{"id":52639,"date":"2019-11-13T00:00:00","date_gmt":"2019-11-12T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/domen-fronting-na-baze-tls-1-3"},"modified":"2026-05-20T19:54:20","modified_gmt":"2026-05-20T17:54:20","slug":"domen-fronting-na-baze-tls-1-3","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/domen-fronting-na-baze-tls-1-3","title":{"rendered":"Domain fronting me baz\u00eb TLS 1.3","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<h3>Hyrje<\/h3>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/9e81fbeed9c8d41c7e4f583235541370.jpg\" alt=\"Domain fronting me baz\u00eb TLS 1.3\" \/><br \/>\nSistemat moderne t\u00eb korporatave p\u00ebr filtrimin e p\u00ebrmbajtjes, nga prodhues si Cisco, BlueCoat, FireEye, kan\u00eb shum\u00eb gj\u00ebra t\u00eb p\u00ebrbashk\u00ebta me homolog\u00ebt e tyre m\u00eb t\u00eb fuqish\u00ebm - sistemet DPI, t\u00eb cilat po implementohen n\u00eb nivel komb\u00ebtar. Thelbi i funksionimit t\u00eb t\u00eb dyjave \u00ebsht\u00eb q\u00eb t\u00eb monitorojn\u00eb trafikun e internetit t\u00eb ardhur dhe t\u00eb shkatur, dhe n\u00eb baz\u00eb t\u00eb listave t\u00eb zeza\/ t\u00eb bardha, t\u00eb marrin vendime p\u00ebr bllokimin e lidhjeve t\u00eb internetit. Dhe duke qen\u00eb se t\u00eb dyja mb\u00ebshteten n\u00eb parime t\u00eb ngjashme, m\u00ebnyrat e anashkalimit gjithashtu do t\u00eb ken\u00eb shum\u00eb ngjasime.<\/p>\n<p>Nj\u00eb nga teknologjit\u00eb q\u00eb lejon t\u00eb anashkalohet mjaft efektivisht si DPI ashtu edhe sistemet korporative \u00ebsht\u00eb teknologjia e domain fronting. Thelbi i saj q\u00ebndron n\u00eb faktin se ne shkojm\u00eb te nj\u00eb burim t\u00eb bllokuar, duke u mbuluar pas nj\u00eb domene publik, me reputacion t\u00eb mir\u00eb, i cili me siguri nuk do t\u00eb bllokohet nga asnj\u00eb sistem, p\u00ebr shembull google.com.<\/p>\n<p>\u00cbsht\u00eb shkruar mjaft p\u00ebr k\u00ebt\u00eb teknologji dhe jan\u00eb dh\u00ebn\u00eb shum\u00eb shembuj. Megjithat\u00eb, teknologjit\u00eb e fundit si DNS-over-HTTPS dhe encrypted-SNI, si edhe versioni i ri i protokollit TLS 1.3, ofrojn\u00eb nj\u00eb mund\u00ebsi p\u00ebr t\u00eb shqyrtuar nj\u00eb variant tjet\u00ebr t\u00eb domain fronting.<br \/>\n<a rel=\"nofollow\" name=\"habracut\"><\/a><\/p>\n<h3>Le t'i hedhim nj\u00eb sy teknologjis\u00eb<\/h3>\n<p>Fillimisht, le t\u00eb p\u00ebrcaktojm\u00eb disa koncepte baz\u00eb, n\u00eb m\u00ebnyr\u00eb q\u00eb t\u00eb gjith\u00eb t\u00eb ken\u00eb nj\u00eb kuptim t\u00eb qart\u00eb se kush \u00ebsht\u00eb kush dhe p\u00ebrse \u00ebsht\u00eb e nevojshme kjo. Ne p\u00ebrmend\u00ebm mekanizmin e eSNI, puna e s\u00eb cilit do t\u00eb shqyrtohet m\u00eb von\u00eb. Mekanizmi eSNI (encrypted Server Name Indication) \u00ebsht\u00eb nj\u00eb variant i mbrojtur i SNI, i disponuesh\u00ebm vet\u00ebm p\u00ebr protokollin TLS 1.3. Thelbi \u00ebsht\u00eb t\u00eb kriptoj\u00eb, p\u00ebrfshir\u00eb informacionin mbi se n\u00eb cilin domen po d\u00ebrgohet k\u00ebrkesa.