Skip to content

NullVPN 1.2.0

Choose a tag to compare

@snarefps snarefps released this 22 Sep 18:30
· 6 commits to main since this release
fa5e4bd
NullVPN

NullVPN 1.2.0

Psiphon joins the free tunnel, and TUN mode gets a real kill switch. On Windows, Android and Linux.

English · فارسی پایین تر


🇬🇧 English

✨ Highlights

  • 🌐 Psiphon inside Aether. The free tunnel can now carry Psiphon, ride on top of it, or use Psiphon alone and you pick the country it leaves from.
  • 🛡️ Strict route, IPv6 and MTU on every platform. With Strict route on, sites never see your real IP now even while NullVPN is reconnecting.
  • 🔌 TUN connects the first time. Fixed on Windows: after a crash, a forced close or a reboot, the first TUN connect often showed no location and no ping until you reconnected.

🆕 New

  • Aether updated to 2.1.0, with its new options in the Aether profile editor:
    • Psiphon: WARP, then Psiphon, Psiphon, then WARP, or Psiphon only. Nothing to set up it works on a fresh install.
    • Psiphon exit country a list of the 23 countries Psiphon has exits in and How Psiphon connects: Automatic, CDN fronting only (for networks that block the rest), or Direct only.
    • Allowed exit countries for WARP, e.g. !IR,RU to refuse those or DE,SE to accept only those. Checked when the tunnel comes up and every minute after.
    • Tor relays as bridges Tor can use thousands of public relays as bridges, not only the few that get blocked early. On a network that blocks Tor, bridges are now fetched through the tunnel.
    • Log traffic stats how much went up and down, once a minute.
    • Tor and Psiphon are one or the other; choosing one turns the other off.
  • TUN settings on every platform (Settings → TUN):
    • MTU lower it (e.g. 1400) if pages start loading and then stall.
    • IPv6 send IPv6 through the tunnel too.
    • Strict route block what the tunnel can't carry instead of letting it go around.
  • The Aether server card now shows the whole chain, e.g. MASQUE (QUIC) + Psiphon (DE) or Tor + MASQUE (TCP).

🔧 Improved

  • Strict route is a real kill switch. While NullVPN reconnects after an engine stops, or when you move to another network other apps are held back instead of going out on your real connection (Windows and Linux).
  • Strict route on Windows now blocks DNS lookups outside the tunnel and IPv6 in both directions. The filters vanish the moment NullVPN closes or crashes, so nothing is left blocking your internet. A firewall rule left behind by 1.1.x is removed.
  • TUN on Windows no longer stalls after a few minutes with Strict route on. The server's address is looked up before the tunnel starts.
  • A tunnel that carries nothing is rebuilt once by itself, and one whose server stopped answering (for example because its address changed) reconnects on its own.
  • Follows the network. On Windows, IPv6 appearing or disappearing rebuilds the tunnel to match. On Linux, a switch between Wi-Fi and Ethernet keeps the Aether helper outside the tunnel.
  • Leak fixes:
    • Linux TUN no longer sends IPv6 outside the tunnel.
    • On Windows, 1.1.1.1 and 1.0.0.1 which browsers use for secure DNS no longer bypass the tunnel.
    • Private and regional names are answered by your network's own DNS without leaving the tunnel's rules.
  • Faster with Strict route: ping and the IP lookup no longer hang, and connecting in TUN mode on Windows takes noticeably fewer steps.
  • Server latency tests while TUN is connected now measure each server directly instead of through the one you're connected to.
  • Aether 2.1 fixes: the TCP (HTTP/2) scan finds an edge in about a second, and the firewall and gfw obfuscation profiles really work now.

🔒 Security

  • Allow LAN connections now lets other devices use the tunnel and nothing else: they can't reach this computer's own services or other private networks through it.
  • nullvpn:// links ask before importing anything.
  • Windows:
    • In TUN mode, the engines' settings are kept in a folder only administrators can change.
    • The installer always installs for all users, into Program Files.
  • Linux: in TUN mode, NullVPN never touches your files through links someone else could plant.
  • Subscriptions larger than 16 MB are refused, and pasted configs can no longer make the engine write log files to arbitrary places.

