summaryrefslogtreecommitdiffhomepage
diff options
context:
space:
mode:
-rw-r--r--CHANGELOG2
-rw-r--r--Cargo.lock2
-rw-r--r--Cargo.toml2
-rw-r--r--dpibreak.12
-rw-r--r--dpibreak.md123
5 files changed, 128 insertions, 3 deletions
diff --git a/CHANGELOG b/CHANGELOG
index 5c99be9..3c5f882 100644
--- a/CHANGELOG
+++ b/CHANGELOG
@@ -14,3 +14,5 @@ DPIBreak v0.0.4
DPIBreak v0.0.5
- linux: properly suppress cleanup warning logs on startup.
- linux: keep error logs on cleanup failure during shutdown.
+DPIBreak v0.0.6
+ - Fixed dependencies to allow installation via cargo install dpibreak.
diff --git a/Cargo.lock b/Cargo.lock
index bf433ff..e5a477b 100644
--- a/Cargo.lock
+++ b/Cargo.lock
@@ -103,7 +103,7 @@ dependencies = [
[[package]]
name = "dpibreak"
-version = "0.0.5"
+version = "0.0.6"
dependencies = [
"anyhow",
"ctrlc",
diff --git a/Cargo.toml b/Cargo.toml
index ba45804..b495087 100644
--- a/Cargo.toml
+++ b/Cargo.toml
@@ -17,7 +17,7 @@
[package]
name = "dpibreak"
-version = "0.0.5"
+version = "0.0.6"
authors = ["Dilluti0n <[email protected]>"]
edition = "2024"
build = "build.rs"
diff --git a/dpibreak.1 b/dpibreak.1
index 6456caa..7d15449 100644
--- a/dpibreak.1
+++ b/dpibreak.1
@@ -1,4 +1,4 @@
-.TH DPIBREAK 1 "October 2025" "DPIBreak v0.0.5" "User Commands"
+.TH DPIBREAK 1 "October 2025" "DPIBreak v0.0.6" "User Commands"
.nh
.ad l
diff --git a/dpibreak.md b/dpibreak.md
new file mode 100644
index 0000000..d43a70d
--- /dev/null
+++ b/dpibreak.md
@@ -0,0 +1,123 @@
+## NAME
+
+dpibreak - simple and efficient DPI circumvention tool in Rust.
+
+## SYNOPSIS
+
+**dpibreak** \[*OPTIONS*\]
+
+## DESCRIPTION
+
+**DPIBreak** is a simple and efficient tool for circumventing Deep
+Packet Inspection (DPI), especially on HTTPS connections. It fragments
+the TCP packet carrying the TLS ClientHello so that certain DPI devices
+cannot extract the Server Name Indication (SNI) field and identify the
+destination site.
+
+It only applies to the first outbound segment that carries the TLS
+ClientHello; Other packets are not queued to userspace and pass through
+the kernel normally, unmodified. UDP/QUIC (HTTP/3) is not affected.
+
+This program is cross-platform and runs the same way on both Linux and
+Windows. No manual firewall configuration is required: starting the
+program enables it system-wide; stopping it disables it.
+
+## REQUIREMENTS
+
+**Linux**
+Root privileges (or capabilities **CAP_NET_ADMIN** and **CAP_NET_RAW**)
+are required to install rules and attach to NFQUEUE. The **nft** command
+should be available. If it is not, **dpibreak** try to fallback
+**iptables** and **ip6tables.** Kernel support for **nfnetlink_queue**
+and **xt_u32** (when **nft** is not available) is required. (these
+modules are typically auto-loaded)
+
+<!-- -->
+
+**Windows**
+Administrator privilege is required to open the WinDivert driver; the
+program opens the driver automatically at startup.
+
+## OPTIONS
+
+**--delay-ms *u64***
+Delay in milliseconds to apply between fragmented pieces of the
+ClientHello. Typical values are 0–1000; larger values may increase
+handshake latency. (default: 0)
+
+**--queue-num *u16***
+
+NFQUEUE number to attach to. The same queue number is used for IPv4 and
+IPv6. (default: 1)
+
+**--nft-command *\<string\>***
+
+Custom nftables command to be executed. (default: nft)
+
+**--loglevel *debug\|info\|warning\|error***
+Set the logging level (default: **warning**). Aliases: **warn** -\>
+**warning**, **err** -\> **error**.
+
+**--no-splash**
+Disable splash messages at startup.
+
+**-h , --help**
+Show usage information and exit.
+
+## EXAMPLES
+
+Run with default options:
+
+> **dpibreak**
+
+Run with a 10 ms delay and verbose logging:
+
+> **dpibreak --delay-ms 10 --loglevel debug**
+
+Use a custom NFQUEUE on Linux:
+
+> **dpibreak --queue-num 3**
+
+## BUGS
+
+Although the program works reliably in the author's region and ISP,
+different regions, ISPs, or organizations may deploy different DPI
+equipment. In such cases, there is a chance that **dpibreak** does not
+function as expected. If you encounter such issue, please report
+symptoms and, if possible, packet capture logs (e.g., collected with
+Wireshark) or hints such as cases where alternative tools like
+GoodByeDPI succeed with specific settings to the bug tracker listed
+below.
+
+When sharing packet capture logs, please make sure they do not contain
+sensitive personal information (e.g., passwords or session cookies). It
+is usually enough to capture only the initial handshake packets showing
+the issue, rather than full sessions.
+
+Any other problems not covered above are also appreciated.
+
+Report bugs at \<https://github.com/dilluti0n/dpibreak/issues\>.
+
+## SECURITY AND PRIVACY
+
+The program does not store or transmit your traffic. Fragmentation is
+performed locally on the host; no external proxy or relay is used.
+
+## EXIT STATUS
+
+Normally, **dpibreak** runs continuously until interrupted by the user
+(e.g. with Ctrl+c) or the system. In such cases it exits with status 0.
+Non-zero exit codes are returned if the program fails to start (for
+example, due to insufficient privileges, missing iptables/WinDivert, or
+invalid options).
+
+## SEE ALSO
+
+**nft**(8), **iptables**(8), **ip6tables**(8), **tcpdump**(1),
+**wireshark**(1)
+
+GoodByeDPI \<https://github.com/ValdikSS/GoodbyeDPI\>
+
+## AUTHOR
+
+Written by Dilluti0n \<[email protected]\>.