77 karma · joined August 14, 2011
PLAY "MBT180o2P2P8L8GGGL2E-P24P8L8FFFL2D"
The DNS injection is obviously in place. But something strange happened when I checked the SNI filtering. The curl command stopped at "TLSv1.2 (OUT), TLS alert, Client hello (1)" and never exited when I tried to connect to www.bbc.com but with a --connect-to that is not blocked. Nothing strange until now. If SNI blocking is in place, they probably drop all the remaining packets of the connection. The strange thing is that when I try the opposite test and I connect to www.kernel.org (not blocked in Iran, too!) but with www.bbc.com SNI it still stops at TLS client hello.
First I thought they blocked the IP address, but I was able to connect to 212.58.244.210 (the IP address of www.bbc.com) on port 443 with telnet command. So, is Iran's regime using some other blocking mechanism that I'm not aware of? Or am I doing some kind of mistake?
It is a dangerous mistake to decide what kind of privacy people need. Privacy should be absolute and without conditions.
What if you live in Iran? Some Ubuntu packages are already inaccessible due to government's pornography keywords censorship. E.g. I can't download "libjs-hooker" from this http link http://archive.ubuntu.com/ubuntu/pool/universe/n/node-hooker... from Iran. What if the government decides to censor the "tor" package?
vi()
{
emacs -nw --eval '(and (switch-to-buffer "foobar") (setq viper-mode t) (setq viper-inhibit-startup-message t) (setq viper-expert-level 1) (viper-mode))' "$@"
}
alias vim=vi
alias vim.tiny=vi
alias vim.basic=visudo add-apt-repository ppa:mohammad-sepent/ppa
sudo apt-get update
sudo apt-get install issh
For other distros you can grab the .deb or the source package from the given link.
I wrote a simple script to do this, and I would like to share it with all of my countrymen:
https://launchpad.net/~mohammad-sepent/+archive/ppa/+package...
To use it, just replace ssh command with issh like this:
issh user@hostname [other-ssh-options]
"Microsoft welcomes OSI open source to Win8 store, GPL blocked at the door"
link: http://www.theregister.co.uk/2011/12/08/open_source_windows_...
Welkom bij JS/Linux
JS/Linux login:
http://www.hostmypic.net/pictures/93969c88a3ecaac84ba81c8d38...
And it is almost obvious that we have two data sets: (A, D, E) and (B, C, F)
http://www.wired.com/threatlevel/2010/06/wikileaks-documents... says "The siphoned documents, supposedly stolen by Chinese hackers or spies who were using the Tor network to transmit the data,..."
What kind of sick spy uses TOR to send important documents in palin text?
[1-7 are ISP routers]
8. 78.38.255.89
9. 78.38.245.17
10. 213.248.76.5
11. 80.91.248.94
12. 80.91.253.118
13. 213.155.130.243
14. 213.248.83.94
15. 72.14.238.232
16. 209.85.251.88
17. 209.85.255.234
18. 209.85.255.231
19. 64.233.175.98
I used mtr and the route to google is changing every several seconds, but I thinks it's normal.
All I know is that internet blocking happens in LCT [78.38.255.] or KAMYARAN [78.38.245.].
My brother works in a company that produces spying software for government. Days ago, he told me he himself has written several programs to spy on yahoo, hotmail and gmail but he thought they couldn't deploy the gmail program because of https. I guess, he should think again.
I am scared. My only hope was SSL and I can't trust that anymore?