12 ms·
Show HN: Wa-tunnel – HTTP Tunneling through Whatsapp
Side project tunneling a TCP port through WhatsApp, can be useful on airplanes or any WiFi/carrier that has unlimited social network data limits. Appreciate feedback :)
- deleted 4y ago[deleted]
- Dylan16807 4y agoFun, but when the comparison is unlimited WhatsApp versus "not many gigabytes" of other data, my first question is what speed this goes. How long does it take to transfer a gigabyte over WhatsApp?
- aleixrodriala 4y agoDepends on the throttle you add and then risking to get your WhatsApp account banned, but can be used to surf when you have no data or use other apps which can be useful, not intended for large files downloading or video streaming although got like 300kbps which wasn't too bad
- Matt3o12_ 4y agoHave you tried different throttles? Did you get any whatsapp account(s) banned at higher speed?
- aleixrodriala 4y agoYes, used different messages max sizes, with 2000 characters got the best speed but got the account banned, using 20000 is a great middle term and not banned for now, could get banned anyway, its an educational project
- cyclotron3k 4y agoCould you try encoding data as images for better bandwidth (and probably worse latency)?
- allanrbo 4y agoImages are often blocked on the free WhatsApp on airplanes
- cyclotron3k 4y agoI wonder how that's implemented if all the traffic is encrypted. Presumably images are sent via a different domain or IP address?
- blowski 4y agoMessage size, perhaps.
- ISL 4y agoAnd volume.
- codetrotter 4y agoI was on a boat recently where WhatsApp was free to use, and you had to pay to use the rest of the internet. You could send and receive messages but attempting to send an image, which wasn’t even all that big in size, did not work on the free connection. It must be either message size, or WhatsApp using a separate host name for attachments.
- zorr 4y agoI would not be surprised if the free WA messaging is implemented by whitelisting the signaling ports and domains (XMPP or similar) which only handle text content and small inline attachments. While larger images are uploaded and fetched out of band (HTTP or similar) with only a URL or reference passing over the signaling channel.
- yellow_lead 4y agoNice, seems useful for airplanes.
- aziaziazi 4y agoDid you click the link ? Planes are mentioned at the second sentence.
- yellow_lead 4y agoYep
- gnfargbl 4y agoIt looks like you're using base64 encoding. If WhatsApp allows an extended alphabet then you might be able to switch to base85 for a slight performance bump.
- kevincox 4y agoSince WhatsApp is end-to-end encrypted you can probably just send bibary data. Stick a prefix on it so that the real client is guaranteed to ignore it as corrupted. I think the only risk is that if you have a real client running it reports the invalid messages and WhatsApp uses this as a signal to van your account.
- staindk 4y agoNote AFAIK WA is e2e encrypted BUT they can flag any weird looking messages (weird patterns etc) to see and review their contents. So I think Meta/WA can opt to decrypt any suspicious messages they come across.
- preisschild 4y agoMeta/Facebook is the last company I would trust regarding their E2EE. They probably have a key themselves.
- orestarod 4y agoThe E2EE here is not about privacy, but about being able to send whatever data you want (like binary) since WhatsApp will only see one type of data (encrypted) in transit, in contrast to needing to send data in a specific format to have it transferred at all. Meta can peek at the original "messages" all they want, they will see encrypted packet data anyway.
- vital_beach 4y agoany CFAA concerns when used in the wrong place and found out (airplanes)?
- aleixrodriala 4y agoI'm not encouraging anyone to use this by saying this but WhatsApp traffic it's encrypted and the traffic through the socket its also encrypted, I guess you can't get in trouble for sending and recieving lots of weird messages? Again, intended for educational usage
- fragmede 4y agothat's a lot of words to say "yes, an overzealous prosecutor could try and make a case using the CFAA", but that's because the CFAA is a bullshit overly-broad law. that it's bullshit doesn't change the threat to the prosecuted, unfortunately.
- aleixrodriala 4y agoyou are totally right
- odo1242 4y agonot CFAA concerns, but you'd probably be in violation of the WhatsApp TOS: "… (d) interfere with or disrupt the safety, security, confidentiality, integrity, availability, or performance of our Services; …" disclaimer: IANAL
- aleixrodriala 4y agoYes, in the own project there is a disclaimer that using this software might get your WhatsApp account banned so use with caution, and anyways is just a fun project for educational purposes. But good to know ofc
- userbinator 4y agoThe word "proxy" used to refer to a human, and this is essentially an automated version of that. The automation of messaging a friend on WhatsApp and asking him to go to a website and send you the information.
- aleixrodriala 4y agoThat would be the human version of this, awesome to know :)
- quickthrower2 4y agoI believe proxy can still refer to a human. For example in voting.
