#domainfronting

C.Suthorn :prn:Life_is@no-pony.farm
2025-05-10

#TIL bei #fdroid gibt es die #Android #App "Wiki fronted". Das ist ein Fork der offiziellen #Wikipedia App, aber mit einbindung des #WMF #DNS #Resolvers und #DomainFronting. So kann Deep Packet Inspection und Zensur (zB in China) umgangen werden.

Ist natürlich auch von Vorteil, wenn der im Betriebssystem eingestellte DNS-Server mal ausfällt.

🛡 H3lium@infosec.exchange/:~# :blinking_cursor:​H3liumb0y@infosec.exchange
2024-02-01

"🚨 CVE-2023-28807 - Domain Fronting Evasion in ZIA 🚨"

An evasion technique identified as CVE-2023-28807, allows attackers to bypass Zscaler Internet Access (ZIA)'s domain fronting detection by exploiting a mismatch between Connect Host and Server Name Indication (SNI) in Client Hello messages. The vulnerability exploits how ZIA handles the SNI field during the TLS handshake process. The SNI is intended to indicate which host the client wants to connect to within a shared hosting environment, allowing the server to present the correct certificate for that host. However, due to this vulnerability, an attacker can manipulate the SNI in such a way that the security mechanisms fail to correctly identify and filter malicious traffic, enabling the attacker to hide malicious activities within what appears to be legitimate traffic.
This vulnerability, discovered and addressed by Zscaler. Users are urged to upgrade to version 6.2r.290 to mitigate this risk. 🛡️💻🔐

Source: Zscaler & VulDB

Tags: #Cybersecurity #CVE2023 #DomainFronting #Zscaler #NetworkSecurity #EvasionTechniques #MITREATTACK MITRE - T1587.003 🌍🔒🔍

Who Let The Dogs Out 🐾ashed@mastodon.ml
2023-12-03

Domain fronting для чайников, и как его использовать для обхода блокировок

#security #proxy #DomainFronting #VPS #xtls #nekoray #shadowsocks #vless #vmess

Давайте сразу вопрос на засыпку: может ли быть так, что клиент подключается, ну, например, к серверу www.python.org (самому настоящему, тому, к которому обращаются еще миллионы клиентов со всего мира), а потом использует его как прокси и гоняет через это подключение трафик до своего VPS для доступа в неподцензурный интернет? Если вы не уверены в ответе на этот вопрос или почему-то ответили "нет", то добро пожаловать в статью.

habr.com/ru/articles/778134/

Tedi Heriyantotedi@infosec.exchange
2023-11-11

Measuring CDNs susceptible to Domain Fronting: arxiv.org/pdf/2310.17851.pdf

#domainfronting

Gareth Emslie 🇿🇦 🇪🇦 🇨🇭keyoke_za@hachyderm.io
2023-01-25

Azure Networking has released an update which includes a feature that blocks domain fronting behavior on newly created customer resources, as well as feature enhancements to Azure Web Application Firewall (WAF). techcommunity.microsoft.com/t5 #AzureNetworking #DomainFronting #AzureWAF

Patryk Krawaczyńskiagresor@infosec.exchange
2022-11-18

Obchodzenie zapór pośrednicząco-filtrujących strony web #2 ( nfsec.pl/pentest/5959 )
#web #proxy #bypass #security #domainfronting #twittermigration

2018-08-23

Wickr announces a firewall-circumventing tool to help beat national censorship regimes boingboing.net/2018/08/23/psip #can'tstopthesignal #domainfronting #censorship #citizenlab #cryptowars #psiphon #wickr #Post

The Tor Projecttorproject@apoil.org
2018-06-11

Tor Browser 7.5.5 and 8.0a8 are now available for download.

Both releases include important security updates to Firefox, and we had to remove the amazon-meek pluggable transport.
blog.torproject.org/tor-browse blog.torproject.org/tor-browse #domainfronting #privacy #openweb twitter.com/torproject/status/ source: twitter.com/torproject/status/

The Tor Projecttorproject@apoil.org
2018-05-08

RT @accessnow: So do we. That's why we want to ensure #domainfronting continues. We're asking for help from the #US Congress in urging comp… source: twitter.com/torproject/status/

The Tor Projecttorproject@apoil.org
2018-05-07

RT @accessnow: Media release: 'Access Now calls on #US Congress to look at companies’ decision on #domainfronting' @lawyerpants @NathanielD… source: twitter.com/torproject/status/

The Tor Projecttorproject@apoil.org
2018-05-07
The Tor Projecttorproject@apoil.org
2018-05-04

We didn't get advance notice of Google & Amazon ending domain fronting, so we're thinking hard on potential solutions to ensure our friends living in repressive regimes can continue to access the open web. blog.torproject.org/domain-fro #censorship #domainfronting #humanrights #openweb twitter.com/torproject/status/ source: twitter.com/torproject/status/

The Tor Projecttorproject@apoil.org
2018-05-04

Amazon and Google are pulling the plug on domain fronting, a crucial tool which helps our most vulnerable users get access to Tor when their countries don’t allow it.
blog.torproject.org/domain-fro
#censorship #domainfronting #humanrights #openweb twitter.com/torproject/status/ source: twitter.com/torproject/status/

Jacobo Nájerajacobonajera
2018-05-04

Amazon amenaza con cortarle el servicio a Signam si siguen utilizando la técnica llamada para eludir la censura. Aquí el comunicado de la organización Access Now: accessnow.org/message-to-googl

Rysiekúr (old account)rysiek
2018-05-03

Aaaaaaand there goes on :
arstechnica.com/information-te

I remember people telling me domain fronting will solve all problems, and me feeling queasy about relying on big players so much.

Google killed it last month, Amazon is killing it now.

Also, interesting: a)> there had to be a misconfiguration in Amazon/Google infras; b). was using it apparently without Amazon/Google approval?

Chris has moved instances 🚫offby1
2018-05-03

RT @pythonista@twitter.com
If I rephrase a tweet three times, I probably shouldn't post it at all.

rugk OLD ACCOUNTrugk@social.wiuwiu.de
2018-05-02

So #domainfronting is going to die? Or what is the takeaway here? At some point, you do not have any big companies willing to allow it, anymore… signal.org/blog/looking-back-o

heise online (inoffiziell)heiseonline@squeet.me
2018-05-02
Über Domain Fronting konnten Signal-Nutzer bisher die Zensur in Ländern wie Ägypten und den Vereinigten Arabischen Emiraten umgehen. Das ist Google und Amazon ein Dorn im Auge, die nun den Signal-Entwicklern diese Möglichkeit nehmen. www.heise.de/newsticker/meldun… #AWS #Amazon #AppEngine #DomainFronting #Google #Messenger #SSL #Signal #TLS #Verschlüsselung

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst