4 ms·
I actually did some fiddling with Wireshark, and it looks to me that it should be easy to make a tunnel masquerading as TLS 1.3 in Python. Firefox's TLS request
by codedokode 2y ago
I actually did some fiddling with Wireshark, and it looks to me that it should be easy to make a tunnel masquerading as TLS 1.3 in Python. Firefox's TLS requests mostly look the same except for several fields (like RandomId, SessionId, SNI) and it is easy to write a tunnel in Python that would send similar initial packets (so that they look exactly like the ones sent by the browser), and after pretending to setup a TLS session, incapsulate real traffic as TLS Application Data records. You don't need to implement real TLS protocol, you just need to make several initial packets by template.
The project you mentioned seems to be pretty complicated; I think it is possible to implement the tunnel in a single Python file without any external libraries. But I was not intending to implement any serious crypto, just masquerade traffic.
Yes, I saw that project and even the English documentation is not easy to read.
- nine_k 2y agoYes, Xray does more than just making the traffic look like typical web traffic. It also makes the open VPN server port look exactly like a port serving a legitimate third-party site, with the proper TLS certificate and all. Put it on port 443, make it proxy something like samsung.com or whatever else your censors find inoffensive. This protects the VPN node from being blocked after a port scan, and gives you plausible deniability: "Yes, I have visited this IP. Let's open it. Ah, I just wanted to look at the newest Samsung phone model."