- comprev 4y agoProxy simply means doing an action on behalf of another entity. This could be a human, a computer or even entire country ("proxy war")
- qbasic_forever 4y agoTermux is such an awesome hidden gem for tunneling cell data. My carrier doesn't allow wifi hotspot use on my phone (and android happily enforces their rules), but I can run sshd on termux and SOCKS5 proxy to my laptop with ssh. It's instant wifi tethering to my laptop without my carrier knowing or blocking it. I can even use adb networking and a USB cable if the laptop can't connect to the phone over wifi for some reason.
- aleixrodriala 4y agoYh it's awesome this project could run on termux without having to modify much or even iodine https://github.com/yarrick/iodine https://github.com/yarrick/iodine which is another awesome tool to avoid network restrictions.
- derwiki 4y agoWow, thanks for the iodine throwback! I distinctly remember using this on United flights in the early 2010s via my Slicehost server.
- easrng 4y agoomg another person who does this!
- aleixrodriala 4y agoCouldn't find any other library that actually worked with HTTPS traffic also, do you have any? Thanks :)
- easrng 4y agoSorry, I don't quite understand what you're asking. Did you reply to the wrong person?
- aleixrodriala 4y ago
- wolpoli 4y agoSlightly off topic: is there a way to tunnel internet over the phone system on a smartphone in the event that phone works but internet doesn't?
- jamal-kumar 4y agohttps://github.com/spandanb/ipos https://github.com/spandanb/ipos I mean if this doesn't charge you up the yahoo per message, might be viable in a very limited circumstance?
- sedatk 4y agoProbably with a dial-up call but you’d be limited to 2400bps: https://superuser.com/a/748163 https://superuser.com/a/748163
- deleted 4y ago[deleted]
- cpeterso 4y agoIt's built into iOS: https://support.apple.com/en-us/HT204023 https://support.apple.com/en-us/HT204023 A Personal Hotspot lets you share the cellular data connection of your iPhone or iPad (Wi-Fi + Cellular) when you don't have access to a Wi-Fi network.
- jamal-kumar 4y agoI remember trying this (Also in Latin America with Zuckerberg's creepy old "internet.com" initiative to make his services free in the third world, which is a done and over with promotion by now at least in Costa Rica) and realizing that ICMP/DNS tunneling was faster and more reliable, you can only get like half-duplex TCP over whatsapp messages and then the frames are limited if you're going to fit them in per message to like 1,024 characters (Though it seems you got more in there?)... DNS or ICMP tunnelling further works on things like getting a foothold for checking your email in some far flung airport network with a broken/sketchy payment gateway, you REALLY need to check your email, and where that passes but nothing else does. Then there's the risk that they decide to ban your SIM chip as you mention, which is like a 2$ mistake in such regions but if you do it on your main number you're risking having to tell everyone "yeah i tried to hack whatsapp and they blocked my old number haha" because that's what they've funnelled everyone into using out there with this free data transfer deal on that platform. By the way your implementation looks way nicer than what I was working with before.
- public_defender 4y agoI love this as a check on zero-rating. I think that Facebook zero-rating in emerging economies will prove to have an abysmal toxic legacy. Anything that can tax the value proposition by e.g. forcing a lot of data through the pipe should be encouraged as a way to generally decrease the prevalence of the practice.
- SergeAx 4y agoYes, please support net neutrality, it is very important.
- graderjs 4y agoThis is like the 2020s version of phreaking
- dsatjkfkhduif 4y ago
- aziaziazi 4y agoNice idea, congrats to OP. Sadly some people here thinks “if I pay for data I should be free using it the way I want”. As others explained carriers create plans (price/data/unitOfTime) based on their antenna capacity. If too many people cheats to torrent/4K/whatever, the carriers will need to readjust the plans for the system continuing to works (= prices will go up). I love FOSS, stop being selfish and think of collective benefit.
- ghgr 4y ago> If too many people cheats to torrent/4K/whatever, the carriers will need to readjust the plans for the system continuing to works (= prices will go up) This hypothesis assumes that carriers can increase prices and the public will still pay them. If so, it follows that they are now leaving money on the table, which sounds unlikely. I think it was Tim Hardford who wrote about something similar in his book "The Undercover Economist", in the context of the spectrum auctions in the different countries.
- aziaziazi 4y agoMaybe I wasn’t clear enough, my argument is carriers will need to install and maintain new equipment. That’s what would drive price increase, not laying money on a table. M
- neonsunset 4y agoIf a particular zone is overloaded, the carriers will for sure throttle usually just the offending people. As much as I support the argument in its general meaning, the carriers and ISPs especially in the US are probably the last thing anyone should vouch for given monopolistic policies, total market control and insane prices.
