9 ms·
“Boobs check” – Technique to verify if sites behind CDN are hosted in Iran
https://xcancel.com/hkashfi/status/1995109785679573167 https://xcancel.com/hkashfi/status/1995109785679573167
- ThePowerOfFuet 10mo agohttps://xcancel.com/hkashfi/status/1995109785679573167 https://xcancel.com/hkashfi/status/1995109785679573167
- behnamoh 10mo ago[flagged]
- floodle 10mo agoIt's easier to view the tweet, to be fair
- llimllib 10mo agosome people don't want to give clicks to X, no we're not done with it. It doesn't harm you does it?
- hypeatei 10mo ago> XCancel is an instance of Nitter. > Nitter is a free and open source alternative Twitter front-end focused on privacy and performance. Where is the mission statement about wanting X gone? https://xcancel.com/about https://xcancel.com/about
- behnamoh 10mo ago[flagged]
- throwaway290 10mo agoif nitter robs twitter, then ublock robs youtube and youtubers. actually worse because nitter at least saves musk money on server costs.
- gpm 10mo agoRemarkable that you're simultaneously arguing this while arguing that > then I ask: what does X gain from your clicks? https://news.ycombinator.com/item?id=46100703 https://news.ycombinator.com/item?id=46100703 > Worst that can happen is they waste resources showing you ads that you don't click on. https://news.ycombinator.com/item?id=46100744 https://news.ycombinator.com/item?id=46100744 Almost like you are engaging in entirely bad faith.
- qbit42 10mo agoI don't want to have to create an account to view the full context.
- dvngnt_ 10mo agoyou can view replies without logging in
- lexlambda 10mo agoLike posting an archive.is link, others can actually read it. No login required for reading replays, no popups and signup nagss.
- Boogie_Man 10mo agoThanks for posting this. I mostly gave up on viewing the one or two Twitter feeds that interest me after nitter stopped working. It wasn't ideological, I just wasn't able to reliably view and navigate without an account, and when I made an account it just kept showing me like "black HS football player bad sportsmanship". Look like I've got about two years of James Cage White story arcs to check in on.
- skeledrew 10mo agoThis has been so useful to me that I've created a filter in URLCheck[0] that automatically converts all X-related links. [0] https://github.com/TrianguloY/URLCheck https://github.com/TrianguloY/URLCheck
- jimbob45 10mo agoWhy does this work while nitter doesn’t?
- KomoD 10mo agoThis is a hosted instance of nitter, the reason why nearly all nitter instances died is because "guest" accounts got removed, so now you need tons of real twitter/x accounts instead of just generating thousands of "guest" accounts.
- KiranRao0 10mo agoDoes anyone have sample sites that return this?
- deleted 10mo ago[deleted]
- phgn 10mo agoAlso interested in a sample site where the request successfully resolves ;)
- asdefghyk 10mo agoIf search in google search with site:ir it returns lots .ir links. I clicked on one and it went to a .com domain site. This may or may not be useful. How all this works is beyond my knowledge ..
- readthenotes1 10mo agoAre you asking if there are pictures of boobs on the internet?
- miniBill 10mo agoYou never know! Maybe they've all disappeared!
- KomoD 10mo agoHere: tehranpich.com It's behind CF
- lovegrenoble 10mo agoWhy not?
- Aloisius 10mo agoSo presumably Iran has a reverse proxy in front of the entire internet for HTTP? I really want to know what's on the webpage for the iframe.
- mschuster91 10mo ago> So presumably Iran has a reverse proxy in front of the entire internet for HTTP? Standard DPI firewalls can do that for you. Absolutely no issue.
- manmal 10mo agoFor the path component, in a TLS secured request?