<\/p>\n<p>Tani le t\u00eb shqyrtojm\u00eb funksionimin e mekanizmit eSNI n\u00eb praktik\u00eb.<\/p>\n<p>Supozoni se kemi nj\u00eb burim n\u00eb internet, i cili bllokohet nga nj\u00eb zgjidhje moderne DPI (le t\u00eb marrim p\u00ebr shembull, torrent tracker-in e njohur \u2014 rutracker.nl). Kur p\u00ebrpiqemi t\u00eb hyjm\u00eb n\u00eb faqen e torrent tracker-it, ne shohim standardin e mesazhit t\u00eb bllokimit nga provajderi:<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/6a2aeccd290f9046efa799166ffa875f.jpg\" alt=\"Domain fronting me baz\u00eb TLS 1.3\" \/><\/p>\n<p>N\u00eb faqen e RKN, ky domen n\u00eb t\u00eb v\u00ebrtet\u00eb \u00ebsht\u00eb i p\u00ebrfshir\u00eb n\u00eb listat e bllokimeve:<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/1c881e2c8403cf85f77d9d74cbf3f54e.jpg\" alt=\"Domain fronting me baz\u00eb TLS 1.3\" \/><\/p>\n<p>Kur k\u00ebrkoni informacionet whois - duket se domeni \u00ebsht\u00eb \"fshehur\" pas sh\u00ebrbimit t\u00eb shp\u00ebrndarjes s\u00eb mjeteve Cloudflare.<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/55b472de20a6eb85162ffbba286b9487.jpg\" alt=\"Domain fronting me baz\u00eb TLS 1.3\" \/><\/p>\n<p>Por, p\u00ebrkund\u00ebr \"specialist\u00ebve\" t\u00eb RKN-s\u00eb, punonj\u00ebsit m\u00eb teknik\u00eb t\u00eb Beeline (ose t\u00eb m\u00ebsuar nga p\u00ebrvoja e hidhur e rregullatorit ton\u00eb t\u00eb njohur) nuk e bllokuan thjesht faqen sipas adres\u00ebs IP - por e fut\u00ebn n\u00eb list\u00ebn e ndalimeve sakt\u00ebsisht <a href=\"https:\/\/prohoster.info\/sq\/domain\/\">emri i domenit<\/a>. Kjo \u00ebsht\u00eb e leht\u00eb p\u00ebr t'u verifikuar, n\u00ebse shihni se cilat domenet e tjera jan\u00eb t\u00eb fshehura pas k\u00ebtij t\u00eb nj\u00ebjtit <a href=\"https:\/\/prohoster.info\/sq\/lir\/ipv4\/\">IP-adres\u00ebn<\/a>, p\u00ebr t\u00eb vizituar nj\u00ebrin prej tyre dhe p\u00ebr t\u00eb par\u00eb se qasja nuk \u00ebsht\u00eb bllokuar:<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/fe7de472c9c5cc8abe4d4ed6cacdd21c.jpg\" alt=\"Domain fronting me baz\u00eb TLS 1.3\" \/><\/p>\n<p>Si ndodh kjo? Si e di DPI i ofruesit se n\u00eb cilin nga domenet \u00ebsht\u00eb duke shkuar shfletuesi im, duke qen\u00eb se t\u00eb gjitha komunikimet ndodhin p\u00ebrmes protokollit https, dhe deri tani nuk kemi v\u00ebn\u00eb re nd\u00ebrrime t\u00eb certifikatave https nga Beeline? A \u00ebsht\u00eb ai ndonj\u00eb form\u00eb e parashikueshme apo m\u00eb ndjekin?