建帐户时指定的本地部分共同构成。您的名称将采用以下格式::

@localpart:my.domain.name

(读作“at localpart on my dot domain dot name”)。

与登录时一样,您需要指定一个“自定义服务器”。在“用户名”框中输入您想要的 localpart。

故障排除与支持

管理 FAQ <https://matrix-org.github.io/synapse/latest/usage/administration/admin_faq.html>_ 包含处理一些常见问题的技巧。有关更多详细信息,请参阅 Synapse 更广泛的文档 <https://matrix-org.github.io/synapse/latest/>_。

如需有关安装或管理 Synapse 的额外支持,请在社区支持房间 |room|_ 中提问(如有必要,请使用 matrix.org 帐户)。我们不使用 GitHub issues 来处理支持请求,只用于错误报告和功能请求。

.. |room| replace:: #synapse:matrix.org .. _room: https://matrix.to/#/#synapse:matrix.org

.. |docs| replace:: docs .. _docs: docs

身份服务器

身份服务器的任务是将电子邮件地址和其他第三方 ID(3PID)映射到 Matrix 用户 ID,以及在创建映射之前验证 3PID 的所有权。

它们不存储帐户或凭据——这些存储在家服务器上。身份服务器仅用于将第三方 ID 映射到 Matrix ID。

这个过程对安全性非常敏感,因为如果注册 Matrix 帐户或收集 3PID 数据过于容易,就会存在明显的垃圾邮件风险。长期来看,我们希望创建一个去中心化的系统来管理它(matrix-doc #712 <https://github.com/matrix-org/matrix-doc/issues/712>),但与此同时,在 Matrix 生态系统中管理受信任身份的角色被外包给一组已知的受信任生态系统合作伙伴集群,他们运行“Matrix 身份服务器”,例如 Sydent <https://github.com/matrix-org/sydent>,其角色纯粹是验证和跟踪 3PID 登录,并发布最终用户的公钥。

您可以托管自己的 Sydent 副本,但这会阻止您通过电子邮件地址联系 Matrix 生态系统中的其他用户,并阻止他们找到您。因此,我们建议您现在使用集中式身份服务器之一,位于 https://matrix.org 或 https://vector.im。

重申:仅当您选择将电子邮件地址与您的帐户关联,或通过电子邮件地址向其他用户发送邀请时,才会使用身份服务器。

开发

我们欢迎社区为 Synapse 做出贡献! 最佳起点是我们的 贡献者指南 <https://matrix-org.github.io/synapse/latest/development/contributing_guide.html>。 这是我们的较大 文档 <https://matrix-org.github.io/synapse/latest> 的一部分,其中包含

面向 Synapse 开发者和 Synapse 管理员的信息。开发者可能特别感兴趣:

  • Synapse 的数据库模式 <https://matrix-org.github.io/synapse/latest/development/database_schema.html>_,
  • 关于 Synapse 实现细节的说明 <https://matrix-org.github.io/synapse/latest/development/internal_documentation/index.html>_,以及
  • 我们如何使用 git <https://matrix-org.github.io/synapse/latest/development/git.html>_。

除此之外,欢迎加入我们在 Matrix 上的开发者社区: #synapse-dev:matrix.org <https://matrix.to/#/#synapse-dev:matrix.org>_,有真人参与!

.. |support| image:: https://img.shields.io/matrix/synapse:matrix.org?label=support&logo=matrix :alt: (在 #synapse:matrix.org 上获取支持) :target: https://matrix.to/#/#synapse:matrix.org

.. |development| image:: https://img.shields.io/matrix/synapse-dev:matrix.org?label=development&logo=matrix :alt: (在 #synapse-dev:matrix.org 上讨论开发) :target: https://matrix.to/#/#synapse-dev:matrix.org

.. |documentation| image:: https://img.shields.io/badge/documentation-%E2%9C%93-success :alt: (GitHub Pages 上的已渲染文档) :target: https://matrix-org.github.io/synapse/latest/

.. |license| image:: https://img.shields.io/github/license/matrix-org/synapse :alt: (在 LICENSE 文件中查看许可证) :target: LICENSE

.. |pypi| image:: https://img.shields.io/pypi/v/matrix-synapse :alt: (PyPi 上发布的最新版本) :target: https://pypi.org/project/matrix-synapse

.. |python| image:: https://img.shields.io/pypi/pyversions/matrix-synapse :alt: (支持的 Python 版本) :target: https://pypi.org/project/matrix-synapse

下载工具