<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>未分类 &#8211; Daoker小站</title>
	<atom:link href="https://daoker.cc/category/uncategorized/feed" rel="self" type="application/rss+xml" />
	<link>https://daoker.cc</link>
	<description>个人随笔小记</description>
	<lastBuildDate>Thu, 03 Sep 2026 07:01:42 +0000</lastBuildDate>
	<language>zh-Hans</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://daoker.cc/wp-content/uploads/2022/08/cropped-daoker_blog_s-32x32.png</url>
	<title>未分类 &#8211; Daoker小站</title>
	<link>https://daoker.cc</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>扒开一个&#8221;企业补贴&#8221;钓鱼站：背后是一套成熟的诈骗 SaaS 产业链</title>
		<link>https://daoker.cc/daokerto1296.html</link>
					<comments>https://daoker.cc/daokerto1296.html#respond</comments>
		
		<dc:creator><![CDATA[博主]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 07:01:41 +0000</pubDate>
				<category><![CDATA[未分类]]></category>
		<guid isPermaLink="false">https://daoker.cc/?p=1296</guid>

					<description><![CDATA[扒开一个&#8221;企业补贴&#8221;钓鱼站：背后是一套成熟的诈骗 SaaS 产业链 扒开一个&#822 [&#8230;]]]></description>
										<content:encoded><![CDATA[
<!DOCTYPE html>
<html lang="zh-CN">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>扒开一个&#8221;企业补贴&#8221;钓鱼站：背后是一套成熟的诈骗 SaaS 产业链</title>
<style>
  :root {
    --bg: #ffffff;
    --text: #1f2328;
    --muted: #6b7280;
    --border: #e5e7eb;
    --accent: #c0392b;
    --accent-soft: #fdf3f2;
    --code-bg: #f6f8fa;
    --link: #185fa5;
  }
  * { box-sizing: border-box; }
  body {
    margin: 0;
    background: #fafafa;
    color: var(--text);
    font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", "PingFang SC", "Hiragino Sans GB", "Microsoft YaHei", sans-serif;
    line-height: 1.8;
    font-size: 16px;
  }
  .container { max-width: 740px; margin: 0 auto; padding: 48px 24px 80px; }
  article { background: var(--bg); border: 1px solid var(--border); border-radius: 12px; padding: 48px 44px; }
  h1 { font-size: 28px; line-height: 1.4; margin: 0 0 8px; font-weight: 600; }
  .meta { color: var(--muted); font-size: 14px; margin-bottom: 8px; }
  .tagline { color: var(--muted); font-size: 15px; border-left: 3px solid var(--accent); padding-left: 14px; margin: 16px 0 28px; }
  h2 { font-size: 21px; margin: 36px 0 14px; font-weight: 600; padding-bottom: 8px; border-bottom: 1px solid var(--border); }
  p { margin: 14px 0; }
  a { color: var(--link); text-decoration: none; }
  code {
    background: var(--code-bg);
    padding: 2px 6px;
    border-radius: 4px;
    font-family: "SFMono-Regular", Consolas, "Liberation Mono", Menlo, monospace;
    font-size: 14px;
  }
  pre {
    background: var(--code-bg);
    border: 1px solid var(--border);
    border-radius: 8px;
    padding: 16px;
    overflow-x: auto;
    font-size: 14px;
    line-height: 1.6;
  }
  pre code { background: none; padding: 0; }
  blockquote {
    margin: 16px 0;
    padding: 12px 18px;
    background: var(--accent-soft);
    border-left: 3px solid var(--accent);
    border-radius: 0 8px 8px 0;
    color: #5f3a34;
  }
  table { width: 100%; border-collapse: collapse; margin: 18px 0; font-size: 14.5px; }
  th, td { border: 1px solid var(--border); padding: 10px 12px; text-align: left; }
  th { background: #f6f7f9; font-weight: 600; }
  tr:nth-child(even) td { background: #fafbfc; }
  ol, ul { padding-left: 24px; }
  li { margin: 8px 0; }
  strong { font-weight: 600; }
  .warn {
    background: #fff8e6;
    border: 1px solid #f5e3b8;
    border-radius: 8px;
    padding: 16px 20px;
    margin: 20px 0;
  }
  .warn strong { color: #9a6b00; }
  @media (max-width: 600px) {
    article { padding: 28px 20px; }
    h1 { font-size: 24px; }
  }
</style>
</head>
<body>
<div class="container">
<article>
  <h1>扒开一个&#8221;企业补贴&#8221;钓鱼站：背后是一套成熟的诈骗 SaaS 产业链</h1>
  <div class="meta">安全研究复盘 · 2026-09-03 · 反诈警示</div>
  <div class="tagline">一个陌生短链，一次公开情报追踪，最后挖出了诈骗团伙的完整中控后台和 23 条话术库。</div>

