12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184 |
- #!/bin/bash
- red='\033[0;31m'
- green='\033[0;32m'
- yellow='\033[0;33m'
- plain='\033[0m'
- #Add some basic function here
- function LOGD() {
- echo -e "${yellow}[DEG] $* ${plain}"
- }
- function LOGE() {
- echo -e "${red}[ERR] $* ${plain}"
- }
- function LOGI() {
- echo -e "${green}[INF] $* ${plain}"
- }
- # check root
- [[ $EUID -ne 0 ]] && LOGE "ERROR: You must be root to run this script! \n" && exit 1
- # Check OS and set release variable
- if [[ -f /etc/os-release ]]; then
- source /etc/os-release
- release=$ID
- elif [[ -f /usr/lib/os-release ]]; then
- source /usr/lib/os-release
- release=$ID
- else
- echo "Failed to check the system OS, please contact the author!" >&2
- exit 1
- fi
- echo "The OS release is: $release"
- os_version=""
- os_version=$(grep -i version_id /etc/os-release | cut -d \" -f2 | cut -d . -f1)
- if [[ "${release}" == "centos" ]]; then
- if [[ ${os_version} -lt 8 ]]; then
- echo -e "${red} Please use CentOS 8 or higher ${plain}\n" && exit 1
- fi
- elif [[ "${release}" == "ubuntu" ]]; then
- if [[ ${os_version} -lt 20 ]]; then
- echo -e "${red}please use Ubuntu 20 or higher version! ${plain}\n" && exit 1
- fi
- elif [[ "${release}" == "fedora" ]]; then
- if [[ ${os_version} -lt 36 ]]; then
- echo -e "${red}please use Fedora 36 or higher version! ${plain}\n" && exit 1
- fi
- elif [[ "${release}" == "debian" ]]; then
- if [[ ${os_version} -lt 10 ]]; then
- echo -e "${red} Please use Debian 10 or higher ${plain}\n" && exit 1
- fi
- elif [[ "${release}" == "arch" ]]; then
- echo "Your OS is ArchLinux"
- elif [[ "${release}" == "manjaro" ]]; then
- echo "Your OS is Manjaro"
- elif [[ "${release}" == "armbian" ]]; then
- echo "Your OS is Armbian"
- fi
- # Declare Variables
- log_folder="${XUI_LOG_FOLDER:=/var/log}"
- iplimit_log_path="${log_folder}/3xipl.log"
- iplimit_banned_log_path="${log_folder}/3xipl-banned.log"
- confirm() {
- if [[ $# > 1 ]]; then
- echo && read -p "$1 [Default $2]: " temp
- if [[ "${temp}" == "" ]]; then
- temp=$2
- fi
- else
- read -p "$1 [y/n]: " temp
- fi
- if [[ "${temp}" == "y" || "${temp}" == "Y" ]]; then
- return 0
- else
- return 1
- fi
- }
- confirm_restart() {
- confirm "Restart the panel, Attention: Restarting the panel will also restart xray" "y"
- if [[ $? == 0 ]]; then
- restart
- else
- show_menu
- fi
- }
- before_show_menu() {
- echo && echo -n -e "${yellow}Press enter to return to the main menu: ${plain}" && read temp
- show_menu
- }
- install() {
- bash <(curl -Ls https://raw.githubusercontent.com/MHSanaei/3x-ui/main/install.sh)
- if [[ $? == 0 ]]; then
- if [[ $# == 0 ]]; then
- start
- else
- start 0
- fi
- fi
- }
- update() {
- confirm "This function will forcefully reinstall the latest version, and the data will not be lost. Do you want to continue?" "n"
- if [[ $? != 0 ]]; then
- LOGE "Cancelled"
- if [[ $# == 0 ]]; then
- before_show_menu
- fi
- return 0
- fi
- bash <(curl -Ls https://raw.githubusercontent.com/MHSanaei/3x-ui/main/install.sh)
- if [[ $? == 0 ]]; then
- LOGI "Update is complete, Panel has automatically restarted "
- exit 0
- fi
- }
- uninstall() {
- confirm "Are you sure you want to uninstall the panel? xray will also uninstalled!" "n"
- if [[ $? != 0 ]]; then
- if [[ $# == 0 ]]; then
- show_menu
- fi
- return 0
- fi
- systemctl stop x-ui
- systemctl disable x-ui
- rm /etc/systemd/system/x-ui.service -f
- systemctl daemon-reload
- systemctl reset-failed
- rm /etc/x-ui/ -rf
- rm /usr/local/x-ui/ -rf
- echo ""
- echo -e "Uninstalled Successfully, If you want to remove this script, then after exiting the script run ${green}rm /usr/bin/x-ui -f${plain} to delete it."
