XX-Net: A Python Proxy for Bypassing the Great Firewall
A proxy tool to bypass GFW.
At a glance
- What is it?
- XX-Net is a Python-based proxy tool designed to help users in censored network environments access the open internet. It has been in continuous operation for over nine years according to its README, and its obfuscation strategy focuses on making traffic indistinguishable from ordinary web browsing rather than exploiting firewall weaknesses.
- Who is it for?
- XX-Net is a fit for users in censored network environments who want an open-source, no-installation proxy that runs on any major platform. It is not the right tool for users who need strong anonymity guarantees or a project with a published security audit, since neither is documented.
- Can I use it commercially?
- Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
- Is it still maintained?
- Yes. The repository last received commits 1 day ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The Problem XX-Net Solves
The Great Firewall of China (GFW) blocks access to many websites and services by analyzing outbound network traffic and blocking connections that match known patterns. XX-Net's approach, as described in its README, does not target weaknesses in the firewall itself. Instead it disguises outbound traffic so that it resembles ordinary HTTPS traffic and cannot be identified as a proxy connection.
The README summarizes this philosophy directly: rather than looking for holes in the firewall, the project aims to make its traffic completely indistinguishable from normal connections, hiding in the general mass of web traffic. This design choice reflects a long-term strategy rather than a reactive one, and the README credits the project with nine consecutive years of operation as evidence that the approach holds up.
Platform Support and Distribution
XX-Net runs on Android, iOS, Windows, macOS, and Linux. The README states it supports multiple devices connecting simultaneously and that it does not require installation, making it a portable tool that can run directly from its directory.
The repository structure reflects this multi-platform scope. The top-level directory contains start scripts for multiple operating systems: `start` and `xx_net.sh` for Unix-based systems, `start.bat` for Windows, and `start.vbs` as a Visual Basic script alternative on Windows. The `code/` directory contains the Python source, and `SwitchyOmega/` contains browser proxy configuration files.
A download link to the official website at xx-net.com is provided in the README, suggesting that most users obtain prebuilt packages there rather than cloning the repository directly.
Running XX-Net
The tool is portable: clone the repository or extract a downloaded package, then run the appropriate start script for your platform.
On Unix systems:
./xx_net.shOn Windows, double-clicking `start.bat` or `start.vbs` launches the application.
The Python dependencies listed in `requirements.txt` are pyOpenSSL, babel, jinja2, and googletrans 4.0.0-rc1. Installing them before running:
pip install -r requirements.txtThe README directs users with questions to the wiki documentation (linked from the GitHub page) rather than providing step-by-step setup instructions inline. A Telegram channel and a Twitter account are listed for announcements and community discussion.
Traffic Obfuscation Approach
The README describes the obfuscation mechanism at a high level: XX-Net simulates Chrome browser behavior so that its traffic appears identical to a real browser making HTTPS requests. The README states this approach makes the traffic completely unrecognizable to automated filtering systems.
This is a different model from VPN-style protocols such as WireGuard or OpenVPN, which create a distinct encrypted tunnel that can be fingerprinted. XX-Net instead masquerades as web browsing at the protocol level. The README does not document the specific technique in technical detail, referring users to the wiki for deeper explanation.
The project notes that all known firewall weaknesses are eventually patched, which is why the strategy focuses on traffic mimicry rather than exploit-based circumvention.
Built-in Features and Recent Changes
Version 5.1.0 added a built-in ChatGPT interface, which the README lists as a bundled feature. Each subscription package includes a million tokens of ChatGPT-3.5 according to the README. This suggests the project has moved beyond pure proxy functionality into a broader internet access and AI access platform.
The README changelog entries cover a span of updates: version 5.6.0 refactored code to reduce system resource consumption, version 5.7.0 added a new channel for X-Tunnel, version 5.8.8 improved iOS connection performance, version 5.9.0 upgraded the GAE server component to Python 3, and version 5.16.6 (released 2025-08-26) fixed minor bugs.
The license field for the repository is listed as unknown. Users should verify the terms under which they can use and distribute the software before integrating it into any workflow.
XX-Net Versus WireGuard-Based Solutions
WireGuard is a modern VPN protocol implemented as a Linux kernel module with user-space ports for other platforms. It creates an encrypted tunnel at the network layer. For most use cases outside active censorship environments, WireGuard provides strong performance and simplicity.
XX-Net differs in its threat model. WireGuard tunnels are identifiable as VPN traffic by deep packet inspection, which is why they are blocked in environments like the GFW. XX-Net's masquerade approach aims to bypass that detection by not creating a distinct tunnel fingerprint. The two tools solve different problems: WireGuard is appropriate when you control both endpoints and the network path does not attempt to block VPN traffic, while XX-Net targets environments where VPN protocols are actively blocked.
Editorial conclusion
XX-Net is a fit for users in censored network environments who want an open-source, no-installation proxy that runs on any major platform. It is not the right tool for users who need strong anonymity guarantees or a project with a published security audit, since neither is documented. The last push to the repository was on 2026-06-21. Review the wiki documentation for your platform before running it, as the README itself contains only a summary and links out for deeper configuration guidance.
Frequently asked questions
What is XX-Net?
XX-Net is an open-source Python proxy tool that bypasses internet censorship, particularly the Great Firewall. It runs on Windows, macOS, Linux, Android, and iOS, and requires no installation as it can be run directly from its directory.
How does XX-Net avoid detection?
The README states that XX-Net simulates Chrome browser behavior so its traffic is indistinguishable from ordinary HTTPS browsing. The strategy is to blend into normal web traffic rather than use a recognizable VPN tunnel.
What are the Python dependencies for XX-Net?
The requirements.txt file lists pyOpenSSL, babel, jinja2, and googletrans 4.0.0-rc1. These can be installed with `pip install -r requirements.txt` before starting the tool.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/xx-net-xx-net)