  <h2>起因：一条链接</h2>
  <p>最近有人转来一个链接：<code>https://fpz.hyzt88.cyou/0Rqbvc</code>，说是&#8221;诈骗了很多人&#8221;。我顺手做了个检测，没想到一路挖到了这伙人的老巢。</p>

  <h2>一、这到底是个什么站？</h2>
  <p>打开链接，页面标题赫然写着<strong>&#8220;企业补贴申请&#8221;</strong>。看着像政务平台，实则是个钓鱼表单。真正的猫腻在它&#8221;前后端分离&#8221;的架构上：</p>
  <ul>
    <li>前端 <code>fpz.hyzt88.cyou</code>：一个空壳 Vue 页面，只负责展示表单</li>
    <li>后端 <code>api.het88.top</code>：表单字段全靠这里动态下发</li>
  </ul>
  <p>直接请求后端接口，返回的是一段诱导话术：</p>
  <pre><code>"bank_priority": "使用 中国银行 邮政银行 工商银行 优先办理！"
"module_value": "900"</code></pre>
  <p>&#8220;900 元补贴&#8221;是诱饵，&#8221;优先办理指定银行卡&#8221;是套取卡号的第一步。</p>

  <h2>二、从域名追到服务器</h2>
  <p>顺着域名查下去，服务器位置也清楚了：</p>
  <table>
    <thead><tr><th>角色</th><th>域名</th><th>IP</th><th>云厂商</th></tr></thead>
    <tbody>
      <tr><td>前端套壳</td><td>fpz.hyzt88.cyou</td><td>16.163.104.151</td><td>AWS 香港</td></tr>
      <tr><td>后端收集</td><td>api.het88.top</td><td>43.200.221.80</td><td>AWS 首尔</td></tr>
    </tbody>
  </table>
  <p>两台都在 AWS，前后端分离部署。域名用了廉价的 <code>.cyou</code> 后缀 + 随机短码，注册信息全部隐藏。</p>
  <p><strong>关键突破来自 SSL 证书。</strong>抓取前端证书时，SAN 字段一次暴露了同批 4 个通配域名：</p>
  <pre><code>*.hyzt88.cyou
*.seda88.cyou
*.zqaj88.cyou
*.zujd88.cyou</code></pre>
  <p>也就是说，这伙人手里至少 4 个同构钓鱼域名，用同一张证书批量分发。加上后端 <code>het88.top</code>，一共 5 个域名资产。</p>
  <p>再查证书透明度日志（crt.sh），<code>het88.top</code> 最早的证书是 2026 年 6 月底——<strong>已经运营两个多月</strong>，而且 9 月初刚续签证书，<strong>仍在活跃作案</strong>。</p>

  <h2>三、管理后台：一个完整的诈骗 SaaS</h2>
  <p>真正的重磅发现在后端。访问 <code>https://het88.top/</code>，页面标题直接写着<strong>&#8220;后台管理&#8221;</strong>——这就是诈骗团伙的中控台。</p>
  <p>扒开它的前端代码，后台功能模块一目了然：</p>
  <table>
    <thead><tr><th>模块</th><th>接口</th><th>实际用途</th></tr></thead>
    <tbody>
      <tr><td>代理账号管理</td><td>/users</td><td>按天卖账号，有效期 1~365 天</td></tr>
      <tr><td>剧本配置</td><td>/module-settings/update</td><td>切换财政补贴/学生补贴/育儿补贴</td></tr>
      <tr><td>链接管理</td><td>/urls/batch-upsert</td><td>批量生成分发短链</td></tr>
      <tr><td>数据管理</td><td>/data-records/all</td><td>查看并导出受害者信息</td></tr>
      <tr><td>访问统计</td><td>/urls/visits</td><td>追踪哪个链接骗了多少人</td></tr>
      <tr><td>跳转设置</td><td>/redirect-settings</td><td>配置&#8221;正在处理中&#8221;话术</td></tr>
      <tr><td>广告管理</td><td>/advertisements</td><td>管理引流渠道</td></tr>
      <tr><td>IP 黑名单</td><td>/ip-blacklist</td><td>封禁安全人员/执法 IP</td></tr>
    </tbody>
  </table>
  <p>最硬核的证据，是后台内置的一套<strong>话术指令库</strong>——23 条指挥受害者的话术，每条一个编号：</p>
  <blockquote>获取短信 / 支付密码错误 / 验证码错误 / 银行卡错误 / <strong>余额低于 5000·3000·2000</strong> / 取 4 位短信 / 换中建邮浦光民银行 / <strong>风险存入 2000·3000·5000</strong> / 更换工行·中行 / 跳转页面……</blockquote>
  <p>配合后台收集的字段——<strong>账号、登录密码、短信验证码、手机号、支付密码、IP、地理位置、信用卡卡号 + 有效期、银行、姓名</strong>——完整作案手法浮出水面：</p>
  <ol>
    <li>受害者点链接，填卡号、身份证、姓名</li>
    <li>数据通过 WebSocket <strong>实时推送到</strong>骗子后台</li>
    <li>骗子看卡里余额（&#8221;余额低于 X&#8221;），挑对应话术</li>
    <li>谎称&#8221;风控&#8221;&#8221;保证金&#8221;，诱导往卡里存钱（&#8221;风险存入 2000/3000/5000&#8243;）</li>
    <li>套走短信验证码 + 支付密码 → 盗刷/转走资金</li>
  </ol>