- echo ""
- if [[ $# == 0 ]]; then
- before_show_menu
- fi
- }
- reset_user() {
- confirm "Are you sure to reset the username and password of the panel?" "n"
- if [[ $? != 0 ]]; then
- if [[ $# == 0 ]]; then
- show_menu
- fi
- return 0
- fi
- read -rp "Please set the login username [default is a random username]: " config_account
- [[ -z $config_account ]] && config_account=$(date +%s%N | md5sum | cut -c 1-8)
- read -rp "Please set the login password [default is a random password]: " config_password
- [[ -z $config_password ]] && config_password=$(date +%s%N | md5sum | cut -c 1-8)
- /usr/local/x-ui/x-ui setting -username ${config_account} -password ${config_password} >/dev/null 2>&1
- /usr/local/x-ui/x-ui setting -remove_secret >/dev/null 2>&1
- echo -e "Panel login username has been reset to: ${green} ${config_account} ${plain}"
- echo -e "Panel login password has been reset to: ${green} ${config_password} ${plain}"
- echo -e "${yellow} Panel login secret token disabled ${plain}"
- echo -e "${green} Please use the new login username and password to access the X-UI panel. Also remember them! ${plain}"
- confirm_restart
- }
- reset_config() {
- confirm "Are you sure you want to reset all panel settings, Account data will not be lost, Username and password will not change" "n"
- if [[ $? != 0 ]]; then
- if [[ $# == 0 ]]; then
- show_menu
- fi
- return 0
- fi
- /usr/local/x-ui/x-ui setting -reset
- echo -e "All panel settings have been reset to default, Please restart the panel now, and use the default ${green}2053${plain} Port to Access the web Panel"
- confirm_restart
- }
- check_config() {
- info=$(/usr/local/x-ui/x-ui setting -show true)
- if [[ $? != 0 ]]; then
- LOGE "get current settings error, please check logs"
- show_menu
- fi
- LOGI "${info}"
- }
- set_port() {
- echo && echo -n -e "Enter port number[1-65535]: " && read port
- if [[ -z "${port}" ]]; then
- LOGD "Cancelled"
- before_show_menu
- else
- /usr/local/x-ui/x-ui setting -port ${port}
- echo -e "The port is set, Please restart the panel now, and use the new port ${green}${port}${plain} to access web panel"
- confirm_restart
- fi
- }
- start() {
- check_status
- if [[ $? == 0 ]]; then
- echo ""
- LOGI "Panel is running, No need to start again, If you need to restart, please select restart"
- else
- systemctl start x-ui
- sleep 2
- check_status
- if [[ $? == 0 ]]; then
- LOGI "x-ui Started Successfully"
- else
- LOGE "panel Failed to start, Probably because it takes longer than two seconds to start, Please check the log information later"
- fi
- fi
- if [[ $# == 0 ]]; then
- before_show_menu
- fi
- }
- stop() {
- check_status
- if [[ $? == 1 ]]; then
- echo ""
- LOGI "Panel stopped, No need to stop again!"
- else
- systemctl stop x-ui
- sleep 2
- check_status
- if [[ $? == 1 ]]; then
- LOGI "x-ui and xray stopped successfully"
- else
- LOGE "Panel stop failed, Probably because the stop time exceeds two seconds, Please check the log information later"
- fi
- fi
- if [[ $# == 0 ]]; then
- before_show_menu
- fi
- }
- restart() {
- systemctl restart x-ui
- sleep 2
- check_status
- if [[ $? == 0 ]]; then
- LOGI "x-ui and xray Restarted successfully"
- else
- LOGE "Panel restart failed, Probably because it takes longer than two seconds to start, Please check the log information later"
- fi
- if [[ $# == 0 ]]; then
- before_show_menu
- fi
- }
- status() {
- systemctl status x-ui -l
- if [[ $# == 0 ]]; then
- before_show_menu
- fi
- }
- enable() {
- systemctl enable x-ui
- if [[ $? == 0 ]]; then
- LOGI "x-ui Set to boot automatically on startup successfully"
- else
- LOGE "x-ui Failed to set Autostart"
- fi
- if [[ $# == 0 ]]; then
- before_show_menu
- fi
- }
- disable() {
- systemctl disable x-ui
- if [[ $? == 0 ]]; then
- LOGI "x-ui Autostart Cancelled successfully"
- else
