0% found this document useful (0 votes)
110 views8 pages

Install Shadowsocks-Python Server

This bash script installs and configures Shadowsocks-Python on CentOS 6+, Debian 7+, or Ubuntu 12+ systems. It downloads and compiles the required libraries, downloads the Shadowsocks files from GitHub, configures Shadowsocks with the user's selected password, port, and cipher, sets the firewall to allow the port, and installs Shadowsocks as a service.

Uploaded by

Gurban Babayew
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
110 views8 pages

Install Shadowsocks-Python Server

This bash script installs and configures Shadowsocks-Python on CentOS 6+, Debian 7+, or Ubuntu 12+ systems. It downloads and compiles the required libraries, downloads the Shadowsocks files from GitHub, configures Shadowsocks with the user's selected password, port, and cipher, sets the firewall to allow the port, and installs Shadowsocks as a service.

Uploaded by

Gurban Babayew
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd

#!

/usr/bin/env bash
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
export PATH
#=================================================================#
# System Required: CentOS 6+, Debian 7+, Ubuntu 12+ #
# Description: One click Install Shadowsocks-Python server #
# Thanks: @clowwindy <[Link] #
#=================================================================#

clear
echo
echo "#############################################################"
echo "# One click Install Shadowsocks-Python server #"
echo "# Github: [Link] #"
echo "#############################################################"
echo

libsodium_file="libsodium-1.0.16"
libsodium_url="[Link]
[Link]"

# Current folder
cur_dir=`pwd`
# Stream Ciphers
ciphers=(
aes-256-gcm
aes-192-gcm
aes-128-gcm
aes-256-ctr
aes-192-ctr
aes-128-ctr
aes-256-cfb
aes-192-cfb
aes-128-cfb
camellia-128-cfb
camellia-192-cfb
camellia-256-cfb
chacha20-ietf-poly1305
chacha20-ietf
chacha20
rc4-md5
)
# Color
red='\033[0;31m'
green='\033[0;32m'
yellow='\033[0;33m'
plain='\033[0m'

# Make sure only root can run our script


[[ $EUID -ne 0 ]] && echo -e "[${red}Error${plain}] This script must be run as
root!" && exit 1

# Disable selinux
disable_selinux(){
if [ -s /etc/selinux/config ] && grep 'SELINUX=enforcing' /etc/selinux/config;
then
sed -i 's/SELINUX=enforcing/SELINUX=disabled/g' /etc/selinux/config
setenforce 0
fi
}

#Check system
check_sys(){
local checkType=$1
local value=$2

local release=''
local systemPackage=''

if [[ -f /etc/redhat-release ]]; then


release="centos"
systemPackage="yum"
elif grep -Eqi "debian" /etc/issue; then
release="debian"
systemPackage="apt"
elif grep -Eqi "ubuntu" /etc/issue; then
release="ubuntu"
systemPackage="apt"
elif grep -Eqi "centos|red hat|redhat" /etc/issue; then
release="centos"
systemPackage="yum"
elif grep -Eqi "debian" /proc/version; then
release="debian"
systemPackage="apt"
elif grep -Eqi "ubuntu" /proc/version; then
release="ubuntu"
systemPackage="apt"
elif grep -Eqi "centos|red hat|redhat" /proc/version; then
release="centos"
systemPackage="yum"
fi

if [[ "${checkType}" == "sysRelease" ]]; then


if [ "${value}" == "${release}" ]; then
return 0
else
return 1
fi
elif [[ "${checkType}" == "packageManager" ]]; then
if [ "${value}" == "${systemPackage}" ]; then
return 0
else
return 1
fi
fi
}

# Get version
getversion(){
if [[ -s /etc/redhat-release ]]; then
grep -oE "[0-9.]+" /etc/redhat-release
else
grep -oE "[0-9.]+" /etc/issue
fi
}

# CentOS version
centosversion(){
if check_sys sysRelease centos; then
local code=$1
local version="$(getversion)"
local main_ver=${version%%.*}
if [ "$main_ver" == "$code" ]; then
return 0
else
return 1
fi
else
return 1
fi
}

# Get public IP address


get_ip(){
local IP=$( ip addr | egrep -o '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'
| egrep -v "^192\.168|^172\.1[6-9]\.|^172\.2[0-9]\.|^172\.3[0-2]\.|^10\.|^127\.|
^255\.|^0\." | head -n 1 )
[ -z ${IP} ] && IP=$( wget -qO- -t1 -T2 [Link] )
[ -z ${IP} ] && IP=$( wget -qO- -t1 -T2 [Link]/ip )
[ ! -z ${IP} ] && echo ${IP} || echo
}

get_char(){
SAVEDSTTY=`stty -g`
stty -echo
stty cbreak
dd if=/dev/tty bs=1 count=1 2> /dev/null
stty -raw
stty echo
stty $SAVEDSTTY
}