  <h2>四、真实话术样本：群内实拍</h2>
  <p>这套系统的话术库不是纸面上的，它每天都在往真实微信群里投。下面这条，就是同事群里实拍到的原话：</p>
  <blockquote>@所有人 关于〔2026年度〕补贴通知：<br>
  根据国家财政局&#8221;人力资源和社会保障部&#8221;要求关于落实用于补助缓解经济下行个人消费等综合补贴正常发放<br>
  依据《国家劳动法管理条例》一次性发放补贴2735元申领办法如下：<br>
  进入官网提交申办流程：https://fpz.hyzt88.cyou/0Rqbvc<br>
  （部分地区需将主页链接复制到手机浏览器登记申领）<br>
  注：昨天领过的同事请忽略。未领取人员请立即提交登记，逾期将视为放弃申领！</blockquote>
  <p>链接还是那个 <code>/0Rqbvc</code>，一个字没变，只是把诱饵金额换成了 2735 元。这段话术的破绽，几乎每一句都是：</p>
  <table>
    <thead><tr><th>原文</th><th>破绽</th></tr></thead>
    <tbody>
      <tr><td>&#8220;国家财政局&#8221;</td><td>机构不存在，国家财政主管部门是&#8221;财政部&#8221;</td></tr>
      <tr><td>《国家劳动法管理条例》</td><td>法律不存在，只有《中华人民共和国劳动法》</td></tr>
      <tr><td>&#8220;复制到手机浏览器登记&#8221;</td><td>规避微信内置浏览器的钓鱼拦截</td></tr>
      <tr><td>&#8220;昨天领过的同事请忽略&#8221;</td><td>制造&#8221;已经有人领了&#8221;的从众心理</td></tr>
      <tr><td>&#8220;逾期将视为放弃申领&#8221;</td><td>制造紧迫感，催你立刻点</td></tr>
      <tr><td>@所有人</td><td>伪装群公告，蹭权威感</td></tr>
    </tbody>
  </table>
  <p><strong>记住这个模式</strong>：金额会变（900、2735……）、剧本会变（财政/学生/育儿补贴），但&#8221;陌生短链 + 要填银行卡 + 制造紧迫感&#8221;的骨架永远不变。</p>

  <h2>五、这是一条黑产产业链</h2>
  <p>整套系统的本质，是一个<strong>加盟式诈骗 SaaS</strong>：</p>
  <pre><code>顶层团伙开发平台（het88.top）
        ↓ 招商
二级代理按天付费买账号（1~365 天）
        ↓ 批量生成链接分发
剧本随便切：财政补贴 / 学生补贴 / 育儿补贴
        ↓
受害者填卡 + 身份证 + 支付密码
        ↓ 数据实时进中控
话术库指挥 + 诱导"风险存入"
        ↓
盗刷资金 → 按比例分成</code></pre>
  <p>顶层只卖工具，下面一堆代理各自作案，骗到钱再分成。这就是为什么封一个链接没用——他们能瞬间换域名、换剧本。</p>

  <h2>六、技术架构拆解</h2>
  <p>从代码层面看，这套系统是标准的&#8221;多租户 SaaS + 动态表单 + 实时推送&#8221;：</p>
  <ol>
    <li><strong>分发引流层</strong>：短链 + 随机短码，批量撒</li>
    <li><strong>受害端表单</strong>：Vue3 + Element Plus 动态表单，字段由后端下发</li>
    <li><strong>数据 API</strong>：REST + token 鉴权</li>
    <li><strong>数据存储</strong>：卡号/身份证/支付密码/验证码</li>
    <li><strong>实时推送</strong>：WebSocket 秒级同步到后台</li>
    <li><strong>中控后台</strong>：代理账号/剧本/话术库/统计导出</li>
    <li><strong>反侦察层</strong>：IP 黑名单 + 域名轮换</li>
  </ol>