- LOGE "x-ui Failed to cancel autostart"
- fi
- if [[ $# == 0 ]]; then
- before_show_menu
- fi
- }
- show_log() {
- journalctl -u x-ui.service -e --no-pager -f
- if [[ $# == 0 ]]; then
- before_show_menu
- fi
- }
- show_banlog() {
- if test -f "${iplimit_banned_log_path}"; then
- if [[ -s "${iplimit_banned_log_path}" ]]; then
- cat ${iplimit_banned_log_path}
- else
- echo -e "${red}Log file is empty.${plain}\n"
- fi
- else
- echo -e "${red}Log file not found. Please Install Fail2ban and IP Limit first.${plain}\n"
- fi
- }
- enable_bbr() {
- if grep -q "net.core.default_qdisc=fq" /etc/sysctl.conf && grep -q "net.ipv4.tcp_congestion_control=bbr" /etc/sysctl.conf; then
- echo -e "${green}BBR is already enabled!${plain}"
- exit 0
- fi
- # Check the OS and install necessary packages
- case "${release}" in
- ubuntu|debian)
- apt-get update && apt-get install -yqq --no-install-recommends ca-certificates
- ;;
- centos)
- yum -y update && yum -y install ca-certificates
- ;;
- fedora)
- dnf -y update && dnf -y install ca-certificates
- ;;
- *)
- echo -e "${red}Unsupported operating system. Please check the script and install the necessary packages manually.${plain}\n"
- exit 1
- ;;
- esac
- # Enable BBR
- echo "net.core.default_qdisc=fq" | tee -a /etc/sysctl.conf
- echo "net.ipv4.tcp_congestion_control=bbr" | tee -a /etc/sysctl.conf
- # Apply changes
- sysctl -p
- # Verify that BBR is enabled
- if [[ $(sysctl net.ipv4.tcp_congestion_control | awk '{print $3}') == "bbr" ]]; then
- echo -e "${green}BBR has been enabled successfully.${plain}"
- else
- echo -e "${red}Failed to enable BBR. Please check your system configuration.${plain}"
- fi
- }
- update_shell() {
- wget -O /usr/bin/x-ui -N --no-check-certificate https://github.com/MHSanaei/3x-ui/raw/main/x-ui.sh
- if [[ $? != 0 ]]; then
- echo ""
- LOGE "Failed to download script, Please check whether the machine can connect Github"
- before_show_menu
- else
- chmod +x /usr/bin/x-ui
- LOGI "Upgrade script succeeded, Please rerun the script" && exit 0
- fi
- }
- # 0: running, 1: not running, 2: not installed
- check_status() {
- if [[ ! -f /etc/systemd/system/x-ui.service ]]; then
- return 2
- fi
- temp=$(systemctl status x-ui | grep Active | awk '{print $3}' | cut -d "(" -f2 | cut -d ")" -f1)
- if [[ "${temp}" == "running" ]]; then
- return 0
- else
- return 1
- fi
- }
- check_enabled() {
- temp=$(systemctl is-enabled x-ui)
- if [[ "${temp}" == "enabled" ]]; then
- return 0
- else
- return 1
- fi
- }
- check_uninstall() {
- check_status
- if [[ $? != 2 ]]; then
- echo ""
- LOGE "Panel installed, Please do not reinstall"
- if [[ $# == 0 ]]; then
- before_show_menu
- fi
- return 1
- else
- return 0
- fi
- }
- check_install() {
- check_status
- if [[ $? == 2 ]]; then
- echo ""
- LOGE "Please install the panel first"
- if [[ $# == 0 ]]; then
- before_show_menu
- fi
- return 1
- else
- return 0
- fi
- }
- show_status() {
- check_status
- case $? in
- 0)
- echo -e "Panel state: ${green}Running${plain}"
- show_enable_status
- ;;
- 1)
- echo -e "Panel state: ${yellow}Not Running${plain}"
- show_enable_status
- ;;
- 2)
- echo -e "Panel state: ${red}Not Installed${plain}"
- ;;
- esac
- show_xray_status
- }
- show_enable_status() {
- check_enabled
- if [[ $? == 0 ]]; then
- echo -e "Start automatically: ${green}Yes${plain}"
- else
- echo -e "Start automatically: ${red}No${plain}"
- fi
- }
- check_xray_status() {
- count=$(ps -ef | grep "xray-linux" | grep -v "grep" | wc -l)
- if [[ count -ne 0 ]]; then
- return 0
- else
- return 1
- fi
- }
- show_xray_status() {
- check_xray_status
- if [[ $? == 0 ]]; then
- echo -e "xray state: ${green}Running${plain}"
- else
- echo -e "xray state: ${red}Not Running${plain}"
- fi
- }
- open_ports() {
- if ! command -v ufw &>/dev/null; then
- echo "ufw firewall is not installed. Installing now..."