- bobmcnamara 10mo agoIt's a CDN, not an IP router. CDNs usually terminate TCP+TLS as close to the client as possible. This used to be done right at the edge - within the NIC for a long time, but CPUs have been more than capable for the last decade+ Few guesses: 1) CDN connects to backend server over TLS, using the national I.R. Iran root CA 2) CDN connects to backend server over HTTP 3) Backend server is running a nationally blessed Linux OS For 1 & 2, the National Information Network would be implementing this DigiNotar style but they already own the root keys. For #3, the backend does so itself. These are the people who p0wned DigiNotar after all.
- Yokolos 10mo agoI'm wondering for what purpose one would be interested in finding out if a site is hosted in Iran or not.
- asdefghyk 10mo agoIm guessing - its for some protest action? ... but really I have NO IDEA.
- nostrademons 10mo agoWould assume it's to check if a site is foreign propaganda. A lot of the lesser-known news sites that you see linked on social media are actually psy-ops pushing an agenda, many of them foreign-based. Follow the technique in the article and you can easily blacklist Iranian ones.
- mdni007 10mo ago[flagged]
- testdelacc1 10mo agoDozens of Scottish independence X accounts ‘went dark’ after Iranian internet blackout (https://www.telegraph.co.uk/politics/2025/06/25/scottish-independence-went-dark-iran-internet-blackout-snp/ https://www.telegraph.co.uk/politics/2025/06/25/scottish-ind...) Iran is actively working hard to make us hate our fellow citizens. That matters.
- rozab 10mo agoMore concretely, a bunch of Scottish nationalist accounts were unearthed as Iranian by the recent X location switch-on
- FilosofumRex 10mo ago[flagged]
- 10mo ago
- shishcat 10mo agoThis behavior only works when the reverse proxy or CDN is configured like this: Proxy/CDN: HTTPS (443) → Origin server: plain HTTP (80) (example: Cloudflare in Flexible mode) If the origin server uses any proper TLS configuration, even a self-signed certificate, this method stops working. It only succeeds when the upstream connection to the origin is unsecured. If you want to test this on a random site without Cloudflare or reverse proxy in general on HTTP: curl http://www.digiboy.ir/boobs.jpg http://www.digiboy.ir/boobs.jpg -v
- mort96 10mo agoAh, Cloudflare. The world's most widely deployed encryption remover.
- spoiler 10mo agoTo be fair, Cloudflare is also the reason why most sites even have TLS at all, because it offered free certs (through letsencrypt I think?) in a fairly easy to set up way. Certs used to be expensive, and had way more operational overhead and quirks (even setting up ACME/LE)
- Tostino 10mo agoI'm not going to give them credit for the work that Lets Encrypt did.
- master_crab 10mo agoI agree, Let’s encrypt and ACME played a massive role. But it’s still far easier having Cloudflare handle TLS encryption for you. And i say this as someone who uses ACME in certmanager and certbot at home and still prefers the ease with which Cloudflare generates a cert for my domain and terminates TLS for the public side of my cloudflare tunnel.
- Tostino 10mo ago
- cluckindan 10mo agoWow. The screenshot had the IP address exactly where I placed my finger to scroll, and iOS Safari briefly opened a popup window where it started connecting to that IP. Fuck this shit, I’m moving to a hovel in the woods.
- pizzalife 10mo agoIt’s in a private Ip range so unless you’re inside Iran you’re fine.
- ycombinatrix 10mo agoI don't think that works in Iran either
- rootusrootus 10mo agoAlong the same lines, I occasionally find myself cursing iOS for its willingness to just bring up the dialer and call a number. I really, really wish that it would confirm any dialing before doing it, especially if you didn't click on a phone number on a contact. Couple times I've ended up dialing a recent spam caller, which is the last thing I ever want to do.
- lxgr 10mo agoOn top of that, the only possible interaction with the number is to call it or to not call it. Want to copy the number into the clipboard to call it later, call it from a different app, or forward it to somebody else? Tough luck.
- MaintenanceMode 10mo agoOccasionally, if you're lucky enough, an option to copy the phone number shows up, it seems like completely at the whim of the OS. And that's after accidentally starting to dial the number, of course.