# Pre-installation settings
pre_install(){
if check_sys packageManager yum || check_sys packageManager apt; then
# Not support CentOS 5
if centosversion 5; then
echo -e "$[{red}Error${plain}] Not supported CentOS 5, please change to
CentOS 6+/Debian 7+/Ubuntu 12+ and try again."
exit 1
fi
else
echo -e "[${red}Error${plain}] Your OS is not supported. please change OS
to CentOS/Debian/Ubuntu and try again."
exit 1
fi
# Set shadowsocks config password
echo "Please enter password for shadowsocks-python"
read -p "(Default password: [Link]):" shadowsockspwd
[ -z "${shadowsockspwd}" ] && shadowsockspwd="[Link]"
echo
echo "---------------------------"
echo "password = ${shadowsockspwd}"
echo "---------------------------"
echo
# Set shadowsocks config port
while true
do
dport=$(shuf -i 9000-19999 -n 1)
echo "Please enter a port for shadowsocks-python [1-65535]"
read -p "(Default port: ${dport}):" shadowsocksport
[ -z "$shadowsocksport" ] && shadowsocksport=${dport}
expr ${shadowsocksport} + 1 &>/dev/null
if [ $? -eq 0 ]; then
if [ ${shadowsocksport} -ge 1 ] && [ ${shadowsocksport} -le 65535 ] && [ $
{shadowsocksport:0:1} != 0 ]; then
echo
echo "---------------------------"
echo "port = ${shadowsocksport}"
echo "---------------------------"
echo
break
fi
fi
echo -e "[${red}Error${plain}] Please enter a correct number [1-65535]"
done

# Set shadowsocks config stream ciphers


while true
do
echo -e "Please select stream cipher for shadowsocks-python:"
for ((i=1;i<=${#ciphers[@]};i++ )); do
hint="${ciphers[$i-1]}"
echo -e "${green}${i}${plain}) ${hint}"
done
read -p "Which cipher you'd select(Default: ${ciphers[0]}):" pick
[ -z "$pick" ] && pick=1
expr ${pick} + 1 &>/dev/null
if [ $? -ne 0 ]; then
echo -e "[${red}Error${plain}] Please enter a number"
continue
fi
if [[ "$pick" -lt 1 || "$pick" -gt ${#ciphers[@]} ]]; then
echo -e "[${red}Error${plain}] Please enter a number between 1 and $
{#ciphers[@]}"
continue
fi
shadowsockscipher=${ciphers[$pick-1]}
echo
echo "---------------------------"
echo "cipher = ${shadowsockscipher}"
echo "---------------------------"
echo
break
done

echo
echo "Press any key to start...or Press Ctrl+C to cancel"
char=`get_char`
# Install necessary dependencies
if check_sys packageManager yum; then
yum install -y python python-devel python-setuptools openssl openssl-devel
curl wget unzip gcc automake autoconf make libtool
elif check_sys packageManager apt; then
apt-get -y update
apt-get -y install python python-dev python-setuptools openssl libssl-dev
curl wget unzip gcc automake autoconf make libtool
fi
cd ${cur_dir}
}

# Download files
download_files(){
# Download libsodium file
if ! wget --no-check-certificate -O ${libsodium_file}.[Link] ${libsodium_url};
then
echo -e "[${red}Error${plain}] Failed to download $
{libsodium_file}.[Link]!"
exit 1
fi
# Download Shadowsocks file
if ! wget --no-check-certificate -O [Link]
[Link] then
echo -e "[${red}Error${plain}] Failed to download shadowsocks python file!"
exit 1
fi
# Download Shadowsocks init script
if check_sys packageManager yum; then
if ! wget --no-check-certificate
[Link] -
O /etc/init.d/shadowsocks; then
echo -e "[${red}Error${plain}] Failed to download shadowsocks chkconfig
file!"
exit 1
fi
elif check_sys packageManager apt; then
if ! wget --no-check-certificate
[Link]
debian -O /etc/init.d/shadowsocks; then
echo -e "[${red}Error${plain}] Failed to download shadowsocks chkconfig
file!"
exit 1
fi
fi
}