  <h2>七、怎么防？（重点）</h2>
  <div class="warn">
    <strong>凡索要&#8221;支付密码&#8221;&#8221;短信验证码&#8221;的补贴/退款页面 = 100% 诈骗。</strong><br>
    正规政务补贴从不要你输支付密码。
  </div>
  <ol>
    <li><strong>&#8220;余额低于 X&#8221;&#8221;风险存入 X 元&#8221;是骗子专用话术</strong>，见到就挂断/关闭。</li>
    <li><strong>陌生短链 + 廉价后缀（.cyou/.top/.xyz）+ 随机短码 = 高危</strong>，别好奇点。</li>
    <li><strong>别记域名黑名单，记行为特征</strong>。这类站换域名比拉黑快，靠&#8221;要密码/验证码&#8221;识别最靠谱。</li>
    <li>企业侧：给员工做防诈培训，尤其是财务、行政岗位（他们最容易接触&#8221;补贴&#8221;&#8221;退款&#8221;类诈骗）。</li>
  </ol>

  <h2>八、结语</h2>
  <p>这篇文章里出现的域名、IP、话术，都是公开的威胁情报（IoC）。写出来的目的只有一个——让更多人认出这类骗局。</p>
  <p>如果你也收到类似链接：</p>
  <ul>
    <li>不点、不填、不转发</li>
    <li>举报：国家反诈中心 App / 96110 / 12321.cn</li>
    <li>已经填过的：立即冻结银行卡 + 报警</li>
  </ul>
  <p>安全研究的意义，从来不是炫技，而是让下一个受害者不再出现。</p>
</article>
</div>
</body>
</html>
]]></content:encoded>
					
					<wfw:commentRss>https://daoker.cc/daokerto1296.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>【好玩的Docker项目】搭建一个小而美的网站流量监控——Umami</title>
		<link>https://daoker.cc/daokerto904.html</link>
					<comments>https://daoker.cc/daokerto904.html#comments</comments>
		
		<dc:creator><![CDATA[博主]]></dc:creator>
		<pubDate>Mon, 26 Dec 2022 17:26:00 +0000</pubDate>
				<category><![CDATA[未分类]]></category>
		<guid isPermaLink="false">https://daoker.cc/?p=904</guid>

					<description><![CDATA[又抄咕咕的文章了，哈哈哈 https://blog.laoda.de/archives/umami 1.首先从 [&#8230;]]]></description>
										<content:encoded><![CDATA[
<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">又抄咕咕的文章了，哈哈哈</p>
<cite>https://blog.laoda.de/archives/umami</cite></blockquote>



<div class="wp-block-argon-github github-info-card card shadow-sm github-info-card-full" data-author="umami-software" data-project="umami"><div class="github-info-card-header"><a href="https://github.com/" target="_blank" title="Github" rel="noopener"><span><i class="fa fa-github"></i> GitHub</span></a></div><div class="github-info-card-body"><div class="github-info-card-name-a"><a href="https://github.com/umami-software/umami" target="_blank" rel="noopener"><span class="github-info-card-name">umami-software/umami</span></a></div><div class="github-info-card-description"></div></div><div class="github-info-card-bottom"><span class="github-info-card-meta github-info-card-meta-stars"><i class="fa fa-star"></i> <span class="github-info-card-stars"></span></span><span class="github-info-card-meta github-info-card-meta-forks"><i class="fa fa-code-fork"></i> <span class="github-info-card-forks"></span></span></div></div>



<p class="wp-block-paragraph">1.首先从github上克隆项目</p>



<pre class="wp-block-code"><code>git clone https://github.com/umami-software/umami.git
cd umami/
vim docker-compose.yml</code></pre>



<pre class="wp-block-code"><code>---
version: '3'
services:
  umami:
    image: ghcr.io/umami-software/umami:postgresql-latest
    ports:
      - "3000:3000"
    environment:
      DATABASE_URL: postgresql://umami:umami@db:5432/umami # 这里的数据库和密码要和下方你修改的相同
      DATABASE_TYPE: postgresql
      HASH_SALT: replace-me-with-a-random-string
    depends_on:
      - db
    restart: always
  db:
    image: postgres:12-alpine
    environment:
      POSTGRES_DB: umami
      POSTGRES_USER: umami # 数据库用户
      POSTGRES_PASSWORD: umami  # 数据库密码
    volumes:
      - ./sql/schema.postgresql.sql:/docker-entrypoint-initdb.d/schema.postgresql.sql:ro
      - ./umami-db-data:/var/lib/postgresql/data
    restart: always
</code></pre>



<pre class="wp-block-code"><code>docker-compose up -d
</code></pre>



<pre class="wp-block-preformatted">访问http://ip:3000就可以访问了，打开的是英文界面，右上方可以切换语言，默认用户名为admin，密码为umami</pre>



