brook

brook

多功能跨平台网络工具Brook提供灵活控制

Brook是一款跨平台网络工具,支持iOS、Android、Mac、Windows、Linux和OpenWrt等多种操作系统。它提供Fake DNS功能和可编程脚本接口,使用户能够精细控制网络请求和管理。Brook适用于各种网络环境,可用于优化网络性能和管理复杂的网络需求。

Brook网络工具代理VPN跨平台Github开源项目

Brook

<!--SIDEBAR--> <!--G-R3M673HK5V-->

A cross-platform programmable network tool.

Sponsor

❤️ Shiliew - A network app designed for those who value their time

Getting Started

Server

bash <(curl https://bash.ooo/nami.sh)
nami install brook
brook server -l :9999 -p hello

Client

iOSAndroidMacWindowsLinuxOpenWrt
WindowsOpenWrt
//App ModeHowHowHow

You may want to use brook link to customize some parameters

Client

Brook GUI will pass different global variables to the script at different times, and the script only needs to assign the processing result to the global variable out

CLI

Before discussing the GUI client, let's first talk about the command line client brook. As we know, after you have deployed the server, you can use the command line client brook to create a local socks5 proxy or http proxy on your machine, and then configure it in your system proxy settings or in your browser to use this proxy. However:

  1. Not all apps will use this proxy, whether they use it is up to the app itself.
  2. Generally, all UDP protocols will not go through this proxy, such as http3.

For the specifics of socks5 and http proxy, you can read this article.

GUI

The GUI client does not use socks5 and http proxy mode, so there is no issue with some software not using the system proxy. Instead, it uses a virtual network card to take over the entire system's network, including UDP-based http3. Moreover, Brook allows us to control network requests programmatically, so it is necessary to have basic knowledge of network requests.

Without Brook: Basic Knowledge of Network Requests

Note: When we talk about addresses, we mean addresses that include the port number, such as a domain address: google.com:443, or an IP address: 8.8.8.8:53

  1. When an app requests a domain address, such as google.com:443
  2. It will first perform a DNS resolution, which means that the app will send a network request to the system-configured DNS, such as 8.8.8.8:53, to inquire about the IP of google.com
    1. The system DNS will return the IP of google.com, such as 1.2.3.4, to the app
  3. The app will combine the IP and port into an IP address, such as: 1.2.3.4:443
  4. The app makes a network request to this IP address 1.2.3.4:443
  5. The app receives the response data

In the above process, the app actually makes two network requests: one to the IP address 8.8.8.8:53 and another to the IP address 1.2.3.4:443. In other words, the domain name is essentially an alias for the IP, and must obtain the domain's IP to establish a connection.

With Brook: Fake DNS On

Brook has a Fake DNS feature, which can parse the domain name out of the query requests that an app sends to the system DNS and decide how to respond to the app.

  1. When an app requests a domain name address, such as google.com:443
  2. A DNS resolution will be performed first. That is, the app will send a network request to the system-configured DNS, such as 8.8.8.8:53, to inquire about the IP of google.com
  3. The Brook client detects that an app is sending a network request to 8.8.8.8:53. <mark>This will trigger the in_dnsquery variable, carrying information such as domain</mark>
    1. The Brook client returns a fake IP to the app, such as 240.0.0.1
  4. The app combines the IP and port into an IP address, such as: 240.0.0.1:443
  5. The app makes a network request to the IP address 240.0.0.1:443
  6. The Brook client detects that an app is sending a network request to 240.0.0.1:443, discovers that this is a fake IP, and will convert the fake IP address back to the domain address google.com:443. <mark>This will trigger the in_address variable, carrying information such as domainaddress</mark>
    1. The Brook client sends google.com:443 to the Brook Server
    2. The Brook Server first requests its own DNS to resolve the domain name to find out the IP of google.com, such as receiving 1.2.3.4
    3. The Brook Server combines the IP and port into an IP address, such as: 1.2.3.4:443
    4. The Brook Server sends a network request to 1.2.3.4:443 and returns the data to the Brook client
    5. The Brook client then returns the data to the app
  7. The app receives the response data

However, if the following situations occur, the domain name will not/cannot be parsed, meaning that the Brook client will not/cannot know what the domain name is and will treat it as a normal request sent to an IP address:

  • Fake DNS not enabled: in this case, the Brook client will not attempt to parse the domain name from the request sent to the system DNS and will treat it as a normal request sent to an IP address.
  • Even with Fake DNS enabled, but the app uses the system's secure DNS or the app's own secure DNS: in this case, the Brook client cannot parse the domain name from the request sent to the secure DNS and will treat it as a normal request sent to an IP address.

To avoid the ineffectiveness of Fake DNS, please refer to this article.