# Config shadowsocks
config_shadowsocks(){
cat > /etc/[Link]<<-EOF
{
"server":"[Link]",
"server_port":${shadowsocksport},
"local_address":"[Link]",
"local_port":1080,
"password":"${shadowsockspwd}",
"timeout":300,
"method":"${shadowsockscipher}",
"fast_open":false
}
EOF
}

# Firewall set
firewall_set(){
echo -e "[${green}Info${plain}] firewall set start..."
if centosversion 6; then
/etc/init.d/iptables status > /dev/null 2>&1
if [ $? -eq 0 ]; then
iptables -L -n | grep -i ${shadowsocksport} > /dev/null 2>&1
if [ $? -ne 0 ]; then
iptables -I INPUT -m state --state NEW -m tcp -p tcp --dport $
{shadowsocksport} -j ACCEPT
iptables -I INPUT -m state --state NEW -m udp -p udp --dport $
{shadowsocksport} -j ACCEPT
/etc/init.d/iptables save
/etc/init.d/iptables restart
else
echo -e "[${green}Info${plain}] port ${shadowsocksport} has already
been set up."
fi
else
echo -e "[${yellow}Warning${plain}] iptables looks like shutdown or not
installed, please manually set it if necessary."
fi
elif centosversion 7; then
systemctl status firewalld > /dev/null 2>&1
if [ $? -eq 0 ]; then
firewall-cmd --permanent --zone=public
--add-port=${shadowsocksport}/tcp
firewall-cmd --permanent --zone=public
--add-port=${shadowsocksport}/udp
firewall-cmd --reload
else
echo -e "[${yellow}Warning${plain}] firewalld looks like not running or
not installed, please enable port ${shadowsocksport} manually if necessary."
fi
fi
echo -e "[${green}Info${plain}] firewall set completed..."
}

# Install Shadowsocks
install(){
# Install libsodium
if [ ! -f /usr/lib/libsodium.a ]; then
cd ${cur_dir}
tar zxf ${libsodium_file}.[Link]
cd ${libsodium_file}
./configure --prefix=/usr && make && make install
if [ $? -ne 0 ]; then
echo -e "[${red}Error${plain}] libsodium install failed!"
install_cleanup
exit 1
fi
fi

ldconfig
# Install Shadowsocks
cd ${cur_dir}
unzip -q [Link]
if [ $? -ne 0 ];then
echo -e "[${red}Error${plain}] unzip [Link] failed! please
check unzip command."
install_cleanup
exit 1
fi

cd ${cur_dir}/shadowsocks-master
python [Link] install --record /usr/local/shadowsocks_install.log

if [ -f /usr/bin/ssserver ] || [ -f /usr/local/bin/ssserver ]; then


chmod +x /etc/init.d/shadowsocks
if check_sys packageManager yum; then
chkconfig --add shadowsocks
chkconfig shadowsocks on
elif check_sys packageManager apt; then
update-rc.d -f shadowsocks defaults
fi
/etc/init.d/shadowsocks start
else
echo
echo -e "[${red}Error${plain}] Shadowsocks install failed! please visit
[Link] and contact."
install_cleanup
exit 1
fi

clear
echo
echo -e "Congratulations, Shadowsocks-python server install completed!"
echo -e "Your Server IP : \033[41;37m $(get_ip) \033[0m"
echo -e "Your Server Port : \033[41;37m ${shadowsocksport} \033[0m"
echo -e "Your Password : \033[41;37m ${shadowsockspwd} \033[0m"
echo -e "Your Encryption Method: \033[41;37m ${shadowsockscipher} \033[0m"
echo
echo "Welcome to visit:[Link]
echo "Enjoy it!"
echo
}

# Install cleanup
install_cleanup(){
cd ${cur_dir}
rm -rf [Link] shadowsocks-master ${libsodium_file}.[Link] $
{libsodium_file}
}

# Uninstall Shadowsocks
uninstall_shadowsocks(){
printf "Are you sure uninstall Shadowsocks? (y/n) "
printf "\n"
read -p "(Default: n):" answer
[ -z ${answer} ] && answer="n"
if [ "${answer}" == "y" ] || [ "${answer}" == "Y" ]; then
ps -ef | grep -v grep | grep -i "ssserver" > /dev/null 2>&1
if [ $? -eq 0 ]; then
/etc/init.d/shadowsocks stop
fi
if check_sys packageManager yum; then
chkconfig --del shadowsocks
elif check_sys packageManager apt; then
update-rc.d -f shadowsocks remove
fi
# delete config file
rm -f /etc/[Link]
rm -f /var/run/[Link]
rm -f /etc/init.d/shadowsocks
rm -f /var/log/[Link]
if [ -f /usr/local/shadowsocks_install.log ]; then
cat /usr/local/shadowsocks_install.log | xargs rm -rf
fi
echo "Shadowsocks uninstall success!"
else
echo
echo "uninstall cancelled, nothing to do..."
echo
fi
}

