Repository navigation
v0.4.0
Important
Responsible use. Ghostline is provided for research and educational purposes. Its main goals are privacy (keeping DNS queries from being read or logged), protection against DNS spoofing and hijacking, and network diagnostics. You are solely responsible for how you use it and for complying with the laws of your country and your network provider's terms. Do not use Ghostline for any unlawful purpose, including:
- reaching websites, services or content that a competent authority has ordered to be blocked under the law of your country;
- online gambling, copyright infringement, fraud, or spreading content that is prohibited by law;
- attacking, disrupting or getting unauthorized access to any network or system.
Ghostline does not ship, recommend or maintain lists of sites blocked by authorities. Lists and rules you add yourself are your own responsibility. The software is provided "as is", without warranty of any kind; the authors are not liable for any damage, data loss, service disruption or legal consequences arising from its use. See the Disclaimer and LICENSE.
What's changed in 0.4.0
- DNS server for your browsers and other devices: a local DoH endpoint (
https://127.0.0.1/dns-query) for browsers on this PC, and, with share on the LAN, plain DNS on port 53 plus DoH on this PC's LAN addresses. Routers, TVs, Android phones and the Steam Deck only need this PC's IP as their DNS, no certificate. LAN sharing works only on networks marked Private; on Public networks aGhostline Block Publicfirewall rule keeps other devices out, even if you clicked Allow in Windows' firewall prompt. - iPhone / iPad DoH profile: enter your home Wi-Fi name (Ghostline suggests the networks this PC knows, or the phone types it on the page), open the phone setup page and scan the QR code. The page lives 10 minutes, shows the certificate fingerprint to compare, and walks through the required Full Trust step. The encrypted DNS is used only on that Wi-Fi; mobile data and other networks are untouched.
- Fake SNI (advanced, opt-in after a mandatory warning): for domains with an
sni=rule, the proxy decrypts the browser's HTTPS and reconnects with an allowed name (domain fronting), falling back to fragmentation when a server refuses. Only browsers on this PC through the proxy are affected; a violet banner shows while it runs, with counters on the Fake SNI page. A signed Google & YouTube preset group is included. - Scoped certificates only: the LAN CA can sign only private addresses and
*.ghostline.lan; the Fake SNI CA can sign only the domains in your rules, lives in RAM for the session and is removed on Disconnect, by the watchdog after a crash, and on uninstall. Settings → certificates lists every Ghostline certificate and removes them all. - Disconnect asks first (app and tray) when devices on your network used this PC's DNS in the last 10 minutes, because they lose the internet with it. Shutting Windows down and Quit do not ask.
- Rules:
sni=andconnect=actions; lists from other sources can carry them only after you mark them trust for Fake SNI. - zapret2 strategy list is now signed, so the daily update applies instead of failing the signature check.
- Guides, READMEs and the release checklist cover the DNS server, Fake SNI, certificates and the iPhone setup (EN + VI).
Note
Devices using this PC's DNS lose the internet when it is off or disconnected. iOS has no fallback: with the DoH profile, choose Automatic in Settings › General › VPN & Device Management › DNS (or remove the profile) to get the iPhone back online at home. If this PC is often off, set the iPhone's DNS manually (Wi-Fi › (i) › Configure DNS › Manual) instead of using the profile.
Warning
Antivirus. Windows Defender may flag Ghostline, zapret2 or WinDivert as malware by mistake (Trojan:Win32/Bearfoos.A!ml, Trojan:Win32/Suschil!rfn). If Ghostline is killed while connected, DNS can stay pointed at 127.0.0.1 until you open Ghostline again (it restores DNS on start). If this happens, add the Ghostline folder to Defender's exclusions.
Downloads
| File | What it is |
|---|---|
ghostline-amd64-installer.exe |
Installer (installs WebView2 if missing) |
Ghostline-0.4.0-portable.zip |
Portable: unzip and run |
SHA256SUMS |
Checksums for both |
Requires Windows 10/11 x64 and administrator rights. Builds are not code-signed yet: verify the SHA-256, then choose More info → Run anyway in SmartScreen.
Tuyên bố trách nhiệm (Tiếng Việt)
Ghostline được phát triển với mục đích nghiên cứu và học tập về DNS mã hoá, cơ chế lọc mạng và DPI. Mục tiêu chính là bảo vệ quyền riêng tư (truy vấn DNS không bị đọc hay ghi lại), chống giả mạo và chiếm quyền DNS, và chẩn đoán mạng. Người dùng tự chịu hoàn toàn trách nhiệm về cách sử dụng phần mềm, cũng như việc tuân thủ pháp luật nơi mình sinh sống và điều khoản của nhà cung cấp mạng. Không sử dụng Ghostline vào bất kỳ mục đích vi phạm pháp luật nào, bao gồm:
- truy cập trang web, dịch vụ hay nội dung mà cơ quan có thẩm quyền đã yêu cầu chặn theo quy định của pháp luật;
- cờ bạc trực tuyến, vi phạm bản quyền, lừa đảo, hoặc phát tán nội dung bị pháp luật cấm;
- tấn công, gây gián đoạn hoặc truy cập trái phép vào bất kỳ mạng hay hệ thống nào.
Ghostline không đóng gói, không khuyến nghị và không duy trì danh sách các trang bị cơ quan chức năng chặn. Danh sách và rule do người dùng tự thêm thuộc trách nhiệm của người dùng.
Phần mềm được cung cấp "nguyên trạng", không kèm bất kỳ bảo đảm nào. Tác giả không chịu trách nhiệm về bất kỳ thiệt hại, mất mát dữ liệu, gián đoạn dịch vụ hay hệ quả pháp lý nào phát sinh từ việc sử dụng phần mềm.
Full Changelog: v0.3.1...v0.4.0