With Brook: Fake DNS Off

  1. When an app requests a domain address, such as google.com:443
  2. A DNS resolution will be performed first. That is, the app will send a network request to the system-configured DNS, such as 8.8.8.8:53, to inquire about the IP of google.com
  3. The Brook client detects that an app is sending a network request to 8.8.8.8:53. <mark>This will trigger the in_address variable, carrying information such as ipaddress</mark>
    1. The Brook client sends 8.8.8.8:53 to the Brook Server
    2. The Brook Server sends a network request to 8.8.8.8:53 and returns the result, such as 1.2.3.4, to the Brook client
    3. The Brook client then returns the result to the app
  4. The app combines the IP and port into an IP address, such as: 1.2.3.4:443
  5. The app makes a network request to the IP address 1.2.3.4:443
  6. The Brook client detects that an app is sending a network request to 1.2.3.4:443. <mark>This will trigger the in_address variable, carrying information such as ipaddress</mark>
    1. The Brook client sends 1.2.3.4:443 to the Brook Server
    2. The Brook Server sends a network request to 1.2.3.4:443 and returns the data to the Brook client
    3. The Brook client then returns the data to the app
  7. The app receives the response data

With Brook: Fake DNS On, But the App Uses the System's Secure DNS or Its Own Secure DNS

  1. When an app requests a domain name address, such as google.com:443
  2. A DNS resolution will be performed first. That is, the app will send a network request to the secure DNS, such as 8.8.8.8:443, to inquire about the IP of google.com
  3. The Brook client detects that an app is sending a network request to 8.8.8.8:443. <mark>This will trigger the in_address variable, carrying information such as ipaddress</mark>
    1. The Brook client sends 8.8.8.8:443 to the Brook Server
    2. The Brook Server sends a network request to 8.8.8.8:443, and returns the result, such as 1.2.3.4, to the Brook client
    3. The Brook client then returns the result to the app
  4. The app combines the IP and port into an IP address, such as: 1.2.3.4:443
  5. The app makes a network request to the IP address 1.2.3.4:443
  6. The Brook client detects that an app is sending a network request to 1.2.3.4:443. <mark>This will trigger the in_address variable, carrying information such as ipaddress</mark>
    1. The Brook client sends 1.2.3.4:443 to the Brook Server
    2. The Brook Server sends a network request to 1.2.3.4:443 and returns the data to the Brook client
    3. The Brook client then returns the data to the app
  7. The app receives the response data

To avoid the ineffectiveness of Fake DNS, please refer to this article.

Handle Variable Trigger

  • When the in_brooklinks variable is triggered:
    • This is currently the only variable that gets triggered before the Brook client starts.
    • We know that Brook starts with your choice of a Brook Server, and this variable lets you specify multiple Brook Servers.
    • Then during runtime, you can use one of these Brook Servers as needed.
  • When the in_dnsquery variable is triggered, you can process as needed, such as:
    • Blocking, such as to prevent ad domain names.
    • Directly specifying the response IP.
    • Letting the system DNS resolve this domain.
    • Letting Bypass DNS resolve this domain.
    • And so on.
  • When the in_address variable is triggered, you can process as needed, such as:
    • Block this connection.
    • Rewrite the destination.
    • If it's a domain address, you can specify that Bypass DNS is responsible for resolving the IP of this domain.
    • Allow it to connect directly without going through a proxy.
    • If it's HTTP/HTTPS, you can start MITM (Man-In-The-Middle), which will subsequently trigger in_httprequest and in_httpresponse.
    • And so on.
  • When the in_httprequest variable is triggered, you can process as needed, such as:
    • Modifying the HTTP request.
    • Returning a custom HTTP response directly.
  • When the in_httpresponse variable is triggered, you can process as needed, such as:
    • Modifying the HTTP response.

For detailed information on the properties and responses of variables, please refer to the following content.

Variables

variabletypeconditiontimingdescriptionout type
in_brooklinksmap/Before connectingPredefine multiple brook links, and then programmatically specify which one to connect tomap
in_dnsquerymapFakeDNS: OnWhen a DNS query occursScript can decide how to handle this requestmap
in_addressmap/When connecting to an addressscript can decide how to connectmap
in_httprequestmap/When an HTTP(S) request comes inthe script can decide how to handle this requestmap
in_httprequest,in_httpresponsemap/when an HTTP(S) response comes inthe script can decide how to handle this responsemap

in_brooklinks

KeyTypeDescriptionExample
_boolmeaninglesstrue

out, ignored if not of type map

KeyTypeDescriptionExample
............
custom namestringbrook linkbrook://...
............

