GoodbyeDPI – Passive Deep Packet Inspection Blocker / Circumvention Utility
github.com
github.com
If so, this is a very old idea (I, uh, co-invented it?). A lot of DPI gear isn't built for serious security, but rather best effort, and I'm sure basic TCP tricks like this will bypass those. But you should be aware that serious, modern middleboxes were very definitely built with knowledge of fragrouter-type tricks (and of evasion more generally), and you're better off using a VPN than relying on stuff like this if your evasion actually matters from an opsec perspective.
Not to imply that GoodbyeDPI assuages all my doubts, either.
I suggest you consult a book like "The TCP/IP Guide" to get an overview of the main data protocols and how they work. In this day and age, everybody ought to know something about the basic protocols which form the bedrock of our networked society.
No, not really. GoodbyeDPI does not perform IP-level fragmentation, it does not generate/send any packets at all, it only modifies them or drop them.
What's called "Fragmentation" in GoodbyeDPI is TCP Window Size shrinking, to force OS to send TCP packets of small size.
I'm aware of fragroute, and I have plans to implement some of its techniques in GoodbyeDPI.
TCP-level fragmentation for first data packet
TCP-level fragmentation for persistent (keep-alive) HTTP sessions
Replacing Host header with hoSt
Removing space between header name and value in Host header
Adding additional space between HTTP Method (GET, POST etc) and URI
Mixing case of Host header value
Very interesting. This is, of course, depending on the DPI-blocking application to be pretty poorly engineered, but I wouldn't be surprised. I'd be interested to see which national DPI solutions (GFC, Russia) this successfully circumvents, not just commercial products.For that, I wrote Blockcheck utility to check whether censorship circumvention techniques could be applied on this ISP or not.
> I'd be interested to see which national DPI solutions (GFW, Russia) this successfully circumvents
The GFW seems to do TCP stream reassembly. I don't think this will work in China.
I have plans to implement INTANG methods in GoodbyeDPI, but it requires some architectural changes first.
Modern DPIs in Russia also perform stream reassembly or at least have proper state machine, so they can't be circumvented that easily anymore, unfortunately.
1) How much it looks like *nix. 2) How hard it is to actually use your own code.
> Windows Server 2016 systems must have secure boot disabled.
That's no good.
What do you mean by this? It's easy enough with test-signing. Just use SignTool sign to sign your binary. Then sc create to create the service for the driver, and sc start to start it as usual.
> How much it looks like 'nix.
Also not sure what you mean by this either... to me there's a world of difference between Windows and 'nix kernel development.
Overall very user hostile, and it leaves one with the impression they don't want you to run your own code or let other people run your code without paying protection money.
For the other part... go look at the driver documentation. The names are different but the patterns are all the same except for a few places.
If your complaint is that you have to cough up $$$ to have your driver be trusted by other users' machines, yeah, I'm happy to rant about that issue, but that's not an issue with the "difficulty" of the process. That's like saying it's hard to use a Lamborghini because it's too expensive.
As for the names and patterns... idk, it's hard for me to see what's similar, except that both systems have file systems, both have handles/descriptors, etc... which is hardly an interesting point. Everything from the way you hook I/O to the way syscalls are handled to the quality of the documentation is vastly different on each system.
Err, it's code I wrote, or code I am likely to be familiar with? My issue isn't with the feature of driver signing but its application. I can choose to be in test signing mode on Linux or not, and if I am, it doesn't gimp the system in arbitrary ways.
Look again, Windows is like a black box over a rewritten Unix kernel. It's kind of funny. It took a while for it to click.
I don't know what "gimp the system in arbitrary ways" means. I've been running Windows in test-signing mode for years with no problem. Microsoft doesn't officially bless it, but that doesn't exactly matter in any material way.
I suspect more elaborate evasions might necessary - e.g. tcp fragmentation with inconsistent fragments where the understanding of which final 'reassembly' the target gets is necessary to understand what the DPI system is seeing. This might also ring alarm bells at the intermediate firewall, though. The problem is with the censorship firewalls is that they can just throw stuff on the floor if they feel a bit suspicious about it; they can be inherently 'worse' in their liveness guarantees than, say, a corporate DPI product.
We still don't have national-wide firewall like that in China, each ISP (and we have 1000+ of them) performs censorship using either dumb IP blackholing (breaks a lot of legitimate stuff), on-path DPI (I call it "passive" in GoodbyeDPI, DPI which receive mirrored traffic and can only inject something but not prevent the connectivity per se), in-path DPI (DPI as a router/bridge).
Most DPI systems in Russia were specifically created for Russian censorship (i.e. capable only for HTTP URL and TLS SNI introspection), from scratch. Some ISP have their own in-house DPI systems. These systems were just not designed to handle packets fragmented on TCP or IP level at the beginning, because it's rarely the case in the real world.
If you want to learn more, visit internet censorship forum I created. I write about different DPI systems there and trying to document internet censorship in Russia as a whole. https://ntc.party/c/internet-censorship-all-around-the-world...
Without GoodbyeDPI, the career introspects HTTP User-Agent header and the internet gets blocked if it looks like a PC user agent. With GoodbyeDPI, career systems break and could not introspect the user agent header.
The name is misleading: its a shield, for one weapon. Its not armour against all weapons
Edit: my concern is that the engineers at GFW might quickly upgrade their system to target it.
Anyway, the TCP/HTTP tricks discussed here may work for some time or not, but we really do not expect much from that.
Isn't DPI used to block VPNs?