How to Use a SOCKS5 Proxy with croc for Tor: Complete Guide
croc routes all TCP traffic through a SOCKS5 proxy when you set the --socks5 flag or SOCKS5_PROXY environment variable, enabling anonymous file transfers over the Tor network.
The open-source file transfer tool croc (schollz/croc) includes built-in SOCKS5 proxy support that lets you tunnel connections through Tor. By configuring the Socks5Proxy variable in the communication layer, all relay connections route through Tor's SOCKS5 interface without modifying the underlying transfer protocol.
How SOCKS5 Proxy Support Works in croc
The proxy implementation spans the CLI and communication layers, ensuring that once configured, every outbound TCP connection respects your privacy settings.
The Communication Layer (src/comm/comm.go)
In src/comm/comm.go, the global variable Socks5Proxy stores the proxy address. When the NewConnection function initializes a TCP connection, it checks this value at lines 44-63. If Socks5Proxy is non-empty and the target address is not a local IP (verified via utils.IsLocalIP), croc constructs a SOCKS5 dialer using proxy.FromURL from the golang.org/x/net/proxy package. This dialer then handles the TCP connection to the relay or peer.
The implementation specifically skips the proxy for loopback or LAN addresses to avoid unnecessary Tor hops, ensuring local transfers remain efficient while external traffic receives anonymity protection.
CLI Flag Parsing (src/cli/cli.go)
The user interface for proxy configuration resides in src/cli/cli.go. Lines 81-82 define the --socks5 flag and the SOCKS5_PROXY environment variable. The flag value is injected into the communication layer at line 317 for send operations and line 616 for receive operations, ensuring both sides of the transfer can operate behind Tor.
Configuring croc to Use Tor
When the Tor daemon runs locally, it exposes a SOCKS5 proxy—typically on 127.0.0.1:9050 (standard daemon) or 127.0.0.1:9150 (Tor Browser). Pointing croc to this endpoint tunnels all traffic through the Tor circuit.
Sending Files Through Tor
Set the environment variable or use the command-line flag before specifying your file:
# Method 1: Environment variable
SOCKS5_PROXY=127.0.0.1:9050 croc send secret.txt
# Method 2: Command-line flag
croc send --socks5=127.0.0.1:9050 secret.txt
Receiving Files Through Tor
The receiver must also configure the proxy to connect through Tor:
# Method 1: Environment variable
SOCKS5_PROXY=127.0.0.1:9050 croc receive
# Method 2: Command-line flag
croc receive --socks5=127.0.0.1:9050
Both commands contact the default croc relay (relay.croc.li) via the Tor SOCKS5 proxy. If operating a custom relay, combine --relay (or CROC_RELAY) with the SOCKS5 configuration; the proxy will handle the outbound connection to your specified relay.
Technical Implementation Details
The proxy logic includes safeguards to prevent routing inefficiencies. Before creating the SOCKS5 dialer in src/comm/comm.go, croc calls utils.IsLocalIP (implemented in src/utils/utils.go) to detect whether the destination is a local address. This check prevents Tor from handling connections to 127.0.0.1 or LAN IPs, ensuring the proxy only handles external traffic that requires anonymity.
The NewConnection function in src/comm/comm.go (lines 44-63) handles the dialer selection:
- Check if
Socks5Proxyis configured - Verify the target is not a local IP
- If both conditions pass, create a SOCKS5 dialer using
proxy.FromURL - Use the dialer to establish the TCP connection
Summary
- croc supports SOCKS5 proxies through the
--socks5flag orSOCKS5_PROXYenvironment variable, as implemented insrc/cli/cli.go. - The communication layer in
src/comm/comm.goautomatically routes non-local connections through the configured proxy usingproxy.FromURL. - Local IP detection via
IsLocalIPinsrc/utils/utils.goprevents unnecessary proxy hops for LAN traffic. - Standard Tor SOCKS5 endpoints (
127.0.0.1:9050or127.0.0.1:9150) work out of the box with croc's send and receive commands.
Frequently Asked Questions
What is the default Tor SOCKS5 port?
The standard Tor daemon listens on 127.0.0.1:9050 for SOCKS5 connections. If you are running the Tor Browser instead of the system daemon, it typically uses 127.0.0.1:9150. Use whichever port corresponds to your active Tor instance when configuring croc.
Does croc leak DNS when using a SOCKS5 proxy?
croc uses the SOCKS5 dialer from golang.org/x/net/proxy which handles DNS resolution through the proxy when resolving the relay address. Since the connection establishment in src/comm/comm.go uses the proxy dialer for all non-local destinations, DNS queries for the relay hostname are sent through the Tor circuit rather than being resolved locally.
Can I use croc with the Tor Browser?
Yes. If you have the Tor Browser running, configure croc to use 127.0.0.1:9150 (the default Tor Browser SOCKS5 port). Both sending and receiving commands work normally: croc send --socks5=127.0.0.1:9150 filename.txt. Note that the Tor Browser must remain open to maintain the SOCKS5 listener.
How do I verify traffic is routing through Tor?
Check that croc is connecting to the relay via the Tor network by monitoring the proxy connection. When using SOCKS5_PROXY=127.0.0.1:9050, the TCP connection in src/comm/comm.go will show the proxy dialer being invoked for the relay connection (lines 44-63). You can also use Tor's built-in monitoring tools or temporarily block non-Tor traffic to confirm the transfer fails without the proxy active.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →