4 ms·
I think HTTP web sockets would be an interesting tunneling protocol.
by sebazzz 9mo ago
I think HTTP web sockets would be an interesting tunneling protocol.
- bauruine 9mo agoTor has a transport using exactly that. https://blog.torproject.org/introducing-webtunnel-evading-censorship-by-hiding-in-plain-sight/ https://blog.torproject.org/introducing-webtunnel-evading-ce...
- megous 9mo agoYou don't need websockets, just Connection: Upgrade to anything you want. You can upgrade directly to ssh protocol and just pass on decrypted data from https socket to local port 22 from then on with no further processing.
- ranger_danger 9mo agoProper DPI can tell that wouldn't be acting like a typical HTTP stream, encrypted or not.
- catlifeonmars 9mo agoHehe true, SSH traffic is so characteristically obvious that the packet size and timing can be used as a side channel to leak information about a session. Tangential: but I recall reading about a similar technique used on SRTP packets to guess the phonemes being uttered without needing to decrypt the traffic.
- ranger_danger 9mo agoI guess you would need to either mimic a protocol that always uses a fixed packet size/rate (like a MPEG-TS video stream or something), or artificially pad/delay your packets to throw off detection methods.
- megous 9mo agowould not be able to tell from websockets uses
- ranger_danger 9mo agoI think most websockets do not sustain large amounts of bidirectional traffic for prolonged periods, so IMO this would immediately be suspicious.
- megous 9mo agoMy typical ssh session does not either.