- apt-get update
- apt-get install -y ufw
- else
- echo "ufw firewall is already installed"
- fi
- # Check if the firewall is inactive
- if ufw status | grep -q "Status: active"; then
- echo "firewall is already active"
- else
- # Open the necessary ports
- ufw allow ssh
- ufw allow http
- ufw allow https
- ufw allow 2053/tcp
- # Enable the firewall
- ufw --force enable
- fi
- # Prompt the user to enter a list of ports
- read -p "Enter the ports you want to open (e.g. 80,443,2053 or range 400-500): " ports
- # Check if the input is valid
- if ! [[ $ports =~ ^([0-9]+|[0-9]+-[0-9]+)(,([0-9]+|[0-9]+-[0-9]+))*$ ]]; then
- echo "Error: Invalid input. Please enter a comma-separated list of ports or a range of ports (e.g. 80,443,2053 or 400-500)." >&2
- exit 1
- fi
- # Open the specified ports using ufw
- IFS=',' read -ra PORT_LIST <<<"$ports"
- for port in "${PORT_LIST[@]}"; do
- if [[ $port == *-* ]]; then
- # Split the range into start and end ports
- start_port=$(echo $port | cut -d'-' -f1)
- end_port=$(echo $port | cut -d'-' -f2)
- # Loop through the range and open each port
- for ((i = start_port; i <= end_port; i++)); do
- ufw allow $i
- done
- else
- ufw allow "$port"
- fi
- done
- # Confirm that the ports are open
- ufw status | grep $ports
- }
- update_geo() {
- local defaultBinFolder="/usr/local/x-ui/bin"
- read -p "Please enter x-ui bin folder path. Leave blank for default. (Default: '${defaultBinFolder}')" binFolder
- binFolder=${binFolder:-${defaultBinFolder}}
- if [[ ! -d ${binFolder} ]]; then
- LOGE "Folder ${binFolder} not exists!"
- LOGI "making bin folder: ${binFolder}..."
- mkdir -p ${binFolder}
- fi
- systemctl stop x-ui
- cd ${binFolder}
- rm -f geoip.dat geosite.dat geoip_IR.dat geosite_IR.dat geoip_VN.dat geosite_VN.dat
- wget -N https://github.com/Loyalsoldier/v2ray-rules-dat/releases/latest/download/geoip.dat
- wget -N https://github.com/Loyalsoldier/v2ray-rules-dat/releases/latest/download/geosite.dat
- wget -O geoip_IR.dat -N https://github.com/chocolate4u/Iran-v2ray-rules/releases/latest/download/geoip.dat
- wget -O geosite_IR.dat -N https://github.com/chocolate4u/Iran-v2ray-rules/releases/latest/download/geosite.dat
- wget -O geoip_VN.dat https://github.com/vuong2023/vn-v2ray-rules/releases/latest/download/geoip.dat
- wget -O geosite_VN.dat https://github.com/vuong2023/vn-v2ray-rules/releases/latest/download/geosite.dat
- systemctl start x-ui
- echo -e "${green}Geosite.dat + Geoip.dat + geoip_IR.dat + geosite_IR.dat have been updated successfully in bin folder '${binfolder}'!${plain}"
- before_show_menu
- }
- install_acme() {
- cd ~
- LOGI "install acme..."
- curl https://get.acme.sh | sh
- if [ $? -ne 0 ]; then
- LOGE "install acme failed"
- return 1
- else
- LOGI "install acme succeed"
- fi
- return 0
- }
- ssl_cert_issue_main() {
- echo -e "${green}\t1.${plain} Get SSL"
- echo -e "${green}\t2.${plain} Revoke"
- echo -e "${green}\t3.${plain} Force Renew"
- echo -e "${green}\t0.${plain} Back to Main Menu"
- read -p "Choose an option: " choice
- case "$choice" in
- 0)
- show_menu ;;
- 1)
- ssl_cert_issue ;;
- 2)
- local domain=""
- read -p "Please enter your domain name to revoke the certificate: " domain
- ~/.acme.sh/acme.sh --revoke -d ${domain}
- LOGI "Certificate revoked"
- ;;
- 3)
- local domain=""
- read -p "Please enter your domain name to forcefully renew an SSL certificate: " domain
- ~/.acme.sh/acme.sh --renew -d ${domain} --force ;;
- *) echo "Invalid choice" ;;
- esac
- }
- ssl_cert_issue() {
- # check for acme.sh first
- if ! command -v ~/.acme.sh/acme.sh &>/dev/null; then
- echo "acme.sh could not be found. we will install it"
- install_acme
- if [ $? -ne 0 ]; then
- LOGE "install acme failed, please check logs"
- exit 1
- fi
- fi
- # install socat second
- case "${release}" in
- ubuntu|debian|armbian)
- apt update && apt install socat -y ;;
- centos)
- yum -y update && yum -y install socat ;;
- fedora)
- dnf -y update && dnf -y install socat ;;
- *)
- echo -e "${red}Unsupported operating system. Please check the script and install the necessary packages manually.${plain}\n"
- exit 1 ;;
- esac
- if [ $? -ne 0 ]; then
- LOGE "install socat failed, please check logs"
- exit 1
- else
- LOGI "install socat succeed..."
- fi
- # get the domain here,and we need verify it
- local domain=""
- read -p "Please enter your domain name:" domain
- LOGD "your domain is:${domain},check it..."