- deleted 4y ago[deleted]
- netsharc 4y agoSince WhatsApp sends binaries (images, documents like PDFs, probably Zip files as well), I wonder if this proxy also encodes the data as binaries. It recompresses JPEGs though, although there is an option to turn that off, and in any case the recompression probably happens client (sender) side.
- bsaul 4y agois there any official documentation for whatsapp api somewhere or is this work based on reverse-engineering only ?
- knutzui 4y agoThis uses Baileys [0] which appears to reverse-engineer the protocol Whatsapp uses for it's web app. [0]: https://github.com/adiwajshing/Baileys https://github.com/adiwajshing/Baileys
- deleted 4y ago[deleted]
- jdthedisciple 4y agoNice! Any chance this was inspired by "Wikipedia over WhatsApp"? https://news.ycombinator.com/item?id=31463249 https://news.ycombinator.com/item?id=31463249
- aleixrodriala 4y agoI got the idea myself on a bar, did a quick look online and didnt find anything, later on when I had it built I found that 8 years ago this guy did a similar one: https://github.com/matiasinsaurralde/facebook-tunnel https://github.com/matiasinsaurralde/facebook-tunnel but probably wont work since its using curl
- cto_official 4y agoOne question.. if Whatsapp is encrypting data how are you able to decrypt the packet easily ?
- jfjdskldhjfcj 4y agowell, it's encrypted e2e only in 1:1 chats. groups is weird, the media have the index encrypted but the contents use a shared app key. commercial accounts are also odd. it's encrypted with the business and whatsapp keys, so employees from both can read the messages. then here there's the api issues. you are not using a full client, but sending your access token plus the plain text message for it to be encrypted on their servers. even worse, in this example it's not even you using the api, but you are using twillo's api, who then uses metabook's api for whatsbook. so it's plain text all the way across those.
- jesprenj 4y agoI was on a ferry ship from Italy to Greece where they had paid sattelite Internet via WiFi. The WiFi AP was at first a captive portal. You could buy Internet access with cash at the reception or you could pay online. For that they had to enable access to stripe.com. But stripe uses fastly CDN, so they enabled one specific fastly endpoint that stripe uses. You had direct IP traffic to this specific IP address. reddit also uses fastly CDN. So with a /etc/hosts hack I could load reddit pages for free. Not images though, as they are hosted by imgur. I assume one could also create a tunnel over reddit chat connect to the Internet, but I never did that. By default, reddit did not work though, as their fastly CDN endpoint is different from stripe's, also the stripe's endpoint did not correctly sign TLS for reddit.com. But setting a Host header of old.reddit.com on that fastly IP successfully downloaded the page. When I still had phone network by the coast, I set up iodine IP over DNS tunnel, but it did not work, even though DNS requests worked on that WiFi. Maybe they had some sort of protection specifically for iodine.
- nibbleshifter 4y agoThere's a trick called "Domain fronting" (ab)using CDN's like that which is useful. Tor's "meek" pluggable transport uses it, but only supports a couple of cdns as you need to run infra behind the CDN which costs money. As for Iodine, I used to run a few public DNS tunnel servers with it for people. Its a pain in the ass to get working reliably.
- bythckr 4y agoPls explain how you did that. I would like to try it for myself.
- jesprenj 4y agoFirst of all I was doing all of this on my touchscreen phone, which made me give up soon, as my laptop was packed in the garage. I used a program called Packet capture that registers as a VPN connection in Android and routes all traffic trough itself. I saw some external IPs with TLS data when visiting the captive portal: http://upload.4a.si/pcap.jpg http://upload.4a.si/pcap.jpg When I sent a request to one IP address, I learned from the response that I've reached a fastly endpoint. The response was an error page, claiming they host no one with this domain. I knew from a talk by reddit sysadmins that they use the fastly CDN, so I added a Host header with a value of old.reddit.com: curl -ikH Host:\ old.reddit.com https://151.101.0.176/r/Slovenia.json https://151.101.0.176/r/Slovenia.json Then I added a rule in software AdAway for Android (this one is used for DNS blacklisting to remove ads based on DNS queries and requires root access - changes /etc/hosts AFAIK) to overwrite old.reddit.com to this IP address. I can't remember how I tricked the web browser into ignoring invalid certs.
- metters 4y agoThis might be a stupid question. If WhatsApp wasn’t blocked in China and the second WhatsApp account (aka server side) was outside of China, could this bypass the great firewall?
- aleixrodriala 4y agoSure, just like any proxy though
- georgyo 4y ago> If WhatsApp wasn’t blocked in China The answer is yes, this could be used if WhatsApp wasn't blocked. But since it blocked in China, you would first need to bypass the firewall anyway.
- Komodai 4y ago