<h2 class="wp-block-heading">迁移到另外一台服务器（2024年2月21日）</h2>



<p class="wp-block-paragraph">将安装目录的所有文件打包发送(打包发送速度会快很多，可以使用xftp两台服务器对拷)到新服务器，主要是上文docker-compose.yaml中的挂载的目录。</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">tar 压缩和解压命令</p>
<cite>1.tar 命令压缩<br>tar -cvf test.tar 1.txt 2.txt 3.txt<br>将1.txt 2.txt 3.txt 压缩到test.tar文件内<br>2.tar 解压<br>tar -xvf test.tar<br>解压test.tar，将文件解压至当前目录<br>tar -xvf test.tar -C /home/itheima<br>解压test.tar，将文件解压至指定目录（/home/itheima）</cite></blockquote>



<p class="wp-block-paragraph">docker 容器打包成镜像及在新服务器导入方法：</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="616" src="https://daoker.cc/wp-content/uploads/2024/02/image-13-1024x616.png" alt="" class="wp-image-1247" srcset="https://daoker.cc/wp-content/uploads/2024/02/image-13-1024x616.png 1024w, https://daoker.cc/wp-content/uploads/2024/02/image-13-300x180.png 300w, https://daoker.cc/wp-content/uploads/2024/02/image-13-768x462.png 768w, https://daoker.cc/wp-content/uploads/2024/02/image-13.png 1056w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">完成上述步骤后更改ymal文件中的镜像名为导入的镜像名然后就可以构建了。</p>
]]></content:encoded>
					
					<wfw:commentRss>https://daoker.cc/daokerto904.html/feed</wfw:commentRss>
			<slash:comments>35</slash:comments>
		
		
			</item>
		<item>
		<title>frp内网穿透和ZeroTier内网穿透</title>
		<link>https://daoker.cc/daokerto407.html</link>
					<comments>https://daoker.cc/daokerto407.html#comments</comments>
		
		<dc:creator><![CDATA[博主]]></dc:creator>
		<pubDate>Mon, 12 Sep 2022 07:08:38 +0000</pubDate>
				<category><![CDATA[未分类]]></category>
		<guid isPermaLink="false">https://daoker.cc/?p=407</guid>

					<description><![CDATA[frp内网穿 打算试一试把域名解析到我的树莓派软路由上，正好用的openwrt上有frp插件，于是查了下使用方 [&#8230;]]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">frp内网穿</h2>



<p class="wp-block-paragraph">打算试一试把域名解析到我的树莓派软路由上，正好用的openwrt上有frp插件，于是查了下使用方法。由于我所以的VPS都安装了宝塔面板或者NPM，唯一一台没装的又在洛杉矶，延迟较高，所以就把甲骨文新加坡的其中一台2c12g降低配置，然后再新建一台，重置好debian后开始整活。</p>



<div class="wp-block-argon-github github-info-card card shadow-sm github-info-card-full" data-author="fatedier" data-project="frp"><div class="github-info-card-header"><a href="https://github.com/" target="_blank" title="Github" rel="noopener"><span><i class="fa fa-github"></i> GitHub</span></a></div><div class="github-info-card-body"><div class="github-info-card-name-a"><a href="https://github.com/fatedier/frp" target="_blank" rel="noopener"><span class="github-info-card-name">fatedier/frp</span></a></div><div class="github-info-card-description"></div></div><div class="github-info-card-bottom"><span class="github-info-card-meta github-info-card-meta-stars"><i class="fa fa-star"></i> <span class="github-info-card-stars"></span></span><span class="github-info-card-meta github-info-card-meta-forks"><i class="fa fa-code-fork"></i> <span class="github-info-card-forks"></span></span></div></div>



<h3 class="wp-block-heading">服务端</h3>



<p class="wp-block-paragraph">下载arm64版本的包到服务器上，然后参考官网的文档，修改 frps.ini 文件，设置监听 HTTP 请求端口为 8080：</p>



<pre class="wp-block-code"><code>&#91;common]
bind_port = 7000
vhost_http_port = 8080</code></pre>



<p class="wp-block-paragraph">然后通过<code>./frps -c ./frps.ini</code>&nbsp;启动服务端，这里可以采用</p>



<pre class="wp-block-code"><code>nohup /root/frp/frps -c /root/frp/frps.ini &gt;&gt; /root/frp/log_frps.txt 2&gt;&amp;1 &amp;</code></pre>



<p class="wp-block-paragraph">将服务挂载到后台</p>



<p class="wp-block-paragraph">使用docker部署并且带web监控界面参考：<a href="https://iwanlab.com/frp-with-nginx-proxy-manager/">【好玩儿的Docker项目】家里没有公网IP？FRP+NPM+VPS = 随时随地用域名访问家里的任何设备！内网穿透，从未如此简单！ | 爱玩实验室 (iwanlab.com)</a></p>