- # here we need to judge whether there exists cert already
- local currentCert=$(~/.acme.sh/acme.sh --list | tail -1 | awk '{print $1}')
- if [ ${currentCert} == ${domain} ]; then
- local certInfo=$(~/.acme.sh/acme.sh --list)
- LOGE "system already has certs here,can not issue again,current certs details:"
- LOGI "$certInfo"
- exit 1
- else
- LOGI "your domain is ready for issuing cert now..."
- fi
- # create a directory for install cert
- certPath="/root/cert/${domain}"
- if [ ! -d "$certPath" ]; then
- mkdir -p "$certPath"
- else
- rm -rf "$certPath"
- mkdir -p "$certPath"
- fi
- # get needed port here
- local WebPort=80
- read -p "please choose which port do you use,default will be 80 port:" WebPort
- if [[ ${WebPort} -gt 65535 || ${WebPort} -lt 1 ]]; then
- LOGE "your input ${WebPort} is invalid,will use default port"
- fi
- LOGI "will use port:${WebPort} to issue certs,please make sure this port is open..."
- # NOTE:This should be handled by user
- # open the port and kill the occupied progress
- ~/.acme.sh/acme.sh --set-default-ca --server letsencrypt
- ~/.acme.sh/acme.sh --issue -d ${domain} --standalone --httpport ${WebPort}
- if [ $? -ne 0 ]; then
- LOGE "issue certs failed,please check logs"
- rm -rf ~/.acme.sh/${domain}
- exit 1
- else
- LOGE "issue certs succeed,installing certs..."
- fi
- # install cert
- ~/.acme.sh/acme.sh --installcert -d ${domain} \
- --key-file /root/cert/${domain}/privkey.pem \
- --fullchain-file /root/cert/${domain}/fullchain.pem
- if [ $? -ne 0 ]; then
- LOGE "install certs failed,exit"
- rm -rf ~/.acme.sh/${domain}
- exit 1
- else
- LOGI "install certs succeed,enable auto renew..."
- fi
- ~/.acme.sh/acme.sh --upgrade --auto-upgrade
- if [ $? -ne 0 ]; then
- LOGE "auto renew failed, certs details:"
- ls -lah cert/*
- chmod 755 $certPath/*
- exit 1
- else
- LOGI "auto renew succeed, certs details:"
- ls -lah cert/*
- chmod 755 $certPath/*
- fi
- }
- ssl_cert_issue_CF() {
- echo -E ""
- LOGD "******Instructions for use******"
- LOGI "This Acme script requires the following data:"
- LOGI "1.Cloudflare Registered e-mail"
- LOGI "2.Cloudflare Global API Key"
- LOGI "3.The domain name that has been resolved dns to the current server by Cloudflare"
- LOGI "4.The script applies for a certificate. The default installation path is /root/cert "
- confirm "Confirmed?[y/n]" "y"
- if [ $? -eq 0 ]; then
- # check for acme.sh first
- if ! command -v ~/.acme.sh/acme.sh &>/dev/null; then
- echo "acme.sh could not be found. we will install it"
- install_acme
- if [ $? -ne 0 ]; then
- LOGE "install acme failed, please check logs"
- exit 1
- fi
- fi
- CF_Domain=""
- CF_GlobalKey=""
- CF_AccountEmail=""
- certPath=/root/cert
- if [ ! -d "$certPath" ]; then
- mkdir $certPath
- else
- rm -rf $certPath
- mkdir $certPath
- fi
- LOGD "Please set a domain name:"
- read -p "Input your domain here:" CF_Domain
- LOGD "Your domain name is set to:${CF_Domain}"
- LOGD "Please set the API key:"
- read -p "Input your key here:" CF_GlobalKey
- LOGD "Your API key is:${CF_GlobalKey}"
- LOGD "Please set up registered email:"
- read -p "Input your email here:" CF_AccountEmail
- LOGD "Your registered email address is:${CF_AccountEmail}"
- ~/.acme.sh/acme.sh --set-default-ca --server letsencrypt
- if [ $? -ne 0 ]; then
- LOGE "Default CA, Lets'Encrypt fail, script exiting..."
- exit 1
- fi
- export CF_Key="${CF_GlobalKey}"
- export CF_Email=${CF_AccountEmail}
- ~/.acme.sh/acme.sh --issue --dns dns_cf -d ${CF_Domain} -d *.${CF_Domain} --log
- if [ $? -ne 0 ]; then
- LOGE "Certificate issuance failed, script exiting..."
- exit 1
- else
- LOGI "Certificate issued Successfully, Installing..."
- fi
- ~/.acme.sh/acme.sh --installcert -d ${CF_Domain} -d *.${CF_Domain} --ca-file /root/cert/ca.cer \
- --cert-file /root/cert/${CF_Domain}.cer --key-file /root/cert/${CF_Domain}.key \
- --fullchain-file /root/cert/fullchain.cer
- if [ $? -ne 0 ]; then
- LOGE "Certificate installation failed, script exiting..."
