{"repo":"Eljaja/BibaVPN","free":true,"listed":false,"github":"https://github.com/Eljaja/BibaVPN","clone":"git clone https://github.com/Eljaja/BibaVPN.git","description":"DPI-resistant SOCKS5/HTTP tunnel over TLS+WebSocket for self-hosted single-VPS setups","language":"Rust","stars":56,"topics":["dpi-bypassing","http-proxy","security","vpn-server","dpi","proxy","rust","zapret","android","censorship-circumvention"],"license":"MIT","category":"networking-infra","readme_excerpt":"BibaVPN A DPI-resistant SOCKS5 / HTTP-CONNECT tunnel that wraps your traffic in TLS + WebSocket and ships it through a single VPS. Pure-Rust client and server, plus an Android app (Jetpack Compose) and a Tauri desktop wrapper in the same workspace. Highlights - Encrypted inner wire: opaque HELLO/ACK, ChaCha20-Poly1305, domain-separated keys, sealed control frames, per-frame random decoy + padding. - Looks like normal HTTPS: browser-ordered upgrade headers, configurable TLS client profile (rustls default, optional BoringSSL), leaf pinning, HTTP camouflage on the same port. - Stream multiplexing over 1–4 outer WSS sessions, plus a separate WSS for UDP relay. - Optional REALITY front-domain mode and encrypted biba:// invites (one line of config instead of a wall of flags). Status: experimental. The protocol is not frozen — treat any deployment as a personal lab, not a production service. See Security. The client exposes a local SOCKS5 (and optional HTTP CONNECT) endpoint; the server terminates TLS + WebSocket on a VPS and dials the target. Full wire format and session flow: PROTOCOL.md . Quick start You need Docker (for the lab path) or Rust stable (pinned via rust-toolchain.toml ) to build from source. Anything beyond a local lab also needs a VPS or LAN host for the server. A. Local Docker lab start.sh generates secrets, brings up the server via docker compose , and prints a labeled Invite URI ( biba://… ) and Passphrase — paste both into the app, or smoke-test from the shell: ","default_branch":null,"files":null,"tree":[],"storefront":"/r/Eljaja","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Eljaja/BibaVPN/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}