1import{_ as l,o as a,c as s,j as t,a as o,aj as r}from"./chunks/framework.BASLC-SQ.js";const _=JSON.parse('{"title":"What is Shadowsocks?","description":"","frontmatter":{},"headers":[],"relativePath":"doc/what-is-shadowsocks.md","filePath":"doc/what-is-shadowsocks.md","lastUpdated":1783819531000}'),n={name:"doc/what-is-shadowsocks.md"},i={xmlns:"http://www.w3.org/2000/svg",viewBox:"0 0 720 70",style:{display:"block",margin:"1em auto",width:"100%",height:"auto","max-width":"720px"},role:"img","aria-label":"Shadowsocks data flow: client to ss-local to ss-remote to target, with encrypted link between ss-local and ss-remote"},d={xmlns:"http://www.w3.org/2000/svg",viewBox:"0 0 540 60",style:{display:"block",margin:"1em auto",width:"100%",height:"auto","max-width":"540px"},role:"img","aria-label":"SOCKS5 address format: 1-byte type, variable-length host, 2-byte port"},h={xmlns:"http://www.w3.org/2000/svg",viewBox:"0 0 480 40",style:{display:"block",margin:"1em auto",width:"100%",height:"auto","max-width":"480px"},role:"img","aria-label":"TCP stream payload format: target address followed by payload"},p={xmlns:"http://www.w3.org/2000/svg",viewBox:"0 0 480 40",style:{display:"block",margin:"1em auto",width:"100%",height:"auto","max-width":"480px"},role:"img","aria-label":"UDP packet payload format: target address followed by payload"},x={xmlns:"http://www.w3.org/2000/svg",viewBox:"0 0 480 40",style:{display:"block",margin:"1em auto",width:"100%",height:"auto","max-width":"480px"},role:"img","aria-label":"UDP reply packet format: target address followed by payload"};function y(c,e,g,m,w,f){return a(),s("div",null,[e[5]||(e[5]=t("h1",{id:"what-is-shadowsocks",tabindex:"-1"},[o("What is Shadowsocks? "),t("a",{class:"header-anchor",href:"#what-is-shadowsocks","aria-label":'Permalink to "What is Shadowsocks?"'},"â")],-1)),e[6]||(e[6]=t("p",null,[o("Shadowsocks is a secure split proxy loosely based on "),t("a",{href:"https://tools.ietf.org/html/rfc1928",target:"_blank",rel:"noreferrer"},"SOCKS5"),o(".")],-1)),(a(),s("svg",i,[...e[0]||(e[0]=[r("",3)])])),e[7]||(e[7]=t("p",null,"The Shadowsocks local component (ss-local) acts like a traditional SOCKS5 server and provides proxy service to clients. It encrypts and forwards data streams and packets from the client to the Shadowsocks remote component (ss-remote), which decrypts and forwards to the target. Replies from target are similarly encrypted and relayed by ss-remote back to ss-local, which decrypts and eventually returns to the original client.",-1)),e[8]||(e[8]=t("h2",{id:"addressing",tabindex:"-1"},[o("Addressing "),t("a",{class:"header-anchor",href:"#addressing","aria-label":'Permalink to "Addressing"'},"â")],-1)),e[9]||(e[9]=t("p",null,[o("Addresses used in Shadowsocks follow the "),t("a",{href:"https://tools.ietf.org/html/rfc1928#section-5",target:"_blank",rel:"noreferrer"},"SOCKS5 address format"),o(":")],-1)),(a(),s("svg",d,[...e[1]||(e[1]=[r("",2)])])),e[10]||(e[10]=r("",5)),(a(),s("svg",h,[...e[2]||(e[2]=[r("",2)])])),e[11]||(e[11]=t("p",null,"ss-remote receives the encrypted data stream, decrypts and parses the leading target address. It then establishes a new TCP connection to the target and forwards payload data to it. ss-remote receives reply from the target, encrypts and forwards it back to the ss-local, until ss-local disconnects.",-1)),e[12]||(e[12]=t("p",null,"For better obfuscation purposes, both local and remote SHOULD send the handshake data along with some payload in the first packet.",-1)),e[13]||(e[13]=t("h2",{id:"udp",tabindex:"-1"},[o("UDP "),t("a",{class:"header-anchor",href:"#udp","aria-label":'Permalink to "UDP"'},"â")],-1)),e[14]||(e[14]=t("p",null,"ss-local sends an encrypted data packet containing the target address and payload to ss-remote.",-1)),(a(),s("svg",p,[...e[3]||(e[3]=[r("",2)])])),e[15]||(e[15]=t("p",null,"Upon receiving the encrypted packet, ss-remote decrypts and parses the target address. It then sends a new data packet containing only the payload to the target. ss-remote receives data packets back from target and prepends the target address to the payload in each packet, then sends encrypted copies back to ss-local.",-1)),(a(),s("svg",x,[...e[4]||(e[4]=[r("",2)])])),e[16]||(e[16]=t("p",null,"Essentially, ss-remote is performing Network Address Translation for ss-local.",-1))])}const k=l(n,[["render",y]]);export{_ as __pageData,k as default};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.