🐞 Fixed

  • Disconnecting stops Aether's helpers too on Windows the Psiphon helper kept running and the next connect failed.
  • Saves made in quick succession are no longer lost, and closing NullVPN no longer hangs on a save.
  • Auto-reconnect can no longer bring back an old connection after you've disconnected and picked another server.
  • Android: stopping while the tunnel was still starting could leave it half-running.

📦 Downloads

Platform File
Windows 10 / 11 (64-bit) NullVPN-windows-x64-setup.exe
Android 7.0+, most phones ⭐ NullVPN-android-arm64-v8a.apk
Android, older 32-bit phones NullVPN-android-armeabi-v7a.apk
Android, emulators and x86 tablets NullVPN-android-x86_64.apk
Linux Debian, Ubuntu, Mint ⭐ NullVPN-linux-amd64.deb
Linux Fedora, RHEL, openSUSE NullVPN-linux-x86_64.rpm
Linux any distribution, no install NullVPN-linux-x86_64.AppImage
Linux manual install NullVPN-linux-x64.tar.gz

Tip

Not sure which Android file to pick? Choose arm64-v8a. On Linux, pick the .deb for Debian, Ubuntu or Mint, and the .rpm for Fedora.

📝 Install notes

  • Windows: the installer isn't code-signed yet, so SmartScreen may show "Windows protected your PC". Click More info → Run anyway. It needs administrator rights, since it installs for all users. Windows 7 and 8 are not supported.
  • Android: Google Play Protect may say it hasn't scanned the app yet. Tap Scan, or More info → Install. Both are fine.
  • TUN mode on Windows needs NullVPN to be run as Administrator that is what lets it create the network adapter.
  • With Strict route on, apps have no internet for the few seconds NullVPN takes to reconnect. That is on purpose: it's what keeps your real IP hidden.
  • Updating keeps your servers, subscriptions and settings.

🐧 Linux: install and uninstall

Needs Debian 12, Ubuntu 22.04, Linux Mint 21, Fedora 35, RHEL 9 or newer.

Debian, Ubuntu, Mint .deb

# install
sudo apt install ./NullVPN-linux-amd64.deb

# uninstall
sudo apt remove nullvpn

Fedora, RHEL, openSUSE .rpm

# install
sudo dnf install ./NullVPN-linux-x86_64.rpm      # openSUSE: sudo zypper install ./NullVPN-linux-x86_64.rpm

# uninstall
sudo dnf remove nullvpn                          # openSUSE: sudo zypper remove nullvpn

Any distribution AppImage (no install; needs FUSE, which most desktops already have)

# run
chmod +x NullVPN-linux-x86_64.AppImage
./NullVPN-linux-x86_64.AppImage

# TUN mode
sudo -E ./NullVPN-linux-x86_64.AppImage

# uninstall: delete the file, then its menu entry and icon
rm NullVPN-linux-x86_64.AppImage
rm -f ~/.local/share/applications/nullvpn.desktop ~/.local/share/icons/hicolor/256x256/apps/nullvpn.png

Manual install .tar.gz (installs to /opt/nullvpn)

# install
tar -xzf NullVPN-linux-x64.tar.gz
cd NullVPN-1.2.0-x64
sudo ./install.sh

# uninstall  works even after the unpacked folder is deleted
sudo /opt/nullvpn/uninstall.sh

No root? ./install.sh --user installs into your home folder instead; remove it with ~/.local/share/nullvpn/uninstall.sh --user. A per-user install has no TUN menu entry.

TUN mode: with the .deb, .rpm or .tar.gz, open NullVPN (TUN) from the menu no password needed. Close the normal NullVPN window first; only one copy runs at a time.

Uninstalling keeps your servers and settings. To remove those as well:

rm -rf ~/.local/share/com.nullvpn

🇮🇷 فارسی

✨ مهم ترین تغییرات

  • 🌐 Psiphon داخل Aether. تانل رایگان حالا میتونه Psiphon رو از داخل خودش رد کنه، روی Psiphon سوار بشه، یا فقط Psiphon باشه و خودت کشور خروجیش رو انتخاب میکنی.
  • 🛡️ Strict route و IPv6 و MTU روی همه پلتفرم ها. با روشن بودن Strict route سایت ها هیچ وقت IP واقعیت رو نمیبینن حالا حتی وقتی NullVPN داره دوباره وصل میشه.
  • 🔌 حالت TUN از بار اول وصل میشه. روی ویندوز درست شد: بعد از کرش، بستن اجباری یا ری استارت، اولین اتصال TUN خیلی وقت ها نه لوکیشن نشون میداد نه پینگ، تا وقتی دوباره وصل میشدی.

🆕 جدید

  • Aether به 2.1.0 آپدیت شد و گزینه های جدیدش توی ویرایش پروفایل Aether اومده:
    • Psiphon: اول WARP، بعد Psiphon، اول Psiphon، بعد WARP یا فقط Psiphon. تنظیم خاصی نمیخواد روی نصب تازه هم کار میکنه.
    • کشور خروجی Psiphon لیست ۲۳ کشوری که Psiphon توشون خروجی داره و روش اتصال Psiphon: خودکار، فقط از طریق CDN (برای شبکه هایی که بقیه راه ها رو بستن)، یا فقط مستقیم.
    • کشورهای خروجی مجاز برای WARP، مثلاً !IR,RU برای رد کردن این ها یا DE,SE که فقط همین ها قبول بشن. موقع بالا اومدن تانل و بعدش هر دقیقه چک میشه.
    • رله های Tor به عنوان پل Tor میتونه هزاران رله عمومی رو به عنوان پل استفاده کنه، نه فقط اون چندتایی که زود بسته میشن. روی شبکه ای که Tor رو بسته، پل ها حالا از داخل تانل گرفته میشن.
    • ثبت آمار ترافیک در لاگ چقدر آپلود و دانلود شده، هر دقیقه یه بار.
    • Tor و Psiphon با هم کار نمیکنن؛ انتخاب یکی، اون یکی رو خاموش میکنه.
  • تنظیمات TUN روی همه پلتفرم ها (تنظیمات ← TUN):
    • MTU اگه صفحه ها شروع به لود میکنن و بعد گیر میکنن، کمش کن (مثلاً ۱۴۰۰).
    • IPv6 ترافیک IPv6 هم از تانل رد بشه.
    • Strict route چیزی که تانل نمیتونه ببره بلاک بشه، نه اینکه از کنار تانل رد بشه.
  • کارت سرور Aether حالا کل زنجیره رو نشون میده، مثلاً MASQUE (QUIC) + Psiphon (DE) یا Tor + MASQUE (TCP).

🔧 بهبودها

  • Strict route یه کیل سوییچ واقعیه. وقتی NullVPN داره دوباره وصل میشه بعد از اینکه یه هسته متوقف شد یا وقتی شبکه عوض میشه بقیه برنامه ها نگه داشته میشن و با اتصال واقعیت بیرون نمیرن (ویندوز و لینوکس).
  • Strict route روی ویندوز حالا DNS بیرون از تانل و IPv6 رو در هر دو جهت بلاک میکنه. این فیلترها به محض بسته شدن یا کرش NullVPN از بین میرن، پس چیزی باقی نمیمونه که اینترنتت رو ببنده. قانون فایروالی هم که از نسخه 1.1.x مونده بود پاک میشه.
  • TUN روی ویندوز با Strict route دیگه بعد از چند دقیقه قطع نمیشه. آدرس سرور قبل از شروع تانل پیدا میشه.
  • تانلی که هیچ ترافیکی رد نمیکنه یه بار خودش از نو ساخته میشه، و وقتی سرور جواب نمیده (مثلاً چون آدرسش عوض شده) خودش دوباره وصل میشه.
  • همراه شبکه تغییر میکنه. روی ویندوز، اومدن یا رفتن IPv6 تانل رو متناسبش از نو میسازه. روی لینوکس، جابجایی بین وای فای و کابل، Aether رو بیرون از تانل نگه میداره.
  • رفع نشتی ها:
    • TUN روی لینوکس دیگه IPv6 رو بیرون از تانل نمیفرسته.
    • روی ویندوز 1.1.1.1 و 1.0.0.1 که مرورگرها برای DNS امن استفاده میکنن دیگه از کنار تانل رد نمیشن.
    • اسم های داخلی و منطقه ای با DNS خود شبکه ات جواب داده میشن، بدون اینکه از قوانین تانل بیرون بزنن.
  • سریع تر با Strict route: پینگ و پیدا کردن IP دیگه گیر نمیکنن و اتصال حالت TUN روی ویندوز مراحل خیلی کمتری داره.
  • تست پینگ سرورها موقع اتصال TUN حالا هر سرور رو مستقیم میسنجه، نه از داخل سروری که بهش وصلی.
  • رفع مشکلات Aether 2.1: اسکن TCP (HTTP/2) حدود یه ثانیه ای یه سرور پیدا میکنه و پروفایل های مبهم سازی firewall و gfw حالا واقعاً کار میکنن.