- furyofantares 10mo ago
- losvedir 10mo agoHow's this work with https like in the example? The hops along the way shouldn't see the path. Is this implying that all TLS is terminated at the Iran border and proxied from there? And all Iranian sites are required to host via http? That has significantly more implications than what this post is about. Maybe certificate authorities aren't allowed to issue private certs to Iranian organizations? Even LetsEncrypt?
- tgma 10mo agoThis is referring to something else: to detect whether the backend server host itself is inside or outside Iran. TLS doesn't prevent the backend network from reading the URL of course.
- bawolff 10mo agoWell it would if things are setup according to best practises (i.e. use TLS between the backend connections). Presumably most people dont do that.
- tgma 10mo agoAgain, you are assuming a normal situation. The point is the country itself is operating (or has a heavy grip and perhaps even subsidizes) the backend CDN and enforcing that stuff in a rudimentary way. "TLS between backend connections" usually involves termination and decryption on the frontend webserver and re-encryption of the upstream traffic, whatever it may be.
- bobmcnamara 10mo ago> Is this implying that all TLS is terminated at the Iran border and proxied from there? Yeah, the law-abiding type on the Iranian National Information Network(NIN), either using the Electronic Commerce Council's I.R.Iran CA for HTTPS or just HTTP. > Maybe certificate authorities aren't allowed to issue private certs to Iranian organizations? Even LetsEncrypt? Due to NIN registrations being not very much not anonymous, https://xkcd.com/538/ https://xkcd.com/538/ seems pretty appropriate if you want to use an unapproved certificate authority.
- JumpCrisscross 10mo agoI wonder if this could be broadened to a list of Wikipedia links to humanitarian content folks in repressed regimes are or might get blocked from. Tiananmen Square [1]. Wen Jiabao's staggering corruption [2]. Epstein's e-mails [3]. Et cetera. Like Netflix launching Fast.com, this would directly weaponise these regimes' censoring tendencies against themselves. [1] https://en.wikipedia.org/wiki/1989_Tiananmen_Square_protests_and_massacre https://en.wikipedia.org/wiki/1989_Tiananmen_Square_protests... [2] https://www.nytimes.com/2012/10/26/business/global/family-of-wen-jiabao-holds-a-hidden-fortune-in-china.html?pagewanted=all https://www.nytimes.com/2012/10/26/business/global/family-of... [3] https://jmail.world https://jmail.world
- gnarlouse 10mo agoI saw “boobs” so I ran. -Iran
- bawolff 10mo agoSo does this mean 10.x.x.x is publicly routable inside iran? Why wouldn't the Iranian government just use its own ip space for the censorship message?
- ycombinatrix 10mo agoI just tried this on a few Iranian websites and never got a 403, let alone an iframe.
- lmm 10mo ago> Why wouldn't the Iranian government just use its own ip space for the censorship message? IP addresses are expensive if you're not the US. Also they might be reusing a standard corporate filtering product that expects to be deployed on a private network (and in a way, that's what the Iranian internet is).
- vivzkestrel 10mo agoI am probably a little dumb, i read the article but dont understand what happened. can some HNer kindly explain?
- whynotmaybe 10mo agoI guess that if you GET https://somedomain.com/boobs.jpg https://somedomain.com/boobs.jpg you get a 404 (not found) from a web server hosted outside of Iran but if the server for the domain is hosted in Iran, you get a 403 (forbidden) because the request is intercepted by a firewall that detect the word "boobs" and reject it with a 403 without forwarding it to the webserver that would usually return the 404.
- pavel_lishin 10mo agoA long time ago, my friends and I found a "scary"-looking image, written in a mixture of English and Arabic, warning the viewer that they'd come afoul of ... I forget, some Iranian government department of censorship? Naturally, we made it so that 1% of the requests to a forum we ran at the time displayed it to the viewer. :)
- wyldfire 10mo agoIs there a Scunthorpe problem looming there? Birdwatchers might seek out information about boobies - are they treated like boobs.jpg is?