Re: Passing firewalls and hiding freenet traffic
Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]>
| Newsgroups | gmane.network.freenet.general |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Apr 22, 2005 at 09:43:02AM +0200, panamerica334-hX/r/[email protected] wrote: > >easy; "silent bob" would be transformed to "picky bob" > > > >listen on port 80[http]/443[https]/8080[tomcat]/8443[ssl-tomcat]/3128[squid; not sure if the port number is correct]/whatever. > >if authorization was okay, send freenet protocol data back > >if auth failed, return http-500 with a short delay so retries are somewhat hindered :) > > or yet even better -- return a valid site! so FRED would be a small webserver capable in handling low load for the ocassions someone stumbled into the server but when auth succeeds FRED switches to freenet for this one client. this way even the too-much-telling 500 Now, there's an idea. We've had this idea a few times - pass-through TCP. Basically, you run a webserver on another port (or another machine), and Fred proxies it to a given port. If it sees a magic packet (which depends on the node's identity, the current time etc), it starts an FNP negotiation. We could do this with or without real steg - we can do it without just to make portscanning even harder, or with to provide some more real hiding functionality. > could be evaded. as content for the "innocent" side the node maintainer can create their own webpage (stored within docroot) or use a default webpage saying something like "Hier entsteht eine Internetpr?senz" ("here will be a web presence shortly"), a very > widespread dummy content page for newly created websites. of course that would be typical for german hosts. but perhaps the default page could be automatically adjusted to the language settings of the OS. so in japan their typical "here will be a web presence shortly" > can be used. i think every country has their somewhat standard placeholders for empty webservers. if there are more than one of these for a given region (e.g. america), FRED would pick one of these on first startup by random so e.g. for america there would be five I would have the user install apache via their linux distribution, or whatever else. Then it can't be identified as Freenet. > standard placeholders where alice's FRED would choose one of these, and bob's FRED would choose a different one, making it difficult so see that both are freenet nodes viewed from an untrained eye. > > >ssl is the best foundation for hiding traffic as there are many ssl-encrypted connections around and even if They find out how to break ssl, they would see the (with content-coding: gzip to preserve space and cleartext) http packets and have to demasquerade these. > >difficult to find if you have no suspicion a specific ssl-channel could be carrying freenet protocol data > > hm, does "content-encoding: gzip" support passworded gzips? I doubt it very much. Gzip is just a compressor. > > just my 0,02? -- Matthew J Toseland - toad-EI5O+8PHWbJeeLb3ft/[email protected] Freenet Project Official Codemonkey - http://freenetproject.org/ ICTHUS - Nothing is impossible. Our Boss says so. _______________________________________________ chat mailing list [email protected] Archived: http://news.gmane.org/gmane.network.freenet.general Unsubscribe at http://dodo.freenetproject.org/cgi-bin/mailman/listinfo/chat Or mailto:[email protected]?subject=unsubscribe
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (GNU/Linux) iD8DBQFCaO62HzsuOmVUoi0RAnn/AJ9FuSQc81OVadUyt899nsXJaB8mWQCgnIH+ YNcMenGbZV3aWGv7KyPyjC0= =5s+9 -----END PGP SIGNATURE-----