- exit 1
- else
- LOGI "Certificate installed Successfully,Turning on automatic updates..."
- fi
- ~/.acme.sh/acme.sh --upgrade --auto-upgrade
- if [ $? -ne 0 ]; then
- LOGE "Auto update setup Failed, script exiting..."
- ls -lah cert
- chmod 755 $certPath
- exit 1
- else
- LOGI "The certificate is installed and auto-renewal is turned on, Specific information is as follows"
- ls -lah cert
- chmod 755 $certPath
- fi
- else
- show_menu
- fi
- }
- warp_cloudflare() {
- echo -e "${green}\t1.${plain} Install WARP socks5 proxy"
- echo -e "${green}\t2.${plain} Account Type (free, plus, team)"
- echo -e "${green}\t3.${plain} Turn on/off WireProxy"
- echo -e "${green}\t4.${plain} Uninstall WARP"
- echo -e "${green}\t0.${plain} Back to Main Menu"
- read -p "Choose an option: " choice
- case "$choice" in
- 0)
- show_menu ;;
- 1)
- bash <(curl -sSL https://raw.githubusercontent.com/hamid-gh98/x-ui-scripts/main/install_warp_proxy.sh)
- ;;
- 2)
- warp a
- ;;
- 3)
- warp y
- ;;
- 4)
- warp u
- ;;
- *) echo "Invalid choice" ;;
- esac
- }
- run_speedtest() {
- # Check if Speedtest is already installed
- if ! command -v speedtest &> /dev/null; then
- # If not installed, install it
- local pkg_manager=""
- local speedtest_install_script=""
-
- if command -v dnf &> /dev/null; then
- pkg_manager="dnf"
- speedtest_install_script="https://packagecloud.io/install/repositories/ookla/speedtest-cli/script.rpm.sh"
- elif command -v yum &> /dev/null; then
- pkg_manager="yum"
- speedtest_install_script="https://packagecloud.io/install/repositories/ookla/speedtest-cli/script.rpm.sh"
- elif command -v apt-get &> /dev/null; then
- pkg_manager="apt-get"
- speedtest_install_script="https://packagecloud.io/install/repositories/ookla/speedtest-cli/script.deb.sh"
- elif command -v apt &> /dev/null; then
- pkg_manager="apt"
- speedtest_install_script="https://packagecloud.io/install/repositories/ookla/speedtest-cli/script.deb.sh"
- fi
-
- if [[ -z $pkg_manager ]]; then
- echo "Error: Package manager not found. You may need to install Speedtest manually."
- return 1
- else
- curl -s $speedtest_install_script | bash
- $pkg_manager install -y speedtest
- fi
- fi
- # Run Speedtest
- speedtest
- }
- create_iplimit_jails() {
- # Use default bantime if not passed => 5 minutes
- local bantime="${1:-5}"
- cat << EOF > /etc/fail2ban/jail.d/3x-ipl.conf
- [3x-ipl]
- enabled=true
- filter=3x-ipl
- action=3x-ipl
- logpath=${iplimit_log_path}
- maxretry=4
- findtime=60
- bantime=${bantime}m
- EOF
- cat << EOF > /etc/fail2ban/filter.d/3x-ipl.conf
- [Definition]
- datepattern = ^%%Y/%%m/%%d %%H:%%M:%%S
- failregex = \[LIMIT_IP\]\s*Email\s*=\s*<F-USER>.+</F-USER>\s*\|\|\s*SRC\s*=\s*<ADDR>
- ignoreregex =
- EOF
- cat << EOF > /etc/fail2ban/action.d/3x-ipl.conf
- [INCLUDES]
- before = iptables-common.conf
- [Definition]
- actionstart = <iptables> -N f2b-<name>
- <iptables> -A f2b-<name> -j <returntype>
- <iptables> -I <chain> -p <protocol> -j f2b-<name>
- actionstop = <iptables> -D <chain> -p <protocol> -j f2b-<name>
- <actionflush>
- <iptables> -X f2b-<name>
- actioncheck = <iptables> -n -L <chain> | grep -q 'f2b-<name>[ \t]'
- actionban = <iptables> -I f2b-<name> 1 -s <ip> -j <blocktype>
- echo "\$(date +"%%Y/%%m/%%d %%H:%%M:%%S") BAN [Email] = <F-USER> [IP] = <ip> banned for <bantime> seconds." >> ${iplimit_banned_log_path}
- actionunban = <iptables> -D f2b-<name> -s <ip> -j <blocktype>
- echo "\$(date +"%%Y/%%m/%%d %%H:%%M:%%S") UNBAN [Email] = <F-USER> [IP] = <ip> unbanned." >> ${iplimit_banned_log_path}
- [Init]
- EOF
- echo -e "${green}Created Ip Limit jail files with a bantime of ${bantime} minutes.${plain}"
- }
- iplimit_remove_conflicts() {
- local jail_files=(
- /etc/fail2ban/jail.conf
- /etc/fail2ban/jail.local
- )