<\/p>\n<p>Do t\u00eb p\u00ebrpiqemi t\u00eb p\u00ebrgjigjemi n\u00eb k\u00ebt\u00eb pyetje, duke shqyrtuar trafikun p\u00ebrmes wireshark<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/330f05030e9edb066bf2fd80c935e0c3.jpg\" alt=\"Domain fronting me baz\u00eb TLS 1.3\" \/><\/p>\n<p>N\u00eb skrin, duket se fillimisht shfletuesi merr adres\u00ebn IP t\u00eb serverit n\u00ebp\u00ebrmjet DNS, m\u00eb pas ndodh p\u00ebrshkrimi standard TCP me serverin e destinacionit, dhe m\u00eb pas shfletuesi p\u00ebrpiqet t\u00eb krijoj\u00eb nj\u00eb lidhje ssl me serverin. N\u00eb k\u00ebt\u00eb m\u00ebnyr\u00eb d\u00ebrgon nj\u00eb paket\u00eb <a href=\"https:\/\/prohoster.info\/sq\/ssl-sertifikat\/\">SSL<\/a> P\u00ebrsh\u00ebndetje Klienti, i cili p\u00ebrmban emrin e domain-it origjinal n\u00eb form\u00eb t\u00eb hapur. Ky fush\u00eb \u00ebsht\u00eb e nevojshme p\u00ebr serverin frontend t\u00eb cloudflare p\u00ebr t\u00eb drejtuar n\u00eb m\u00ebnyr\u00eb t\u00eb sakt\u00eb lidhjen. K\u00ebtu na kap DPI i ofruesit, duke nd\u00ebrprer\u00eb lidhjen ton\u00eb. N\u00eb k\u00ebt\u00eb rast, ne nuk marrim asnj\u00eb ndihmes\u00eb nga ofruesi dhe shohim nj\u00eb gabim standard t\u00eb shfletuesit, sikur shfaqja t\u00eb jet\u00eb \u00e7aktivizuar ose thjesht t\u00eb mos funksionoj\u00eb:<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/9642c783158c0ace70c50fea917e7d9d.jpg\" alt=\"Domain fronting me baz\u00eb TLS 1.3\" \/><\/p>\n<p>Tani le t\u00eb aktivizojm\u00eb mekanizmin e eSNI n\u00eb shfletues, si\u00e7 \u00ebsht\u00eb shkruar n\u00eb udh\u00ebzim p\u00ebr <a href=\"https:\/\/miketabor.com\/enable-dns-over-https-and-encrypted-sni-in-firefox\/\" rel=\"nofollow\">Firefox <\/a>:<br \/>\nP\u00ebr k\u00ebt\u00eb, hapim faqen e konfigurimit t\u00eb Firefox <b>about:config<\/b> dhe aktivizojm\u00eb cil\u00ebsimet e m\u00ebposhtme:<\/p>\n<pre><code class=\"plaintext\">network.trr.mode = 2;\nnetwork.trr.uri = https:\/\/mozilla.cloudflare-dns.com\/dns-query\nnetwork.security.esni.enabled = true\n<\/code><\/pre>\n<p>Pasi t\u00eb b\u00ebjm\u00eb k\u00ebt\u00eb, do t\u00eb verifikojm\u00eb sakt\u00ebsin\u00eb e funksionimit t\u00eb cil\u00ebsimeve n\u00eb faqen e cloudflare n\u00eb <a href=\"https:\/\/www.cloudflare.com\/ssl\/encrypted-sni\/\" rel=\"nofollow\">lidhjes<\/a> dhe do t\u00eb provojm\u00eb trikun me tracker-in ton\u00eb t\u00eb torrentit p\u00ebrs\u00ebri.<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/4996a67993bd2f1b5ebeb1ac156ba29a.jpg\" alt=\"Domain fronting me baz\u00eb TLS 1.3\" \/><\/p>\n<p>Voil\u00e0. Tracker-i yn\u00eb i preferuar u hap, pa asnj\u00eb VPN dhe server proxy. Tani le t\u00eb shohim dumps-in e trafikut n\u00eb wireshark, \u00e7far\u00eb ndodhi.<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/a7e305afbf29896f6ebb82e53c7fed88.jpg\" alt=\"Domain fronting me baz\u00eb TLS 1.3\" \/><\/p>\n<p>Tani her\u00eb paketi ssl client hello nuk p\u00ebrmban qart\u00eb domenin destinacion, por n\u00eb vend t\u00eb k\u00ebsaj ka nj\u00eb fush\u00eb t\u00eb re \u2014 encrypted_server_name \u2014 dhe aty gjendet vlera rutracker.nl, e cila mund t\u00eb dekoduar vet\u00ebm nga serveri frontend i cloudflare. Prandaj, DPI i ofruesit nuk ka asnj\u00eb mund\u00ebsi tjet\u00ebr p\u00ebrve\u00e7se t\u00eb l\u00ebr\u00eb t\u00eb kaloj\u00eb k\u00ebt\u00eb trafik. Nuk ka asnj\u00eb opsion tjet\u00ebr p\u00ebr encryption.