Make anonymous HTTP GET requests with proxies via Python
github.com
github.com
No one should be expecting privacy if proxies are the only solution you rely on.
https://www.whonix.org/Comparison_Of_Tor_with_CGI_Proxies,_P...
"Conclusion
Proxies have a high susceptibility of misusing and stealing user data: Many proxies (HTTP/HTTPS/SOCKS) are PCs hijacked by hackers or criminals, or honeypots exclusively offered for the purpose of user observation. Even if they were legitimate, a single operator can decide to enable logging. Additionally, some proxies automatically give your IP address away to the destination server.
Proxies offer, at best, only weak protection against destination website logging, and they offer no protection from third party eavesdropping. Their use is discouraged"
A good starting point if you wish to appreciate privacy more is: https://www.whonix.org/wiki/Security_Guide
Also look into Qubes OS: https://www.whonix.org/wiki/Qubes
The steps I took were so extreme. Cash phone, burner computer, custom proxies, relays, delays, fake data, fake traffic.
And you still never know.
Your adversary could have something you didn't even think of and you get owned anyway.
If all you want to do is avoid tracking scripts from companies, however, use a VM on another user account on your computer and write up a script to light up a new DigitalOcean droplet automatically when you browser. Cycle the IP frequently and use a bunch of different VMs with different browsers and OSes. It's enough for 99.99%.
P.S. proxies do not completely mask DNS requests so timing analysis is still possible for uncached requests.
And worse the payload returned can be used to unmask the user behind a proxy e.g. redirect to uniqueid.myhost.com my honey pot does that to unmask requests originating from TOR or from proxies and it’s quite successful.
And it's been a while but I could have sworn you can do DNS requests through a proxy.
Feel free to correct me if I'm wrong though.
If you have something that is sensitive enough to require anonymity you do not want to disclose it to another party.
Proxies are also finicky my honeypot tries DNS resolving via multiple vectors including applets, flash and more recently the dns.resolve API Firefox implemented with 60 onwards. I also return an SSL cert and use OCSP and CRL resolutions to try and get the actual IP address.
Overall proxies and OpenVPN provides are unasked in about 50% of the cases TOR in the high single digits and im not doing anything super sophisticated.
You can ofc go beyond that and fingerprint the browser, use zero days or abuse headless browsers or other frameworks but I’m not that bored yet.
But in any case anything that is too sensitive to send from your own IP should not be sent over a medium that you have no ability to verify if it's being logged and by whom.
Open proxy operators aren't charities most of them are dubious at best.
If you want anonymity cryptocurrency VPS in data heaven jurisdiction or TOR is the best way to go, if you don't need that much anonymity than "proven" no-logging VPN providers are also better since they guarantee higher privacy than unauthenticated open proxies.
This is simply not true in the slightest.
The only DNS request this script will make locally is for www.us-proxy.org.
Additionally, some proxies don't even try to be anonymous and transmit the client ip in the "X-Forward-For" http header field.
The proxies from this list don't usually last that long, so you might have connection problems.
Mine's a bit different though because I need to discard proxy server IPs that are flagged by cloudflare on target sites and only be left with those that work flawlessly. This should be done every couple of hours to ensure the 'freshness' of the proxy server IPs that I have.