in_dnsquery

KeyTypeDescriptionExample
domainstringdomain namegoogle.com
typestringquery typeA
appidstringApp ID or pathcom.google.Chrome.helper
interfacestringnetwork interface. Mac onlyen0

out, if it is error type will be recorded in the log. Ignored if not of type map

KeyTypeDescriptionExample
blockboolWhether Block, default falsefalse
ipstringSpecify IP directly, only valid when type is A/AAAA1.2.3.4
systemboolResolve by System DNS, default falsefalse
bypassboolResolve by Bypass DNS, default falsefalse
brooklinkkeystringWhen need to connect the Server,instead, connect to the Server specified by the key in_brooklinkscustom name

in_address

KeyTypeDescriptionExample
networkstringNetwork type, the value tcp/udptcp
ipaddressstringIP type address. There is only of ipaddress and domainaddress. Note that there is no relationship between these two1.2.3.4:443
domainaddressstringDomain type address, because of FakeDNS we can get the domain name address heregoogle.com:443
appidstringApp ID or pathcom.google.Chrome.helper
interfacestringnetwork interface. Mac onlyen0

out, if it is error type will be recorded in the log. Ignored if not of type map

KeyTypeDescriptionExample
blockboolWhether Block, default falsefalse
ipaddressstringIP type address, rewrite destination1.2.3.4:443
ipaddressfrombypassdnsstringUse Bypass DNS to obtain A or AAAA IP and rewrite the destination, only valid when domainaddress exists, the value A/AAAAA
bypassboolBypass, default false. If true and domainaddress, then ipaddress or ipaddressfrombypassdns must be specifiedfalse
mitmboolWhether to perform MITM, default false. Only valid when network is tcp. Need to install CA, see belowfalse
mitmprotocolstringMITM protocol needs to be specified explicitly, the value is http/httpshttps
mitmcertdomainstringThe MITM certificate domain name, which is taken from domainaddress by default. If ipaddress and mitm is true and mitmprotocol is https then must be must be specified explicitlyexample.com
mitmwithbodyboolWhether to manipulate the http body, default false. will read the body of the request and response into the memory and interact with the script. iOS 50M total memory limit may kill processfalse
mitmautohandlecompressboolWhether to automatically decompress the http body when interacting with the script, default falsefalse
mitmclienttimeoutintTimeout for MITM talk to server,

编辑推荐精选

音述AI

音述AI

全球首个AI音乐社区

音述AI是全球首个AI音乐社区,致力让每个人都能用音乐表达自我。音述AI提供零门槛AI创作工具,独创GETI法则帮助用户精准定义音乐风格,AI润色功能支持自动优化作品质感。音述AI支持交流讨论、二次创作与价值变现。针对中文用户的语言习惯与文化背景进行专门优化,支持国风融合、C-pop等本土音乐标签,让技术更好地承载人文表达。

lynote.ai

lynote.ai

一站式搞定所有学习需求

不再被海量信息淹没,开始真正理解知识。Lynote 可摘要 YouTube 视频、PDF、文章等内容。即时创建笔记,检测 AI 内容并下载资料,将您的学习效率提升 10 倍。

AniShort

AniShort

为AI短剧协作而生

专为AI短剧协作而生的AniShort正式发布,深度重构AI短剧全流程生产模式,整合创意策划、制作执行、实时协作、在线审片、资产复用等全链路功能,独创无限画布、双轨并行工业化工作流与Ani智能体助手,集成多款主流AI大模型,破解素材零散、版本混乱、沟通低效等行业痛点,助力3人团队效率提升800%,打造标准化、可追溯的AI短剧量产体系,是AI短剧团队协同创作、提升制作效率的核心工具。

seedancetwo2.0

seedancetwo2.0

能听懂你表达的视频模型

Seedance two是基于seedance2.0的中国大模型,支持图像、视频、音频、文本四种模态输入,表达方式更丰富,生成也更可控。

nano-banana纳米香蕉中文站

nano-banana纳米香蕉中文站

国内直接访问,限时3折

输入简单文字,生成想要的图片,纳米香蕉中文站基于 Google 模型的 AI 图片生成网站,支持文字生图、图生图。官网价格限时3折活动

扣子-AI办公

扣子-AI办公

职场AI,就用扣子

AI办公助手,复杂任务高效处理。办公效率低?扣子空间AI助手支持播客生成、PPT制作、网页开发及报告写作,覆盖科研、商业、舆情等领域的专家Agent 7x24小时响应,生活工作无缝切换,提升50%效率!

堆友

堆友

多风格AI绘画神器

堆友平台由阿里巴巴设计团队创建,作为一款AI驱动的设计工具,专为设计师提供一站式增长服务。功能覆盖海量3D素材、AI绘画、实时渲染以及专业抠图,显著提升设计品质和效率。平台不仅提供工具,还是一个促进创意交流和个人发展的空间,界面友好,适合所有级别的设计师和创意工作者。

图像生成AI工具AI反应堆AI工具箱AI绘画GOAI艺术字堆友相机AI图像热门
码上飞

码上飞

零代码AI应用开发平台

零代码AI应用开发平台,用户只需一句话简单描述需求,AI能自动生成小程序、APP或H5网页应用,无需编写代码。

Vora

Vora

免费创建高清无水印Sora视频

Vora是一个免费创建高清无水印Sora视频的AI工具

Refly.AI

Refly.AI

最适合小白的AI自动化工作流平台

无需编码,轻松生成可复用、可变现的AI自动化工作流

下拉加载更多