<\/p>\n<p>Tani kemi par\u00eb se si funksionon teknologjia n\u00eb shfletues \u2014 le t'i japim nj\u00eb shans p\u00ebr ta aplikuar at\u00eb n\u00eb gj\u00ebra m\u00eb specifike dhe interesante. Fillimisht, do ta m\u00ebsojm\u00eb curl se si t\u00eb p\u00ebrdor\u00eb eSNI p\u00ebr t\u00eb punuar me TLS 1.3, dhe gjithashtu do t\u00eb shohim si funksionon domen-fronting me eSNI.<\/p>\n<h3>Domen-fronting me eSNI<\/h3>\n<p>Duke marr\u00eb parasysh se curl p\u00ebr lidhjen me protokollin https p\u00ebrdor bibliotek\u00ebn standarde openssl, s\u00eb pari \u00ebsht\u00eb e nevojshme t\u00eb sigurojm\u00eb mb\u00ebshtetje p\u00ebr eSNI aty. N\u00eb deg\u00ebt master t\u00eb openssl, mb\u00ebshtetja p\u00ebr eSNI aktualisht nuk ekziston, k\u00ebshtu q\u00eb duhet t\u00eb shkarkojm\u00eb nj\u00eb deg\u00eb speciale openssl, ta kompilohem dhe ta instalojm\u00eb.<\/p>\n<p>Klonojm\u00eb repositorin nga gitHub dhe e kompilohemi si zakonisht:<\/p>\n<pre><code class=\"plaintext\">$ git clone https:\/\/github.com\/sftcd\/openssl\n$ cd openssl\n$ .\/config\n\n$ make\n$ cd esnistuff\n$ make\n<\/code><\/pre>\n<p>M\u00eb pas, do t\u00eb klonojm\u00eb ruajtjen me curl dhe do t\u00eb konfigurojm\u00eb kompaktimin e saj duke p\u00ebrdorur bibliotek\u00ebn ton\u00eb t\u00eb mbledhur openssl:<\/p>\n<pre><code class=\"plaintext\">$ cd $HOME\/code\n$ git clone https:\/\/github.com\/niallor\/curl.git curl-esni\n$ cd curl-esni\n\n$ export LD_LIBRARY_PATH=\/opt\/openssl\n$ .\/buildconf\n$ LDFLAGS=\"-L\/opt\/openssl\" .\/configure --with-ssl=\/opt\/openssl --enable-esni --enable-debug\n<\/code><\/pre>\n<p>K\u00ebtu \u00ebsht\u00eb e r\u00ebnd\u00ebsishme t\u00eb tregoni sakt\u00ebsisht t\u00eb gjitha katalog\u00ebt ku ndodhet openssl (n\u00eb rastin ton\u00eb, ky \u00ebsht\u00eb \/opt\/openssl\/) dhe t\u00eb siguroheni q\u00eb procesi i konfigurimit kalon pa gabime.<\/p>\n<p>N\u00ebse konfigurimi p\u00ebrfundon me sukses, do t\u00eb shohim k\u00ebt\u00eb varg:<\/p>\n<p><b>WARNING: esni ESNI e aktivizuar por e Markuar si EXPERIMENTAL. P\u00ebrdorni me kujdes!<\/b><\/p>\n<pre><code class=\"plaintext\">$ make<\/code><\/pre>\n<p>Pas p\u00ebrfundimit t\u00eb suksessh\u00ebm t\u00eb paket\u00ebs, do t\u00eb p\u00ebrdorim nj\u00eb skedar t\u00eb ve\u00e7ant\u00eb bash nga openssl p\u00ebr t\u00eb konfiguruar dhe p\u00ebr t\u00eb nisur curl. Do ta kopjojm\u00eb at\u00eb n\u00eb katalogun me curl p\u00ebr leht\u00ebsi:<\/p>\n<pre><code class=\"plaintext\">cp \/opt\/openssl\/esnistuff\/curl-esni <\/code><\/pre>\n<p>dhe do t\u00eb kryejm\u00eb nj\u00eb k\u00ebrkes\u00eb https testuese n\u00eb serverin cloudflare, duke regjistruar nj\u00ebkoh\u00ebsisht DNS dhe paketa TLS n\u00eb Wireshark.<\/p>\n<pre><code class=\"plaintext\">$ ESNI_COVER=\"www.hello-rkn.ru\" .