# Install Shadowsocks-python
install_shadowsocks(){
disable_selinux
pre_install
download_files
config_shadowsocks
if check_sys packageManager yum; then
firewall_set
fi
install
install_cleanup
}

# Initialization step
action=$1
[ -z $1 ] && action=install
case "$action" in
install|uninstall)
${action}_shadowsocks
;;
*)
echo "Arguments error! [${action}]"
echo "Usage: `basename $0` [install|uninstall]"
;;
esac

Common questions

Powered by AI

The installation process of shadowsocks-python on a supported Linux distribution involves several key steps: 1) Ensuring the script runs as root and disabling SELinux if necessary . 2) Checking the system and determining if the OS is CentOS, Debian, or Ubuntu, each requiring specific actions . 3) Pre-installation setup that involves determining the appropriate package manager (yum or apt) and setting a password and port for the shadowsocks server . 4) Downloading necessary files and dependencies, such as libsodium and the shadowsocks source code . 5) Configuring the shadowsocks JSON configuration file, which includes server, port, local address, password, and encryption method settings . 6) Adjusting firewall settings based on the CentOS version to allow traffic on the designated port . 7) Compiling and installing the necessary software, enabling the Shadowsocks service, and verifying successful setup .

For CentOS 6, the script checks if 'iptables' is actively running, and if so, it adds rules to allow incoming TCP and UDP traffic on the designated Shadowsocks port, thereafter saving and restarting 'iptables' to apply the changes . On CentOS 7, it verifies if 'firewalld' is active and uses 'firewall-cmd' to permanently allow the port for both TCP and UDP through the public zone, then reloads the firewall to apply changes .

The compatibility check is executed by determining the system's OS and package manager. The script first checks for CentOS via '/etc/redhat-release' and uses 'yum' as the package manager if found. If it detects Debian or Ubuntu through checking '/etc/issue' or '/proc/version', it uses 'apt' for package management. This ensures the script runs the appropriate installation commands specific to each distribution .

The script identifies the package manager based on the system's OS. For CentOS, it recognizes 'yum' as the package manager and uses it to install dependencies such as 'python', 'openssl', and development libraries. For Debian or Ubuntu systems, it uses 'apt-get' to update repositories and install similar dependencies suited to those environments . This ensures that the required libraries and tools are appropriately installed based on the system’s package management framework.

The script installs necessary libraries like 'libsodium' by downloading its source, extracting, configuring, and compiling it. It then installs Shadowsocks by extracting the downloaded source zip file, running 'python setup.py install', and verifying the presence of the 'ssserver' executable in specific directories. Successful installation is indicated by no error returns from these commands and through confirming executable permissions .

The script performs IP filtering to exclude private and non-routable IP addresses (such as those starting with '192.168', '172.', '10.', '127.', '255.', or '0.'). It identifies the public IP using system network interfaces or online services. This filtering is crucial for accurately configuring Shadowsocks to serve over the correct external IP, ensuring accessibility and functionality over the internet .

During the installation, the user is prompted to select a stream cipher from a predefined list. The list includes ciphers such as 'aes-256-gcm', 'aes-192-ctr', and 'chacha20', among others. The user selects a cipher by entering an index number corresponding to the available options. This selection is crucial because the cipher determines the encryption method for data transferred through the Shadowsocks server, impacting security and performance .

The script uses service management tools appropriate to the system. For systems using 'yum', it adds Shadowsocks to 'chkconfig' to enable it at boot, using the command 'chkconfig shadowsocks on'. For systems with 'apt', it uses 'update-rc.d' to set Shadowsocks to start at default run levels. These steps ensure Shadowsocks is automatically managed and started when the system boots .

To uninstall Shadowsocks, the user is prompted to confirm by entering 'y'. The script then stops the Shadowsocks service, removes it from service management by deleting from 'chkconfig' or 'update-rc.d', and deletes the Shadowsocks configuration files, logs, and PID files. This thorough removal ensures all traces of the software are eradicated from the system .

SELinux is disabled in the script to avoid any security restrictions that might interfere with Shadowsocks's operations. The script alters SELinux from 'enforcing' to 'disabled' in the '/etc/selinux/config' file and temporarily sets its mode to permissive using 'setenforce 0'. This step is vital in ensuring smooth installation and execution of the server without SELinux policies blocking necessary network activities .

You might also like