A simple and fully-compliant SOCKS Protocol Version 5 server written in Python
10K+
A small SOCKS5 proxy server written in Python with no dependencies. It implements RFC 1928 (CONNECT and UDP ASSOCIATE, IPv4/IPv6/domain names) and RFC 1929 username/password authentication.
Source, full documentation and changelog: https://github.com/j0shcap/simple-socks5
With authentication, published on localhost only:
docker run -d -p 127.0.0.1:1080:1080 \
-e SOCKS5_USERNAME=proxyuser -e SOCKS5_PASSWORD=change-me -e SOCKS5_AUTH_REQUIRED=true \
jcaponigro20/simple-socks5:2.1.0
curl -x socks5h://proxyuser:[email protected]:1080 https://example.com
Without authentication (trusted networks only):
docker run -d -p 127.0.0.1:1080:1080 -e SOCKS5_AUTH_REQUIRED=false jcaponigro20/simple-socks5:2.1.0
| Tag | Contents |
|---|---|
2.1.0, 2.1, 2, latest | Current release. 2.1.0 never changes; the others move to newer releases. |
2.1.0-logging-disabled, logging-disabled | The same with logging turned off. |
2.0.0, 2.0, 2.0.0-logging-disabled | The previous release, for the 2.0 behaviour. |
main | Latest commit on main. Unreleased, for testing only. |
All images are built for linux/amd64, linux/arm64 and linux/arm/v7. Pin an exact version in production.
| Variable | Default | |
|---|---|---|
SOCKS5_USERNAME, SOCKS5_PASSWORD | myusername, mypassword | Credentials. Set your own. |
SOCKS5_AUTH_REQUIRED | false | true to require authentication. |
LOGGING_LEVEL | info | debug, info, warning, error, critical or disabled. |
SOCKS5_ALLOW_LOOPBACK | false | true to allow proxying to loopback and link-local addresses. |
SOCKS5_HANDSHAKE_TIMEOUT, SOCKS5_CONNECT_TIMEOUT | 10 | Seconds. |
SOCKS5_MAX_CONNECTIONS | 200 | Concurrent clients. |
SOCKS5_LOG_FILE | unset | Also write errors to this file. |
2.1 changes some defaults: logs are at info instead of debug, proxying to loopback and link-local addresses (including 169.254.169.254) is refused, /app/errors.log is no longer written, and empty credentials never log in. See the changelog for how to restore each one, or pin 2.0.0.
Without authentication, anyone who can reach the port can use the proxy, and the container logs a warning at startup. SOCKS5 is unencrypted, credentials included; use an SSH tunnel or VPN where traffic could be intercepted.
Content type
Image
Digest
sha256:755f5d5c4…
Size
43.9 MB
Last updated
4 days ago
docker pull jcaponigro20/simple-socks5