
前几天在网上查到了 final shell ,试用感觉不错后就购买了 100+rmb 的专业版。接下来发现一个让我迷惑的地方,如下图: 
每分钟都有很多记录,我曾经用 Surge 把这个目标 ip 直接 reject ,但是还是不断的请求,有人知道它在做什么吗?
1 gra &nsp; Jun 11, 2022 真需要明白人解惑了 |
2 dcty Jun 11, 2022 Enable HTTP Capture, 然后看看内容是啥 |
3 zzgo88 OP surge http 抓包只有这些内容:@gra @dcty {"id":149576,"remoteAddress":"123.151.137.18","inMaxSpeed":0,"proxyMode":1,"interface":"en0","notes":["14:51:01.605585 Sub-rule matched: GEOIP CN","14:51:01.605665 Rule matched: RULE-SET China.list","14:51:01.606662 Connecting with address: 123.151.137.18","14:51:01.642911 Connected to address 123.151.137.18 in 36ms","14:51:01.643131 TCP connection established","14:51:01.643592 Disconnect with reason: Closed by client"],"inCurrentSpeed":0,"failed":0,"status":"Completed","outCurrentSpeed":0,"completed":1,"sourcePort":53795,"completedDate":1654930261.6436291,"outBytes":0,"sourceAddress":"127.0.0.1","localAddress":"192.168.1.101","policyName":"Direct","inBytes":0,"replicaDirectoryPath":"\/var\/folders\/jw\/bwt12vgs6vx6r35t7cjh3t240000gn\/T\/Surge Catpure\/2022-06-11-144659\/Requests\/149576 - 14.51.01 - SOCKS - 123.151.137.18%3A80","method":"SOCKS","pid":96496,"replica":1,"rule":"RULE-SET China.list","startDate":1654930261.603317,"setupCompletedDate":1654930261.6431708,"URL":"123.151.137.18:80","processPath":"\/Applications\/FinalShell.app\/Contents\/MacOS\/FinalShell","outMaxSpeed":0,"modified":0,"timingRecords":[{"durationInMillisecond":1,"name":"Rule Evaluating"},{"durationInMillisecond":36,"name":"Establishing TCP Connection"}]} |
4 dcty Jun 11, 2022 |
8 Ct5T66PVR1bW7b2z Jun 11, 2022 在一个群里看到,finalshell 的专业版解锁就是邮箱的 md5 |
10 XhstormR02 Jun 11, 2022 via Android 这个截图里的是什么监控软件 |
11 zzgo88 OP @XhstormR02 macos 上的 Surge 4 |
13 oldmanong Jun 11, 2022 via iPhone 对于这个闭源软件,因为用习惯了,所以只能预设它是善良的 |
14 kuls Jun 12, 2022 via iPhone 这个 ip 是自己主机?还是其他的,自己的主机可能是获取内存等信息状态 |