HOWTO bypass China's Great Firewall

"Simon Cousins" <simon-MTRkitCQmL6jF/[email protected]> Fri, 30 Jun 2006 18:11:38 +0800
Newsgroups gmane.org.user-groups.linux.beijing
Message-ID <00d601c69c2d$93990be0$6e00a8c0@acertravelmate>
Net censorship: HOWTO bypass China's Great Firewall 


Richard Clayton <http://www.cl.cam.ac.uk/%7Ernc1/> , a computer security
researcher at the University of Cambridge, has been poking around at the
technical structure of China's "great firewall." On the lightbluetouchpaper
<http://www.lightbluetouchpaper.org/>  collective blog, he
<http://www.lightbluetouchpaper.org/2006/06/27/ignoring-the-great-firewall-o
f-china/>  says he's come up with a way to penetrate that "wall" by ignoring
the reset TCP packet returned by Chinese routers to maintain connection. As
he explains it, if those packets are discarded instead of being dutifully
returned as expected, then -- poof, the firewall becomes utterly
ineffective. Clayton acknowledges that Internet filtering in China involves
other methods, too, but this still seems significant: 

The Great <http://news.bbc.co.uk/1/hi/programmes/click_online/4587622.stm>
Firewall of China is an important tool for the Chinese Government in their
<http://www.opennetinitiative.net/studies/china/ONI_China_Country_Study.pdf>
efforts to censor the Internet. It works, in part, by inspecting web traffic
to determine whether or not particular words are present. If the Chinese
Government does not approve of one of the words in a web page (or a web
request), perhaps it says “f” “a” “l” “u” “n”, then the connection is closed
and the web page will be unavailable — it has been censored.

This user-level effect has been known for some time… but up until now,
no-one seems to have looked more closely into what is actually happening (or
when they have, they have <http://www.opennetinitiative.net/bulletins/005/>
misunderstood the packet level events).

It turns out [caveat: in the specific cases we’ve closely examined, YMMV
<http://money.cnn.com/2004/09/02/pf/autos/epa/index.htm> ] that the keyword
detection is not actually being done in large routers on the borders of the
Chinese networks, but in nearby subsidiary machines. When these machines
detect the keyword, they do not actually prevent the packet containing the
keyword from passing through the main router (this would be horribly
complicated to achieve and still allow the router to run at the necessary
speed). Instead, these subsiduary machines generate a series of TCP reset
packets, which are sent to each end of the connection. When the resets
arrive, the end-points assume they are genuine requests from the other end
to close the connection — and obey. Hence the censorship occurs.

However, because the original packets are passed through the firewall
unscathed, if both of the endpoints were to completely ignore the firewall’s
reset packets, then the connection will proceed unhindered! We’ve done some
real experiments on this — and it works just fine!! Think of it as the Harry
Potter approach to the Great Firewall — just shut your eyes and walk onto
Platform 9¾ <http://www.crypto.com/photos/misc/platform9.75.html> .

Link
<http://www.lightbluetouchpaper.org/2006/06/27/ignoring-the-great-firewall-o
f-china/> . Clayton is presenting a paper on this topic (PDF link to paper
<http://www.cl.cam.ac.uk/%7Ernc1/ignoring.pdf> ) at the 6th Workshop on
Privacy <http://www.petworkshop.org/2006/>  Enhancing Technologies being
held in Cambridge this week. (Thanks, Mike Liebhold
<http://www.iftf.org/people/mliebhold.html> ) 

posted by Xeni Jardin, BoingBoing at 06:21:18 PM permalink
<http://www.boingboing.net/2006/06/29/net_censorship_howto.html>  | blogs'
<http://www.technorati.com/cosmos/search.html?rank=&sub=mtcosmos&url=http://
www.boingboing.net/2006/06/29/net_censorship_howto.html>  comments | give
feedback <http://boingboing.net/feedback.html>

_______________________________________________
blug-general list
[email protected]
http://list.beijinglug.org/cgi-bin/mailman/listinfo/blug-general
image001.jpg (image/jpeg, 3.9 KB) - not displayed