\/curl-esni https:\/\/cloudflare.com\/<\/code><\/pre>\n<p>N\u00eb p\u00ebrgjigjen e serverit, p\u00ebrve\u00e7 shum\u00eb informacionit t\u00eb ndihm\u00ebs nga openssl dhe curl, do t\u00eb marr\u00eb nj\u00eb p\u00ebrgjigje HTTP me kodin 301 nga cloudflare.<\/p>\n<pre><code class=\"plaintext\">HTTP\/1.1 301 Moved Permanently\n&lt; Date: Sun, 03 Nov 2019 13:12:55 GMT\n&lt; Transfer-Encoding: chunked\n&lt; Connection: keep-alive\n&lt; Cache-Control: max-age=3600\n&lt; Expires: Sun, 03 Nov 2019 14:12:55 GMT\n&lt; Location: https:\/\/www.cloudflare.com\/\n<\/code><\/pre>\n<p>kjo tregon se k\u00ebrkesa jon\u00eb u dor\u00ebzua me sukses te serveri i destinacionit, u d\u00ebgjua dhe u p\u00ebrpunua.<\/p>\n<p>Tani le t\u00eb shohim dump-in e trafikut n\u00eb wireshark, dometh\u00ebn\u00eb, at\u00eb q\u00eb pa n\u00eb k\u00ebt\u00eb rast DPI i ofruesit.<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/25945e28e6ff5dec3ab92e018b91bab1.jpg\" alt=\"Domain fronting me baz\u00eb TLS 1.3\" \/><\/p>\n<p>Duket se fillimisht curl iu drejtua serverit DNS p\u00ebr \u00e7el\u00ebsin publik eSNI p\u00ebr serverin cloudflare \u2014 k\u00ebrkesa TXT DNS p\u00ebr _esni.cloudflare.com (paketi \u211613). Pastaj, duke p\u00ebrdorur bibliotek\u00ebn openssl, curl d\u00ebrgoi nj\u00eb k\u00ebrkes\u00eb TLS 1.3 te serveri cloudflare, n\u00eb t\u00eb cil\u00ebn fusha SNI ishte e enkriptuar me \u00e7el\u00ebsin publik t\u00eb marr\u00eb n\u00eb faz\u00ebn e m\u00ebparshme (paketi \u211622). <b>Por, p\u00ebrve\u00e7 fush\u00ebs eSNI, n\u00eb paket\u00ebn SSL-hello ishte futur gjithashtu nj\u00eb fush\u00eb me SNI t\u00eb zakonsh\u00ebm \u2014 t\u00eb hapur, t\u00eb cilin mund ta specifikojm\u00eb n\u00eb nj\u00eb rend t\u00eb \u00e7far\u00ebdo (n\u00eb k\u00ebt\u00eb rast \u2014 <a href=\"http:\/\/www.hello-rkn.ru\" rel=\"nofollow\">www.hello-rkn.ru<\/a>). <\/b><\/p>\n<p>Kjo fush\u00eb e SNI t\u00eb hapur nuk u mor parasysh gjat\u00eb p\u00ebrpunimit nga serverat cloudflare dhe ishte vet\u00ebm nj\u00eb mask\u00eb p\u00ebr DPI-n\u00eb e ofruesit. Serveri cloudflare pranoi paket\u00ebn ton\u00eb ssl-hello, e dekriptoi eSNI-n\u00eb, e nxori SNI-n\u00eb origjinale nga aty dhe e p\u00ebrpunoi at\u00eb si\u00e7 ishte parashikuar (b\u00ebri gjith\u00e7ka ashtu si\u00e7 ishte planifikuar gjat\u00eb zhvillimit t\u00eb eSNI).<\/p>\n<p>E vetmi q\u00eb mund t\u00eb kapim n\u00eb k\u00ebt\u00eb rast nga k\u00ebndv\u00ebshtrimi i DPI \u00ebsht\u00eb k\u00ebrkesa fillestare DNS p\u00ebr _esni.cloudflare.com. Por ne e b\u00ebm\u00eb k\u00ebrkes\u00ebn DNS t\u00eb hapur vet\u00ebm p\u00ebr t\u00eb treguar se si funksionon ky mekaniz\u00ebm nga brenda.<\/p>\n<p>P\u00ebr t\u00eb hequr p\u00ebrfundimisht tok\u00ebn nga posht\u00eb DPI, ne p\u00ebrdorim mekanizmin e p\u00ebrmendur tashm\u00eb DNS-over-HTTPS. Nj\u00eb shpjegim i vog\u00ebl \u2013 DOH \u00ebsht\u00eb protokolli q\u00eb lejon mbrojtjen nga sulmi \"njeri n\u00eb mes\" duke d\u00ebrguar k\u00ebrkesat DNS p\u00ebrmes protokollit HTTPS.