<h3 class="wp-block-heading">客户端</h3>



<p class="wp-block-paragraph">参考教程：https://blog.laoda.de/archives/frp-with-nginx-proxy-manager</p>



<p class="wp-block-paragraph">由于openwrt自带的frp内网穿透插件功能较少,所以此处采用在docker中安装frpc的办法。</p>



<p class="wp-block-paragraph">首先在客户机上创建frpc.ini文件</p>



<pre class="wp-block-code"><code>mkdir -p /docker/frp

cd /docker/frp

vim ./frpc.ini 
</code></pre>



<p class="wp-block-paragraph">在其中输入如下配置信息</p>



<pre class="wp-block-code"><code># frpc.ini
&#91;common]
server_addr = 43.132.202.152  
server_port = 5443             
token = 8ad3d1x429a2d          

&#91;router]                      
type = tcp
local_ip = 127.0.0.1
local_port = 80
remote_port = 6005
</code></pre>



<p class="wp-block-paragraph">其中server_addr 为远程服务器地址，server_port 为远程端口 </p>



<p class="wp-block-paragraph">最后，部署容器</p>



<pre class="wp-block-code"><code>docker run --restart=always --network host -d --privileged=true -v /docker/frp/frpc.ini:/etc/frp/frpc.ini --name frpc snowdreamtech/frpc</code></pre>



<p class="wp-block-paragraph">然后在服务端把域名申请ssl后反代到对应的端口即可</p>



<figure class="wp-block-image size-full"><img decoding="async" width="655" height="478" src="http://daoker.cc/wp-content/uploads/2022/10/image-5.png" alt="" class="wp-image-520" srcset="https://daoker.cc/wp-content/uploads/2022/10/image-5.png 655w, https://daoker.cc/wp-content/uploads/2022/10/image-5-300x219.png 300w" sizes="(max-width: 655px) 100vw, 655px" /></figure>



<h2 class="wp-block-heading">ZeroTier内网穿透</h2>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">参考来源</p>
<cite>https://blog.csdn.net/qq_39300041/article/details/126645375<br>https://blog.csdn.net/COCO56/article/details/123296985<br></cite></blockquote>



<h3 class="wp-block-heading">openwrt加入zerotier</h3>



<p class="wp-block-paragraph">1.首先在本地加入申请的zerotier网络</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="385" src="http://daoker.cc/wp-content/uploads/2022/11/image-2-1024x385.png" alt="" class="wp-image-605" srcset="https://daoker.cc/wp-content/uploads/2022/11/image-2-1024x385.png 1024w, https://daoker.cc/wp-content/uploads/2022/11/image-2-300x113.png 300w, https://daoker.cc/wp-content/uploads/2022/11/image-2-768x289.png 768w, https://daoker.cc/wp-content/uploads/2022/11/image-2-1536x578.png 1536w, https://daoker.cc/wp-content/uploads/2022/11/image-2.png 1920w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">2.在zerotier的网络中授权刚才加入的设备，并做如下设置</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="468" src="http://daoker.cc/wp-content/uploads/2022/11/image-3-1024x468.png" alt="" class="wp-image-607" srcset="https://daoker.cc/wp-content/uploads/2022/11/image-3-1024x468.png 1024w, https://daoker.cc/wp-content/uploads/2022/11/image-3-300x137.png 300w, https://daoker.cc/wp-content/uploads/2022/11/image-3-768x351.png 768w, https://daoker.cc/wp-content/uploads/2022/11/image-3-1536x702.png 1536w, https://daoker.cc/wp-content/uploads/2022/11/image-3.png 1903w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="477" src="http://daoker.cc/wp-content/uploads/2022/11/image-4-1024x477.png" alt="" class="wp-image-608" srcset="https://daoker.cc/wp-content/uploads/2022/11/image-4-1024x477.png 1024w, https://daoker.cc/wp-content/uploads/2022/11/image-4-300x140.png 300w, https://daoker.cc/wp-content/uploads/2022/11/image-4-768x358.png 768w, https://daoker.cc/wp-content/uploads/2022/11/image-4-1536x716.png 1536w, https://daoker.cc/wp-content/uploads/2022/11/image-4.png 1920w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">3.在openwrt中添加接口</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="461" src="http://daoker.cc/wp-content/uploads/2022/11/image-5-1024x461.png" alt="" class="wp-image-609" srcset="https://daoker.cc/wp-content/uploads/2022/11/image-5-1024x461.png 1024w, https://daoker.cc/wp-content/uploads/2022/11/image-5-300x135.png 300w, https://daoker.cc/wp-content/uploads/2022/11/image-5-768x346.png 768w, https://daoker.cc/wp-content/uploads/2022/11/image-5-1536x692.png 1536w, https://daoker.cc/wp-content/uploads/2022/11/image-5.png 1690w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">4.设置防火墙：入站允许，出站允许，转发允许；对当前接口防火墙进行修改，将【端口触发】全部切换到Lan中</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="535" src="http://daoker.cc/wp-content/uploads/2022/11/image-6-1024x535.png" alt="" class="wp-image-610" srcset="https://daoker.cc/wp-content/uploads/2022/11/image-6-1024x535.png 1024w, https://daoker.cc/wp-content/uploads/2022/11/image-6-300x157.png 300w, https://daoker.cc/wp-content/uploads/2022/11/image-6-768x401.png 768w, https://daoker.cc/wp-content/uploads/2022/11/image-6-1536x802.png 1536w, https://daoker.cc/wp-content/uploads/2022/11/image-6.png 1920w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="538" src="http://daoker.cc/wp-content/uploads/2022/11/image-7-1024x538.png" alt="" class="wp-image-611" srcset="https://daoker.cc/wp-content/uploads/2022/11/image-7-1024x538.png 1024w, https://daoker.cc/wp-content/uploads/2022/11/image-7-300x158.png 300w, https://daoker.cc/wp-content/uploads/2022/11/image-7-768x403.png 768w, https://daoker.cc/wp-content/uploads/2022/11/image-7-1536x806.png 1536w, https://daoker.cc/wp-content/uploads/2022/11/image-7.png 1920w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">5.最后我们需要进入到防火墙自定义规则中，添加以下规则</p>