- for file in "${jail_files[@]}"; do
- # Check for [3x-ipl] config in jail file then remove it
- if test -f "${file}" && grep -qw '3x-ipl' ${file}; then
- sed -i "/\[3x-ipl\]/,/^$/d" ${file}
- echo -e "${yellow}Removing conflicts of [3x-ipl] in jail (${file})!${plain}\n"
- fi
- done
- }
- iplimit_main() {
- echo -e "\n${green}\t1.${plain} Install Fail2ban and configure IP Limit"
- echo -e "${green}\t2.${plain} Change Ban Duration"
- echo -e "${green}\t3.${plain} Unban Everyone"
- echo -e "${green}\t4.${plain} Check Logs"
- echo -e "${green}\t5.${plain} fail2ban status"
- echo -e "${green}\t6.${plain} Uninstall IP Limit"
- echo -e "${green}\t0.${plain} Back to Main Menu"
- read -p "Choose an option: " choice
- case "$choice" in
- 0)
- show_menu ;;
- 1)
- confirm "Proceed with installation of Fail2ban & IP Limit?" "y"
- if [[ $? == 0 ]]; then
- install_iplimit
- else
- iplimit_main
- fi ;;
- 2)
- read -rp "Please enter new Ban Duration in Minutes [default 5]: " NUM
- if [[ $NUM =~ ^[0-9]+$ ]]; then
- create_iplimit_jails ${NUM}
- systemctl restart fail2ban
- else
- echo -e "${red}${NUM} is not a number! Please, try again.${plain}"
- fi
- iplimit_main ;;
- 3)
- confirm "Proceed with Unbanning everyone from IP Limit jail?" "y"
- if [[ $? == 0 ]]; then
- fail2ban-client reload --restart --unban 3x-ipl
- echo -e "${green}All users Unbanned successfully.${plain}"
- iplimit_main
- else
- echo -e "${yellow}Cancelled.${plain}"
- fi
- iplimit_main ;;
- 4)
- show_banlog
- ;;
- 5)
- service fail2ban status
- ;;
- 6)
- remove_iplimit ;;
- *) echo "Invalid choice" ;;
- esac
- }
- install_iplimit() {
- if ! command -v fail2ban-client &>/dev/null; then
- echo -e "${green}Fail2ban is not installed. Installing now...!${plain}\n"
- # Check the OS and install necessary packages
- case "${release}" in
- ubuntu|debian)
- apt update && apt install fail2ban -y ;;
- centos)
- yum -y update && yum -y install fail2ban ;;
- fedora)
- dnf -y update && dnf -y install fail2ban ;;
- *)
- echo -e "${red}Unsupported operating system. Please check the script and install the necessary packages manually.${plain}\n"
- exit 1 ;;
- esac
- echo -e "${green}Fail2ban installed successfully!${plain}\n"
- else
- echo -e "${yellow}Fail2ban is already installed.${plain}\n"
- fi
- echo -e "${green}Configuring IP Limit...${plain}\n"
- # make sure there's no conflict for jail files
- iplimit_remove_conflicts
- # Check if log file exists
- if ! test -f "${iplimit_banned_log_path}"; then
- touch ${iplimit_banned_log_path}
- fi
- # Check if service log file exists so fail2ban won't return error
- if ! test -f "${iplimit_log_path}"; then
- touch ${iplimit_log_path}
- fi
- # Create the iplimit jail files
- # we didn't pass the bantime here to use the default value
- create_iplimit_jails
- # Launching fail2ban
- if ! systemctl is-active --quiet fail2ban; then
- systemctl start fail2ban
- else
- systemctl restart fail2ban
- fi
- systemctl enable fail2ban
- echo -e "${green}IP Limit installed and configured successfully!${plain}\n"
- before_show_menu
- }
- remove_iplimit(){
- echo -e "${green}\t1.${plain} Only remove IP Limit configurations"
- echo -e "${green}\t2.${plain} Uninstall Fail2ban and IP Limit"
- echo -e "${green}\t0.${plain} Abort"
- read -p "Choose an option: " num
- case "$num" in
- 1)
- rm -f /etc/fail2ban/filter.d/3x-ipl.conf
- rm -f /etc/fail2ban/action.d/3x-ipl.conf
- rm -f /etc/fail2ban/jail.d/3x-ipl.conf
- systemctl restart fail2ban
- echo -e "${green}IP Limit removed successfully!${plain}\n"
- before_show_menu ;;
- 2)
- rm -rf /etc/fail2ban
- systemctl stop fail2ban
- case "${release}" in
- ubuntu|debian)
- apt-get purge fail2ban -y;;
- centos)
- yum remove fail2ban -y;;
- fedora)
- dnf remove fail2ban -y;;
- *)
