3 ms·
Is it possible for anyone to share the full text of the post for those of use behind a great firewall? Edit: thanks!
by netule 10y ago
Is it possible for anyone to share the full text of the post for those of use behind a great firewall?
Edit: thanks!
- willvarfar 10y agourandom.pcap: Belarus (finally) bans Tor Leonid Evdokimov 2016-12-08 00:00:00 +0000 UTC Country: Belarus Probed ISPs: Beltelecom (AS 6697) Censorship method: TCP injections We have recently heard of network anomalies in Belarus. Tor has been finally blocked in December 2016, although it had been explicitly declared that Tor should be blocked since February 2015. Directly connected users from Belarus An anonymous cypherpunk has helped to gather some evidence regarding Tor being blocked in Belarus. It’s neither a complete study nor an in-depth research and it’s unclear if any other further evidence will be gathered, so we decided to share current knowledge as-is: Tor directory authorities are not blocked Public onion routers have their ORPort blocked by TCP RST injection The onion routers’ DirPort is not blocked Plain-old non-obfuscated Tor Bridges from BridgeDB circumvent the interference Beltelecom (or its upstream) has strange configuration of the networking gear injecting reset packets The strangeness in equipment is the following. The first injected RST packet does not have have proper SEQ/ACK numbers. These packet fields are just filled with zeroes. So this packet is dropped by the client’s TCP/IP stack per RFC5961 and does not actually terminate the client’s connection: $ tshark -Tfields -eframe.time_relative -eip.src -etcp.srcport -eip.dst -etcp.dstport \ -eip.ttl -etcp.flags.str -etcp.seq -etcp.ack -r urandom.pcap | sed | awk | perl 0.000000 192.168.1.2 42555 87.118.94.227 443 64 **********S* 899897236 0 0.029459 87.118.94.227 443 192.168.1.2 42555 125 *********R** 0 0 (sic!) 0.096914 87.118.94.227 443 192.168.1.2 42555 52 *******A**S* 1984028404 899897237 0.096958 192.168.1.2 42555 87.118.94.227 443 64 *******A**** 899897237 1984028405 0.136874 87.118.94.227 443 192.168.1.2 42555 125 *********R** 1984028405 0 That’s all for today. Remember, fried potato is better with onion!
- varjag 10y ago("fried potato" is a reference to cliché Belarusian obsession with potato)
- alexellisuk 10y agoThanks for explaining.. was not aware of this.
- bob1122 10y agoCountry: Belarus Probed ISPs: Beltelecom (AS 6697) Censorship method: TCP injections We have recently heard of network anomalies in Belarus. Tor has been finally blocked in December 2016, although it had been explicitly declared that Tor should be blocked since February 2015. Directly connected users from Belarus An anonymous cypherpunk has helped to gather some evidence regarding Tor being blocked in Belarus. It’s neither a complete study nor an in-depth research and it’s unclear if any other further evidence will be gathered, so we decided to share current knowledge as-is: Tor directory authorities are not blocked Public onion routers have their ORPort blocked by TCP RST injection The onion routers’ DirPort is not blocked Plain-old non-obfuscated Tor Bridges from BridgeDB circumvent the interference Beltelecom (or its upstream) has strange configuration of the networking gear injecting reset packets The strangeness in equipment is the following. The first injected RST packet does not have have proper SEQ/ACK numbers. These packet fields are just filled with zeroes. So this packet is dropped by the client’s TCP/IP stack per RFC5961 and does not actually terminate the client’s connection: $ tshark -Tfields -eframe.time_relative -eip.src -etcp.srcport -eip.dst -etcp.dstport \ -eip.ttl -etcp.flags.str -etcp.seq -etcp.ack -r urandom.pcap | sed | awk | perl 0.000000 192.168.1.2 42555 87.118.94.227 443 64 S* 899897236 0 0.029459 87.118.94.227 443 192.168.1.2 42555 125 R* 0 0 (sic!) 0.096914 87.118.94.227 443 192.168.1.2 42555 52 AS 1984028404 899897237 0.096958 192.168.1.2 42555 87.118.94.227 443 64 A* 899897237 1984028405 0.136874 87.118.94.227 443 192.168.1.2 42555 125 R* 1984028405 0 That’s all for today. Remember, fried potato is better with onion!
- zeroer 10y agoOONI About Install Tests Data Get Involved Blog urandom.pcap: Belarus (finally) bans Tor Leonid Evdokimov 2016-12-08 00:00:00 +0000 UTC Country: Belarus Probed ISPs: Beltelecom (AS 6697) Censorship method: TCP injections We have recently heard of network anomalies in Belarus. Tor has been finally blocked in December 2016, although it had been explicitly declared that Tor should be blocked since February 2015. Directly connected users from Belarus An anonymous cypherpunk has helped to gather some evidence regarding Tor being blocked in Belarus. It’s neither a complete study nor an in-depth research and it’s unclear if any other further evidence will be gathered, so we decided to share current knowledge as-is: Tor directory authorities are not blocked Public onion routers have their ORPort blocked by TCP RST injection The onion routers’ DirPort is not blocked Plain-old non-obfuscated Tor Bridges from BridgeDB circumvent the interference Beltelecom (or its upstream) has strange configuration of the networking gear injecting reset packets The strangeness in equipment is the following. The first injected RST packet does not have have proper SEQ/ACK numbers. These packet fields are just filled with zeroes. So this packet is dropped by the client’s TCP/IP stack per RFC5961 and does not actually terminate the client’s connection: $ tshark -Tfields -eframe.time_relative -eip.src -etcp.srcport -eip.dst -etcp.dstport \ -eip.ttl -etcp.flags.str -etcp.seq -etcp.ack -r urandom.pcap | sed | awk | perl 0.000000 192.168.1.2 42555 87.118.94.227 443 64 S* 899897236 0 0.029459 87.118.94.227 443 192.168.1.2 42555 125 R* 0 0 (sic!) 0.096914 87.118.94.227 443 192.168.1.2 42555 52 AS 1984028404 899897237 0.096958 192.168.1.2 42555 87.118.94.227 443 64 A* 899897237 1984028405 0.136874 87.118.94.227 443 192.168.1.2 42555 125 R* 1984028405 0 That’s all for today. Remember, fried potato is better with onion! The Onion
- wruza 10y agohttps://web.archive.org/web/20161208223355/https://ooni.torproject.org/post/belarus-fries-onion/ https://web.archive.org/web/20161208223355/https://ooni.torp... Hope you still have access to archive.org ;)
- mirages 10y agoMy corp firewall is blocking it for "Cache/Proxy" :p
- alexellisuk 10y agoThat is a neat trick.. I was also blocked but web archive works fine!
- beardog 10y agoYou know things are looking bad when the post reporting on censorship is censored.
- BuuQu9hu 10y agoIs it possible to access any of these where you are? archive.org archive.is archive.today archive.fo webcache.googleusercontent.com