[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y ] [Home]
4chanarchives logo
Can I bypass a physical firewall similar to the one pictured?
Images are sometimes not shown due to bandwidth/network limitations. Refreshing the page usually helps.

You are currently reading a thread in /g/ - Technology

Thread replies: 51
Thread images: 5
File: GPZ_1000.png (391 KB, 960x386) Image search: [Google]
GPZ_1000.png
391 KB, 960x386
Can I bypass a physical firewall similar to the one pictured? The company that makes them is called gateprotect.
I can't watch porn in my own house, and now, my university has started using it too so no watching porn there either. Any help /g/? I can get access to the physical machine where I live. Can I bypass it somehow?
>>
File: 1453685392671.png (214 KB, 400x399) Image search: [Google]
1453685392671.png
214 KB, 400x399
>>54863197
Porn is haram, anon.
>>
>>54863197
use a fucking proxy you retard
>>
>>54863197
VPN possibly. Other than that, no.
>>
>>54863197
>I can't watch porn in my own house
why
>>
>>54863197
Use a VPN anon. Buy a ~$5/mo VPS from digital ocean and set it up using TCP on port 443. That's the same port and protocol as HTTPS, they litearlly cannot block it without fucking up the internet.
>>
>>54863563
Any true firewall appliance will be able to detect VPN traffic over 443 and be able to block it.
>>
>>54863197
>can't watch porn in my own house
If you've got a firewall like that in your house and you didn't put it there, it's not your house.
>>
You a graduate student and if your wife or wife's son caught you looking at porn, you would be JUST'd? And the only chance you get to look at porn is while you are working at uni?
>>
>>54863601
You're assuming they block VPNs.
>>
I wish porn was blocked for me.
>>
>>54863601
Tell me exactly how you distinguish between encrypted http traffic and a vpn connection using port 443.
>>
>>54863197
>can't watch porn in own house
Give it back Jamal
>>
>>54863197
>your own house
>physical firewall
underage b& or lives in a dorm
>>
Can you? Nope.

Can someone with dedication and technical aptitude? Yes.
>>
>>54863514
Either because his wife is cucking him or because mommy won't let him corrupt his soul.
>>
>>54863563
>digital ocean

Top tier cuckoldry

>>54863601
That's why you use openVPN and configure it to run on port 80
>>
>>54864746
Uh... You ever heard of packet inspection and traffic flow analysis? Dedicated hardware firewalls like the one OP posted are especially good at it.
>>
>>54864885
Good luck trying to inspect a fucking encrypted packet when you have no private cert.
>>
>>54864885
well it's given that the firewall won't be able to read the content of his traffic, it's encrypted. If it's doing something too clever by half and saying "Ah, the timing of these packets looks like streaming video!" he can juts use youtube-dl or something. To the firewall it'll be indistinguishable from downloading any other file over HTTPS.
>>
>>54863197
post pictures of the cute gf that is cucking you.
>>
>>54864612
Underrated

But same desu.
Makes it less interesting/stimulating irl
>>
>>54863653
This, all of this, and nothing but this.
>>
>>54864920
Cant read the content of the stream? Blocked by default. Wew that was hard.
>>
>>54863197
>I can get access to the physical machine where I live
Take machine offline. Sell components on ebay. Get a better ISP.
>>
>>54864746
Hate to be one of those people that are like "you're retarded"... but anon, you gotta get learned.

https traffic will show up as https traffic, vpn traffic will show up as vpn traffic. https traffic in VPN traffic will show up as vpn traffic. It doesn't matter what port it runs on, packets are packets.
>>
>>54867049
What if he tunnels his vpn over https?
>>
>>54867072
actually, I would try vpn over ssh.
>>
top kek.

Perhaps try not being an ultra-beta.
>>
>>54863197
>define VPN

unless the firewall blocks VPNs, in that case your probably limited to finding some unblocked proxy or Tor, I2P, etc.
>>
File: burgerking-whereisyourgodnow.jpg (22 KB, 555x300) Image search: [Google]
burgerking-whereisyourgodnow.jpg
22 KB, 555x300
>>54863601
>Over 443
Put it over port 80
>>
File: image.png (230 KB, 500x298) Image search: [Google]
image.png
230 KB, 500x298
>>54864920
>>54864937
Guys pls what the fag is wrong with you? A firewall can only block traffic which is not encrypted or decryptable? Are you dumb? The FW don't need the data header to block it, just the source/destination and the other flags are enough for it?

>>54867382
top kek
/thread
>>
>>54868039
How is a firewall suppose to know the source?
>>
>>54867049
>>54868039
obsfproxy, or tunnel it through ssl/ssh.

>>54867382
OpenVPN is port 80 by default, so any decent DPI firewall trying to block VPN connections will look at port 80 packets and reject them if it determines they're VPN packets.
>>
>>54868142
what you mean? source of the vpn server farm, it's not as that difficult.

>>54868151
I don#t think this will help anymore when all the other will be block.
>>
SOCKS proxy over ssh.
>>
>>54868151
>openvpn
>default port 80
>w-w-what, desu?

default port of openvpn is normally 1194? dafuq?
>>
>>54868151
palo altos detect openvpn traffic regardless of port.
>>
>>54864937
What are https handshake headers
>>
>>54868151
OpenVPN default is 1194.
If you were to run it over port 443 it would be much harder to distinguish from HTTPS.
>>
>>54866162
Would that not break all HTTPS sites and online banking etc?
>>
>>54868592
...and?
>>
>>54864920
It's called MITM

bet you had to google that
>>
>>54868592
yeah and? the admin can block also the traffic through 80 and any other port
>>
>>54868607
>>54868630
That would just be dumb as fuck from an individual security/privacy standpoint.
>>
>>54868862
newsflash, companies using deep packet inspecting corporate firewalls don't give a shit about your “privacy”
>>
>>54863197
Yes. Physically wire yourself past it. Take out the Ethernet, put it in the thing past it, unplug the thing. It's in your fucking house. Why do you have this junk inside your house? That makes no sense.

There are far more esoteric ways, including things that tunnel/encapsulate connections (in standard headers like OpenVPN or IKE, or in custom ones fully IND-CCA2 like SILVERBROOK or obfs4, or even protocol masquerading like WHITEBROOK), but you don't need those.

There are even really aggressive ones that will take over the firewall and let you either DoS, monitor or MiTM/infect other users on your network (from inside or outside, RCE, just by sending one UDP packet past it, from any IP address - it's fun when DPI devices try to parse things, particularly easy with AV engines!) but I'm not going to disclose PoCs to you and thereby the vendor, because internet censorship middleboxes are inherently destructive, and I'm not in the business of aiding destruction.
>>
>>54869175
Look at Mr. Fancywords over here!
>>
>>54868160
you retard we're talking about a fucking VPS here
why would they block digital ocean IPs
>>
File: swag.jpg (15 KB, 221x300) Image search: [Google]
swag.jpg
15 KB, 221x300
>>54869869
>you retard we're talking about a fucking VPS here
Yes and where is the problem? Iam talking about a VPS with his server farm, too?

>why would they block digital ocean IPs
Why would they not? The source will be changed by the VPS and you can find out which IP Ranges there Subnets have and block them? Where is the problem now, jamal or pajeet?
>>
>>54870199
>Firewalls are sentient
Thread replies: 51
Thread images: 5

banner
banner
[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y] [Home]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
If a post contains personal/copyrighted/illegal content you can contact me at [email protected] with that post and thread number and it will be removed as soon as possible.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com, send takedown notices to them.
This is a 4chan archive - all of the content originated from them. If you need IP information for a Poster - you need to contact them. This website shows only archived content.