- echo -e "${red}Unsupported operating system. Please uninstall Fail2ban manually.${plain}\n"
- exit 1 ;;
- esac
- echo -e "${green}Fail2ban and IP Limit removed successfully!${plain}\n"
- before_show_menu ;;
- 0)
- echo -e "${yellow}Cancelled.${plain}\n"
- iplimit_main ;;
- *)
- echo -e "${red}Invalid option. Please select a valid number.${plain}\n"
- remove_iplimit ;;
- esac
- }
- show_usage() {
- echo "x-ui control menu usages: "
- echo "------------------------------------------"
- echo -e "x-ui - Enter control menu"
- echo -e "x-ui start - Start x-ui "
- echo -e "x-ui stop - Stop x-ui "
- echo -e "x-ui restart - Restart x-ui "
- echo -e "x-ui status - Show x-ui status"
- echo -e "x-ui enable - Enable x-ui on system startup"
- echo -e "x-ui disable - Disable x-ui on system startup"
- echo -e "x-ui log - Check x-ui logs"
- echo -e "x-ui banlog - Check Fail2ban ban logs"
- echo -e "x-ui update - Update x-ui "
- echo -e "x-ui install - Install x-ui "
- echo -e "x-ui uninstall - Uninstall x-ui "
- echo "------------------------------------------"
- }
- show_menu() {
- echo -e "
- ${green}3X-ui Panel Management Script${plain}
- ${green}0.${plain} Exit Script
- ————————————————
- ${green}1.${plain} Install x-ui
- ${green}2.${plain} Update x-ui
- ${green}3.${plain} Uninstall x-ui
- ————————————————
- ${green}4.${plain} Reset Username & Password & Secret Token
- ${green}5.${plain} Reset Panel Settings
- ${green}6.${plain} Change Panel Port
- ${green}7.${plain} View Current Panel Settings
- ————————————————
- ${green}8.${plain} Start x-ui
- ${green}9.${plain} Stop x-ui
- ${green}10.${plain} Restart x-ui
- ${green}11.${plain} Check x-ui Status
- ${green}12.${plain} Check x-ui Logs
- ————————————————
- ${green}13.${plain} Enable x-ui On System Startup
- ${green}14.${plain} Disable x-ui On System Startup
- ————————————————
- ${green}15.${plain} SSL Certificate Management
- ${green}16.${plain} Cloudflare SSL Certificate
- ${green}17.${plain} IP Limit Management
- ${green}18.${plain} WARP Management
- ————————————————
- ${green}19.${plain} Enable BBR
- ${green}20.${plain} Update Geo Files
- ${green}21.${plain} Active Firewall and open ports
- ${green}22.${plain} Speedtest by Ookla
- "
- show_status
- echo && read -p "Please enter your selection [0-22]: " num
- case "${num}" in
- 0)
- exit 0
- ;;
- 1)
- check_uninstall && install
- ;;
- 2)
- check_install && update
- ;;
- 3)
- check_install && uninstall
- ;;
- 4)
- check_install && reset_user
- ;;
- 5)
- check_install && reset_config
- ;;
- 6)
- check_install && set_port
- ;;
- 7)
- check_install && check_config
- ;;
- 8)
- check_install && start
- ;;
- 9)
- check_install && stop
- ;;
- 10)
- check_install && restart
- ;;
- 11)
- check_install && status
- ;;
- 12)
- check_install && show_log
- ;;
- 13)
- check_install && enable
- ;;
- 14)
- check_install && disable
- ;;
- 15)
- ssl_cert_issue_main
- ;;
- 16)
- ssl_cert_issue_CF
- ;;
- 17)
- iplimit_main
- ;;
- 18)
- warp_cloudflare
- ;;
- 19)
- enable_bbr
- ;;
- 20)
- update_geo
- ;;
- 21)
- open_ports
- ;;
- 22)
- run_speedtest
- ;;
- *)
- LOGE "Please enter the correct number [0-22]"
- ;;
- esac
- }
- if [[ $# > 0 ]]; then
- case $1 in
- "start")
- check_install 0 && start 0
- ;;
- "stop")
- check_install 0 && stop 0
- ;;
- "restart")
- check_install 0 && restart 0
- ;;
- "status")
- check_install 0 && status 0
- ;;
- "enable")
- check_install 0 && enable 0
- ;;
- "disable")
- check_install 0 && disable 0
- ;;
- "log")
- check_install 0 && show_log 0
- ;;
- "banlog")
- check_install 0 && show_banlog 0
- ;;
- "update")
- check_install 0 && update 0
- ;;
- "install")
- check_uninstall 0 && install 0
- ;;
- "uninstall")
- check_install 0 && uninstall 0
- ;;
- *) show_usage ;;
- esac
- else
- show_menu
- fi
|