🔒 امنیت

  • Allow LAN connections حالا فقط اجازه میده بقیه دستگاه ها از تانل استفاده کنن و بس: از طریقش نمیتونن به سرویس های خود این کامپیوتر یا بقیه شبکه های خصوصی برسن.
  • لینک های nullvpn:// قبل از وارد کردن هر چیزی سوال میپرسن.
  • ویندوز:
    • توی حالت TUN، تنظیمات هسته ها توی پوشه ای نگه داشته میشه که فقط ادمین میتونه تغییرش بده.
    • فایل نصب همیشه برای همه کاربرها و توی Program Files نصب میکنه.
  • لینوکس: توی حالت TUN، NullVPN هیچ وقت از طریق لینک هایی که کس دیگه ای ممکنه گذاشته باشه به فایل هات دست نمیزنه.
  • اشتراک های بزرگ تر از ۱۶ مگابایت قبول نمیشن، و کانفیگ های دستی دیگه نمیتونن هسته رو وادار کنن هر جایی فایل لاگ بنویسه.

🐞 رفع باگ ها

  • با قطع اتصال، کمک رسان های Aether هم بسته میشن روی ویندوز Psiphon در حال اجرا میموند و اتصال بعدی خطا میداد.
  • ذخیره هایی که پشت سر هم انجام میشن دیگه گم نمیشن، و بستن NullVPN دیگه موقع ذخیره گیر نمیکنه.
  • اتصال مجدد خودکار دیگه نمیتونه بعد از اینکه قطع کردی و سرور دیگه ای انتخاب کردی، اتصال قبلی رو برگردونه.
  • اندروید: توقف وقتی تانل هنوز داشت شروع میشد، میتونست نیمه کاره روشن نگهش داره.

📦 دانلود

پلتفرم فایل
ویندوز ۱۰ و ۱۱ (۶۴ بیتی) NullVPN-windows-x64-setup.exe
اندروید ۷ به بالا، بیشتر گوشی ها ⭐ NullVPN-android-arm64-v8a.apk
اندروید، گوشی های قدیمی ۳۲ بیتی NullVPN-android-armeabi-v7a.apk
اندروید، شبیه ساز و تبلت x86 NullVPN-android-x86_64.apk
لینوکس دبیان، اوبونتو، مینت ⭐ NullVPN-linux-amd64.deb
لینوکس فدورا، RHEL، اوپن سوزه NullVPN-linux-x86_64.rpm
لینوکس هر توزیعی، بدون نصب NullVPN-linux-x86_64.AppImage
لینوکس نصب دستی NullVPN-linux-x64.tar.gz

[!TIP]
نمیدونی کدوم فایل اندروید رو بگیری؟ arm64-v8a رو بگیر. روی لینوکس، برای دبیان و اوبونتو و مینت .deb و برای فدورا .rpm رو بگیر.

📝 نکته های نصب

  • ویندوز: فایل نصب هنوز امضای دیجیتال نداره، برای همین ممکنه SmartScreen پیام «Windows protected your PC» نشون بده. روی More info و بعد Run anyway بزن. چون برای همه کاربرها نصب میکنه، دسترسی ادمین میخواد. ویندوز ۷ و ۸ پشتیبانی نمیشن.
  • اندروید: ممکنه Google Play Protect بگه برنامه هنوز اسکن نشده. Scan رو بزن، یا روی More info و بعد Install بزن. هر دوش اوکیه.
  • حالت TUN توی ویندوز باید NullVPN رو Run as Administrator اجرا کنی؛ همین اجازه ساختن کارت شبکه رو میده.
  • با روشن بودن Strict route، برنامه ها برای چند ثانیه ای که NullVPN داره دوباره وصل میشه اینترنت ندارن. این عمدیه: همین IP واقعیت رو مخفی نگه میداره.
  • با آپدیت، سرورها و اشتراک ها و تنظیماتت سر جاشون میمونن.