<\/p>\n<p>Do ta kryejm\u00eb k\u00ebrkes\u00ebn p\u00ebrs\u00ebri, por k\u00ebt\u00eb her\u00eb \u00e7el\u00ebsat publik\u00eb eSNI do t'i marrim p\u00ebrmes protokollit https, jo DNS:<\/p>\n<pre><code class=\"plaintext\">ESNI_COVER=\"www.hello-rkn.ru\" DOH_URL=https:\/\/mozilla.cloudflare-dns.com\/dns-query .\/curl-esni https:\/\/cloudflare.com\/<\/code><\/pre>\n<p>Dumpi i trafikut t\u00eb k\u00ebrkes\u00ebs \u00ebsht\u00eb paraqitur n\u00eb screenshot-in m\u00eb posht\u00eb:<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/284d1d8110b24c647a57e644d93a8142.jpg\" alt=\"Domain fronting me baz\u00eb TLS 1.3\" \/><\/p>\n<p>N\u00eb t\u00eb duket se fillimisht curl i drejtohet serverit mozilla.cloudflare-dns.com p\u00ebrmes protokollit DoH (konexioni https me serverin 104.16.249.249), p\u00ebr t\u00eb marr\u00eb nga ata vlerat e \u00e7el\u00ebsave publik\u00eb p\u00ebr enkriptimin e SNI, dhe pastaj drejtohet te serveri q\u00ebllim t\u00eb mbuluar nga domeni. <a href=\"http:\/\/www.hello-rkn.ru\" rel=\"nofollow\">www.hello-rkn.ru<\/a>.<\/p>\n<p>P\u00ebrve\u00e7 rezolutorit DoH t\u00eb p\u00ebrmendur m\u00eb sip\u00ebr mozilla.cloudflare-dns.com, ne gjithashtu mund t\u00eb p\u00ebrdorim sh\u00ebrbime t\u00eb tjera t\u00eb njohura DoH, p\u00ebr shembull, nga korporata e famshme e s\u00eb keqes.<br \/>\nDo ta realizojm\u00eb nj\u00eb k\u00ebrkes\u00eb t\u00eb till\u00eb:<\/p>\n<pre><code class=\"plaintext\">ESNI_COVER=\"www.kremlin.ru\" DOH_URL=https:\/\/dns.google\/dns-query .\/curl-esni https:\/\/rutracker.nl\/<\/code><\/pre>\n<p>Dhe do t\u00eb marrim nj\u00eb p\u00ebrgjigje:<\/p>\n<pre><code class=\"plaintext\">&lt; HTTP\/1.1 301 Moved Permanently\n&lt; Date: Sun, 03 Nov 2019 14:10:22 GMT\n&lt; Content-Type: text\/html\n&lt; Transfer-Encoding: chunked\n&lt; Connection: keep-alive\n&lt; Set-Cookie: __cfduid=da0144d982437e77b0b37af7d00438b1a1572790222; expires=Mon, 02-Nov-20 14:10:22 GMT; path=\/; domain=.rutracker.nl; HttpOnly; Secure\n&lt; Location: https:\/\/rutracker.nl\/forum\/index.php\n&lt; CF-Cache-Status: DYNAMIC\n&lt; Expect-CT: max-age=604800, report-uri=&quot;https:\/\/report-uri.cloudflare.com\/cdn-cgi\/beacon\/expect-ct&quot;\n&lt; Server: cloudflare\n&lt; CF-RAY: 52feee696f42d891-CPH\n<\/code><\/pre>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/c77b8a396e7d20f0b4d74b61380595df.jpg\" alt=\"Domain fronting me baz\u00eb TLS 1.3\" \/><\/p>\n<p>N\u00eb k\u00ebt\u00eb rast, ne iu drejtuam serverit t\u00eb bllokuar rutracker.nl, duke p\u00ebrdorur nj\u00eb zgjidh\u00ebs DoH dns.google (k\u00ebtu nuk ka ndonj\u00eb gabim, tani korporata e njohur ka nj\u00eb domene t\u00eb nivelit t\u00eb par\u00eb) dhe u mbulua me nj\u00eb domene tjet\u00ebr, bllokimi i t\u00eb cilit \u00ebsht\u00eb rrept\u00ebsisht i ndaluar nga \u00e7do DPI n\u00ebn k\u00ebrc\u00ebnimin e d\u00ebnimit me vdekje. Nga p\u00ebrgjigja e marr\u00eb, mund t\u00eb kuptohet se k\u00ebrkesa jon\u00eb u p\u00ebrpunua me sukses.