<pre class="wp-block-code"><code>iptables -I FORWARD -i ztrta3lbl3 -j ACCEPT<br>iptables -I FORWARD -o ztrta3lbl3 -j ACCEPT<br>iptables -t nat -I POSTROUTING -o ztrta3lbl3 -j MASQUERADE</code></pre>



<h3 class="wp-block-heading">其他系统加入zerotier</h3>



<p class="wp-block-paragraph">下载：</p>



<pre class="wp-block-code"><code>curl -s https://install.zerotier.com | sudo bash</code></pre>



<p class="wp-block-paragraph">加入网络：</p>



<pre class="wp-block-code"><code>zerotier-cli join 8286ac0e47198b3c</code></pre>



<p class="wp-block-paragraph">开机自启动：</p>



<pre class="wp-block-code"><code>systemctl enable zerotier-one.service</code></pre>



<h3 class="wp-block-heading">更换zerotier地址</h3>



<p class="wp-block-paragraph">有的时候，由于种种原因，zerotier不正常，但是卸载重装地址不变，其实是没有删除配置文件</p>



<pre class="wp-block-code"><code>sudo apt remove zerotier-one</code></pre>



<pre class="wp-block-code"><code>sudo rm -rf /var/lib/zerotier-one/</code></pre>



<p class="wp-block-paragraph">然后再执行上面的安装命令</p>



<h2 class="wp-block-heading">黑群晖 安装 zerotier-docker,实现外网访问家里的NAS</h2>



<p class="wp-block-paragraph">1.在黑群晖docker注册表中拉取zerotier/zerotier-synology镜像</p>



<p class="wp-block-paragraph">2.双击镜像创建一个容器，记得给予高级权限，网络类型和docker hub一样，并映射一个目录/var/lib/zerotier-one</p>



<p class="wp-block-paragraph">3.开启ssh访问群晖</p>



<p class="wp-block-paragraph">4.创建 tun 模块</p>



<ul class="wp-block-list">
<li>检查是否安装了&nbsp;<code>tun</code>&nbsp;模块：</li>
</ul>



<pre class="wp-block-code"><code>lsmod | grep tun
</code></pre>



<ul class="wp-block-list">
<li>如果结果为空，请尝试安装它：</li>
</ul>



<pre class="wp-block-code"><code>insmod /lib/modules/tun.ko
</code></pre>



<ul class="wp-block-list">
<li>查看 TUN 的运行状态</li>
</ul>



<pre class="wp-block-code"><code>ls /dev/net/tun
</code></pre>



<p class="wp-block-paragraph">返回为 /dev/net/tun 即可</p>



<ul class="wp-block-list">
<li>再次查看 tun 是否安装完成</li>
</ul>



<pre class="wp-block-code"><code>lsmod | grep tun
</code></pre>



<p class="wp-block-paragraph">5.加入网络</p>



<pre class="wp-block-code"><code>docker exec -it 容器名称 zerotier-cli join 网络id
</code></pre>



<p class="wp-block-paragraph">6.开启IP转发</p>



<p class="wp-block-paragraph">在群晖系统&nbsp;<code>/etc/sysctl.conf</code>&nbsp;中增加</p>



