TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Domain Fronting with Meterpreter

25 点作者 wolframio超过 7 年前

2 条评论

Tepix超过 7 年前
I had a closer look at this technique after reading the article.<p>The cool thing about this hack is that even in the TLS Server Name Indication (SNI) extension, the front domain name shows up, and only the (encrypted) HTTP Host header shows the true covert destination.<p>The paper &quot;Blocking-resistant communication through domain fronting&quot; (<a href="https:&#x2F;&#x2F;www.bamsoftware.com&#x2F;papers&#x2F;fronting&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.bamsoftware.com&#x2F;papers&#x2F;fronting&#x2F;</a>) is very interesting.<p>One thing that I&#x27;m left wondering is if the front domain owners will be at risk being blocked if domain fronting is being done with their domain. If so they may ask the CDN companies to block this routing behaviour.
creeble超过 7 年前
Not sure I understand the point of the article. How is this different from what CloudFlare does (for free)?
评论 #15863625 未加载