<\/p>\n<p>Si nj\u00eb kontroll t\u00eb shtuar p\u00ebr t\u00eb par\u00eb se si DPI e ofruesit reagon ndaj SNI t\u00eb hapur, t\u00eb cilin e d\u00ebrgojm\u00eb si mbules\u00eb \u2014 ne mund t\u00eb b\u00ebjm\u00eb nj\u00eb k\u00ebrkes\u00eb p\u00ebr rutracker.nl duke u mbrojtur me ndonj\u00eb burim tjet\u00ebr t\u00eb ndaluar, p\u00ebr shembull nj\u00eb tjet\u00ebr 'torrenti i mir\u00eb':<\/p>\n<pre><code class=\"plaintext\">$ ESNI_COVER=\"rutor.info\" DOH_URL=https:\/\/dns.google\/dns-query .\/curl-esni https:\/\/rutracker.nl\/<\/code><\/pre>\n<p>Nuk do t\u00eb marrim p\u00ebrgjigje nga serveri, pasi k\u00ebrkesa jon\u00eb do t\u00eb bllokohet nga sistemi DPI.<\/p>\n<h3>Nj\u00eb p\u00ebrfundim i vog\u00ebl p\u00ebr pjes\u00ebn e par\u00eb<\/h3>\n<p>Pra, na ka arritur t\u00eb tregojm\u00eb funksionalitetin e eSNI me openssl dhe curl dhe t\u00eb verifikojm\u00eb funksionin e domain fronting bazuar n\u00eb eSNI. Po ashtu, mund t\u00eb adaptojm\u00eb mjetet tona t\u00eb preferuara q\u00eb p\u00ebrdorin bibliotek\u00ebn openssl p\u00ebr t\u00eb punuar \"n\u00eb m\u00ebnyr\u00eb t\u00eb fsheht\u00eb\" me domene t\u00eb tjera. M\u00eb shum\u00eb rreth k\u00ebsaj - n\u00eb artikujt tan\u00eb t\u00eb ardhsh\u00ebm.<\/p>\n<p>Burimi: <a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/475372\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0421\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0435 \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u044b\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430, \u043e\u0442 \u0442\u0430\u043a\u0438\u0445 \u0438\u043c\u0435\u043d\u0438\u0442\u044b\u0445 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u0435\u0439 \u043a\u0430\u043a Cisco, BlueCoat, FireEye \u0438\u043c\u0435\u044e\u0442 \u0434\u043e\u0432\u043e\u043b\u044c\u043d\u043e \u043c\u043d\u043e\u0433\u043e \u043e\u0431\u0449\u0435\u0433\u043e \u0441 \u0431\u043e\u043b\u0435\u0435 \u043c\u043e\u0449\u043d\u044b\u043c\u0438 \u0438\u0445 \u0441\u043e\u0431\u0440\u0430\u0442\u044c\u044f\u043c\u0438 \u2014 DPI \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0443\u0441\u0438\u043b\u0435\u043d\u043d\u043e \u0432\u043d\u0435\u0434\u0440\u044f\u044e\u0442\u0441\u044f \u043d\u0430 \u043d\u0430\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u043c \u0443\u0440\u043e\u0432\u043d\u0435. \u0421\u0443\u0442\u044c \u0440\u0430\u0431\u043e\u0442\u044b \u0438 \u0442\u0435\u0445 \u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e\u0431\u044b \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u044c \u0434\u043e\u0441\u043c\u043e\u0442\u0440 \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u0433\u043e \u0438 \u0438\u0441\u0445\u043e\u0434\u044f\u0449\u0435\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0438, \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0430\u043d\u0438\u0438 \u0447\u0435\u0440\u043d\u044b\u0445\/\u0431\u0435\u043b\u044b\u0445 \u0441\u043f\u0438\u0441\u043a\u043e\u0432, \u043f\u0440\u0438\u043d\u0438\u043c\u0430\u0442\u044c \u0440\u0435\u0448\u0435\u043d\u0438\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-52639","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0421\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0435 \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u044b\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/domen-fronting-na-baze-tls-1-3\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0414\u043e\u043c\u0435\u043d-\u0444\u0440\u043e\u043d\u0442\u0438\u043d\u0433 \u043d\u0430 \u0431\u0430\u0437\u0435 TLS 1.3 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0421\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0435 \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u044b\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/domen-fronting-na-baze-tls-1-3\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-12T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-05-20T17:54:20+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Domain Fronting mbi TLS 1.3 | ProHoster","description":"Hyrja Sistemet moderne t\u00eb filtrimit p\u00ebr korporata.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/domen-fronting-na-baze-tls-1-3","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0414\u043e\u043c\u0435\u043d-\u0444\u0440\u043e\u043d\u0442\u0438\u043d\u0433 \u043d\u0430 \u0431\u0430\u0437\u0435 TLS 1.3 | ProHoster","og:description":"\u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0421\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0435 \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u044b\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/domen-fronting-na-baze-tls-1-3","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-12T21:00:00+00:00","article:modified_time":"2026-05-20T17:54:20+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"52639","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 04:19:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:39:27","updated":"2026-01-24 04:19:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/52639","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=52639"}],"version-history":[{"count":3,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/52639\/revisions"}],"predecessor-version":[{"id":173323,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/52639\/revisions\/173323"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=52639"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=52639"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=52639"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}