<pre class="wp-block-code"><code>net.ipv4.ip_forward=1
net.ipv6.conf.all.forwarding=1
</code></pre>



<p class="wp-block-paragraph">ipV6按需添加</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><a href="https://blog.csdn.net/m0_63314361/article/details/131326719?utm_medium=distribute.pc_relevant.none-task-blog-2~default~baidujs_baidulandingword~default-4-131326719-blog-115684928.235^v38^pc_relevant_anti_vip&amp;spm=1001.2101.3001.4242.3&amp;utm_relevant_index=7">黑/白群晖 安装 zerotier-docker 完美版_docker安装zerotier_AYing丶L灬小绵羊的博客-CSDN博客</a></p>
</blockquote>
]]></content:encoded>
					
					<wfw:commentRss>https://daoker.cc/daokerto407.html/feed</wfw:commentRss>
			<slash:comments>37</slash:comments>
		
		
			</item>
		<item>
		<title>【AI翻唱】从So-VITS-SVC到DDSP-SVC 3.0（小显存，旧显卡福音） </title>
		<link>https://daoker.cc/jhjto1114.html</link>
					<comments>https://daoker.cc/jhjto1114.html#respond</comments>
		
		<dc:creator><![CDATA[小编]]></dc:creator>
		<pubDate>Tue, 20 Jun 2023 02:45:24 +0000</pubDate>
				<category><![CDATA[未分类]]></category>
		<guid isPermaLink="false">https://daoker.cc/?p=1114</guid>

					<description><![CDATA[原本看了零度的视频，觉得&#160;So-VITS-SVC真牛，于是趁这段时间比较空闲，打算部署一个，用自己的 [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">原本看了零度的视频，觉得&nbsp;So-VITS-SVC真牛，于是趁这段时间比较空闲，打算部署一个，用自己的声音作为训练，然后翻唱歌曲。然而发觉我的GTX 960 4G 版根本跑不动So-VITS-SVC，于是在网上找到了替代的DDSP-SVC 3.0。</p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
					<wfw:commentRss>https://daoker.cc/jhjto1114.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>github工作流</title>
		<link>https://daoker.cc/daokerto734.html</link>
					<comments>https://daoker.cc/daokerto734.html#comments</comments>
		
		<dc:creator><![CDATA[博主]]></dc:creator>
		<pubDate>Fri, 25 Nov 2022 03:45:53 +0000</pubDate>
				<category><![CDATA[未分类]]></category>
		<guid isPermaLink="false">https://daoker.cc/?p=734</guid>

					<description><![CDATA[最近发觉自己很多代码都存在本地，时间久了就忘了，或者硬盘坏了丢失了都有可能，最关键的是版本控制很不，打算学习下 [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">最近发觉自己很多代码都存在本地，时间久了就忘了，或者硬盘坏了丢失了都有可能，最关键的是版本控制很不，打算学习下github仓库发布更新的方法。</p>



<iframe src="//player.bilibili.com/player.html?aid=561005338&#038;bvid=BV19e4y1q7JJ&#038;cid=846391446&#038;page=1" scrolling="no" border="0" frameborder="no" framespacing="0" allowfullscreen="true" style="width: 100%; height: 500px; max-width: 100%；align:center; padding:20px 0;" > </iframe>



<pre class="wp-block-code"><code>1.git clone // 到本地
2.git checkout -b xxx 切换至新分支xxx
（相当于复制了remote的仓库到本地的xxx分支上
3.修改或者添加本地代码（部署在硬盘的源文件上）
4.git diff 查看自己对代码做出的改变
5.git add 上传更新后的代码至暂存区
6.git commit 可以将暂存区里更新后的代码更新到本地git
7.git push origin xxx 将本地的xxxgit分支上传至github上的git
-----------------------------------------------------------
（如果在写自己的代码过程中发现远端GitHub上代码出现改变）
1.git checkout main 切换回main分支
2.git pull origin master(main) 将远端修改过的代码再更新到本地
3.git checkout xxx 回到xxx分支
4.git rebase main 我在xxx分支上，先把main移过来，然后根据我的commit来修改成新的内容
（中途可能会出现，rebase conflict -----》手动选择保留哪段代码）
5.git push -f origin xxx 把rebase后并且更新过的代码再push到远端github上
（-f ---》强行）
6.原项目主人采用pull request 中的 squash and merge 合并所有不同的commit
----------------------------------------------------------------------------------------------
远端完成更新后
1.git branch -d xxx 删除本地的git分支
2.git pull origin master 再把远端的最新代码拉至本地</code></pre>
]]></content:encoded>
					
					<wfw:commentRss>https://daoker.cc/daokerto734.html/feed</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
	</channel>
</rss>