🐧 لینوکس: نصب و حذف

پیش نیاز: دبیان ۱۲، اوبونتو ۲۲.۰۴، لینوکس مینت ۲۱، فدورا ۳۵، RHEL 9 یا جدیدتر.

دبیان، اوبونتو، مینت .deb

# install
sudo apt install ./NullVPN-linux-amd64.deb

# uninstall
sudo apt remove nullvpn

فدورا، RHEL، اوپن سوزه .rpm

# install
sudo dnf install ./NullVPN-linux-x86_64.rpm      # openSUSE: sudo zypper install ./NullVPN-linux-x86_64.rpm

# uninstall
sudo dnf remove nullvpn                          # openSUSE: sudo zypper remove nullvpn

هر توزیعی AppImage (نصب نمیخواد؛ به FUSE نیاز داره که بیشتر دسکتاپ ها دارن)

# run
chmod +x NullVPN-linux-x86_64.AppImage
./NullVPN-linux-x86_64.AppImage

# TUN mode
sudo -E ./NullVPN-linux-x86_64.AppImage

# uninstall: delete the file, then its menu entry and icon
rm NullVPN-linux-x86_64.AppImage
rm -f ~/.local/share/applications/nullvpn.desktop ~/.local/share/icons/hicolor/256x256/apps/nullvpn.png

نصب دستی .tar.gz (توی /opt/nullvpn نصب میشه)

# install
tar -xzf NullVPN-linux-x64.tar.gz
cd NullVPN-1.2.0-x64
sudo ./install.sh

# uninstall  works even after the unpacked folder is deleted
sudo /opt/nullvpn/uninstall.sh

دسترسی root نداری؟ با ./install.sh --user توی پوشه خودت نصب میشه و با ~/.local/share/nullvpn/uninstall.sh --user حذف میشه. نصب کاربری گزینه TUN توی منو نداره.

حالت TUN: با .deb یا .rpm یا .tar.gz، از منو NullVPN (TUN) رو باز کن؛ رمز نمیخواد. اول پنجره NullVPN معمولی رو ببند؛ همزمان فقط یکیش اجرا میشه.

با حذف برنامه، سرورها و تنظیماتت پاک نمیشن. اگه میخوای اونا هم پاک بشن:

rm -rf ~/.local/share/com.nullvpn

🔐 SHA-256 checksums
ec827fb62666af272887b06e6a9785007dab174383899fd8d4cdc1a389da1288  NullVPN-windows-x64-setup.exe
8007aa3301078be47c5c33546542bccfc51b4ea97ade954b214a1fabdc82ba69  NullVPN-android-arm64-v8a.apk
6366bb7a8568930ce5da44e30ad3da8559c7ef6f126629618195352c533e253e  NullVPN-android-armeabi-v7a.apk
438659d377e63ae24b90da7b049071c0944c407379d52c3177e8e2494b33c909  NullVPN-android-x86_64.apk
b6b88bf2330eea534c634d22c1644e120e7b23f1a6078c856d02d0d7a1feb99f  NullVPN-linux-amd64.deb
a21b102514c51fc8510be5581f51c8feaf42986006f5e466e6bb889619682b68  NullVPN-linux-x86_64.rpm
a09463bbb0bb5595bf6aa80fd3a943fc2ad587c3a98a97bde5f63efb5b465212  NullVPN-linux-x86_64.AppImage
ce5c76d9041ab9df81b0437b3099772a9c26293553719a34b90e5269e230af56  NullVPN-linux-x64.tar.gz

Download only from this page or t.me/ZeroNullex. If a file's checksum doesn't match, don't install it.

💬 Telegram channel · 🐞 Report a bug

Made with ❤️ by ZeroNullex