# proxychains-ng: LD_PRELOAD Socket Hooking for SOCKS and HTTP Proxies

> proxychains-ng forces dynamically linked programs through SOCKS4a, SOCKS5 or HTTP proxies by preloading a library that hooks libc socket calls. It is a hack that works well on simple compiled binaries and fails on scripts, daemons and dlopen-heavy applications.

**rofl0r/proxychains-ng** — proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more socks/http proxies. continuation of the unmaintained proxychains project. the sf.net page is currently not updated, use releases from github release page instead.

- Repository: https://github.com/rofl0r/proxychains-ng
- Website: http://sourceforge.net/projects/proxychains-ng/files
- Stars: 10,683 · Forks: 1,114
- Language: C
- License: GPL-2.0
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/rofl0r-proxychains-ng

## What proxychains-ng does that a proxy setting cannot

Many programs have no proxy option. telnet is the README's own example. A program may speak a protocol whose client library ignores http_proxy, or it may open raw sockets to a hardcoded address. proxychains-ng exists for that gap: it is a preloaded library that intercepts network-related libc functions in a dynamically linked process and rewrites the destination so the connection travels through one or more SOCKS4a, SOCKS5 or HTTP proxies instead. The README lists the intended users plainly: people whose only route out of a LAN is a proxy, people behind a firewall that filters outgoing ports, people who want to chain two or more proxies, people who need DNS resolved behind the proxy, and people reaching Tor onion services. It is a continuation of the unmaintained proxychains project, and the README notes the SourceForge page is not updated, directing users to the GitHub release page instead.

## How the LD_PRELOAD hook actually redirects connections

The mechanism is a shared library, libproxychains4.so, injected with LD_PRELOAD. The Makefile builds it from src/core.c, src/libproxychains.o, src/rdns.o, src/hostsreader.o, src/allocator_thread.o and related objects, and the CFLAGS_MAIN definition passes the install-time libdir and sysconfdir into the main binary as -DLIB_DIR and -DSYSCONFDIR. When the target process calls connect(), getaddrinfo() or related functions, the preloaded definitions run first. Instead of dialing the address the program asked for, the library opens a connection to the proxy from the configured chain and performs the SOCKS or HTTP CONNECT handshake. DNS is the interesting part: the README describes remote DNS lookup replacing the old dnsresolver script that needed a dynamically linked dig binary, which is what makes .onion names work through Tor. The README is explicit that this is a hack, and names the failure cases: scripts, programs that start many processes such as background daemons, and programs that use dlopen() to load modules, where it points at a bug in the glibc dynamic linker. Simple compiled C or C++ dynamically linked programs are the case it is designed for. TCP only; UDP and ICMP are not supported.

## Installing proxychains-ng and running a first proxified command

The project builds with a plain Makefile and a configure script. The README says you need a working C compiler, preferably gcc, and gives this sequence. The configure invocation sets the install prefix and the configuration directory, which is what gets compiled into the binary as SYSCONFDIR.

## Where the preload trick breaks, and when to use something else

The README does not oversell this. It states that proxychains may not work with your program, especially when it is a script or when it starts numerous processes like background daemons, and that programs using dlopen() can hit a glibc dynamic linker bug. The changelog shows how much of the project's history is patching exactly these edges: close() was hooked in 4.5 because OpenSSH segfaulted when proxified, 4.7 changed the close hook to return EBADF instead of EINTR because chromium looped on retries, 4.17 added a hook for close_range to fix newer OpenSSH, and 4.16 fixed a double-close in multithreaded applications. Those are not incidental bugs; they are the cost of intercepting libc calls underneath a program that did not ask for it. The README's recommendation when your program does not work is an iptables-based solution, which it calls much more robust. UDP and ICMP traffic is out of scope entirely, so anything built on QUIC or raw ICMP will bypass the proxy. The README also carries a blunt warning that this software can be used to circumvent censorship, that doing so can be very dangerous in certain countries, and that you should always verify both the program and the proxy work as expected before using it for anything serious.

## proxychains-ng versus an iptables redirect

The real alternative is not another preload tool; it is a packet-level redirect. An iptables rule that sends outbound TCP to a local transparent proxy operates below the application, so it does not care whether the program is a script, a daemon, a statically linked binary or something that calls dlopen(). It also covers traffic from processes you did not launch through a wrapper. The trade-off runs the other way too. iptables rules need root, they are system-wide or per-uid rather than per-command, and they interact with routing and network namespaces in ways that are harder to reason about for a one-off task. proxychains-ng is per-invocation: you prefix one command, and only that process tree is affected. For a single interactive client on a machine where you can set LD_PRELOAD, that is a smaller blast radius. For a daemon, a container, or anything you cannot launch yourself, the iptables route is the one the README itself points to. A third option worth naming: many programs, including ssh and curl, have native proxy support that avoids the preload entirely and should be preferred when it exists.

## Maintenance, releases and the GPL-2.0 licence

The last push to the repository was on 2026-08-27, and the repository is not archived. The most recent tagged release is v4.17 from 2024-01-21, preceded by v4.16 in 2022 and v4.15 in 2021. That gap between commits and tags matters for planning: if you track releases, you are on code from early 2024, while fixes such as the close_range hook for newer OpenSSH landed in the 4.17 tag itself. The project is licensed GPL-2.0. For a tool you run as a preloaded library on your own machine, that is unremarkable. It becomes a consideration if you link the library into something you distribute, because GPL-2.0 carries obligations that a permissive licence does not; this is a description of the licence identifier in the repository, not legal advice, and you should read COPYING and talk to counsel if redistribution is on the table. Upgrading is cheap in the ordinary case: configure, make, make install, and re-run install-config if the shipped proxychains.conf changed. The risk in an upgrade is not the build, it is behavioural. A new hook or a changed close() return value can alter how an already-working program behaves, which is why the changelog entries about OpenSSH and chromium exist.

## Conclusion

Adopt proxychains-ng when you need to force a simple, dynamically linked binary through a SOCKS or HTTP proxy and you accept the LD_PRELOAD mechanism's limits: TCP only, no UDP or ICMP, and unreliable behaviour with scripts, background daemons and programs that call dlopen(). Do not adopt it as a system-wide transparent proxy; the README itself points to iptables-based solutions as more robust for that job. Before relying on it, verify the chain actually carries your traffic by connecting to an address-checking service such as ifconfig.me, and confirm the config file path your build installed, since the configure script sets sysconfdir and the README's example uses /etc.

## FAQ

### What is proxychains-ng used for?

It forces a dynamically linked program's TCP connections through one or more SOCKS4a, SOCKS5 or HTTP proxies by preloading a library with LD_PRELOAD. The README lists use cases such as getting out through a proxy-only LAN, escaping a firewall that filters outgoing ports, chaining proxies, resolving DNS behind the proxy, and reaching Tor onion services.

### Where is the proxychains-ng configuration file?

The configure script's --sysconfdir option determines where proxychains.conf is installed, and the README's example uses --sysconfdir=/etc. The install-config make target places the file there. You can also bypass the installed copy with the -f flag, as in the README's example that points at src/proxychains.conf in the build tree.

### How do I install proxychains-ng?

The README gives a four-step sequence: run ./configure --prefix=/usr --sysconfdir=/etc, then make, then sudo make install, then sudo make install-config to install proxychains.conf. It needs a working C compiler, preferably gcc, and you can skip installation entirely and run ./proxychains4 from the build directory with -f pointing at the source-tree config.

### proxychains-ng vs proxychains: what is the difference?

proxychains-ng is described in its README as a continuation of the unmaintained proxychains project. The README also states the SourceForge page is not updated and directs users to the GitHub release page for releases instead.

### Can I use proxychains-ng with Nmap?

The changelog for version 4.8 mentions a fix for a corner case where getaddrinfo was used with AI_NUMERICHOST to test for a numeric IP instead of resolving it, which it credits with fixing nmap. The README does not otherwise document Nmap usage, and Nmap's raw-packet scanning modes are outside the TCP-only scope the README describes.

## Sources

- [License: GPL-2.0](https://github.com/rofl0r/proxychains-ng/blob/master/LICENSE)
- [Project website](http://sourceforge.net/projects/proxychains-ng/files)
- [README](https://github.com/rofl0r/proxychains-ng/blob/master/README.md)
- [Releases](https://github.com/rofl0r/proxychains-ng/releases)
- [rofl0r/proxychains-ng on GitHub](https://github.com/rofl0r/proxychains-ng)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/rofl0r-proxychains-ng
