{"id":52639,"date":"2019-11-13T00:00:00","date_gmt":"2019-11-12T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/domen-fronting-na-baze-tls-1-3"},"modified":"2026-05-20T19:54:20","modified_gmt":"2026-05-20T17:54:20","slug":"domen-fronting-na-baze-tls-1-3","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/domen-fronting-na-baze-tls-1-3","title":{"rendered":"Domain Fronting na baz\u00ebn e TLS 1.3","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<h3>Hyrje<\/h3>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/9e81fbeed9c8d41c7e4f583235541370.jpg\" alt=\"Domain Fronting na baz\u00ebn e TLS 1.3\" \/><br \/>\nSistemet moderne t\u00eb filtrimit t\u00eb p\u00ebrmbajtjes s\u00eb korporatave, nga prodhues t\u00eb njohur si Cisco, BlueCoat, FireEye, kan\u00eb shum\u00eb t\u00eb p\u00ebrbashk\u00ebta me homolog\u00ebt e tyre m\u00eb t\u00eb fuqish\u00ebm \u2014 sistemet DPI, t\u00eb cilat po implementohen me forc\u00eb n\u00eb nivel komb\u00ebtar. Q\u00ebllimi i t\u00eb dyja \u00ebsht\u00eb t\u00eb kontrollojn\u00eb trafikun e internetit q\u00eb hyn dhe del dhe, n\u00eb baz\u00eb t\u00eb listave t\u00eb bardha\/ t\u00eb zeza, t\u00eb marrin vendimin p\u00ebr ndalimin e lidhjes me internetin. Dhe duke qen\u00eb se t\u00eb dyja varen nga parime t\u00eb ngjashme, metodat p\u00ebr t\u00eb kaluar ato gjithashtu do t\u00eb ken\u00eb shum\u00eb t\u00eb p\u00ebrbashk\u00ebta.<\/p>\n<p>Nj\u00eb nga teknologjit\u00eb q\u00eb lejon kalimin mjaft efikas si p\u00ebr DPI ashtu edhe p\u00ebr sistemet korporative, \u00ebsht\u00eb teknologjia e domain fronting. Thelbi i saj \u00ebsht\u00eb se ne qasemi n\u00eb nj\u00eb burim t\u00eb bllokuar, duke u mbuluar me nj\u00eb domain tjet\u00ebr publik, me nj\u00eb reputacion t\u00eb mir\u00eb, i cili sigurisht nuk do t\u00eb bllokohet nga asnj\u00eb sistem, p\u00ebr shembull google.com.<\/p>\n<p>P\u00ebr k\u00ebt\u00eb teknologji jan\u00eb shkruar tashm\u00eb mjaft artikuj dhe jan\u00eb dh\u00ebn\u00eb shum\u00eb shembuj. Megjithat\u00eb, teknologjit\u00eb popullore dhe t\u00eb diskutueshme s\u00eb fundmi si DNS-over-HTTPS dhe encrypted-SNI, si dhe versioni i ri i protokollit TLS 1.3 ofrojn\u00eb mund\u00ebsin\u00eb p\u00ebr t\u00eb shqyrtuar nj\u00eb tjet\u00ebr opsion p\u00ebr domain fronting.<br \/>\n<a rel=\"nofollow\" name=\"habracut\"><\/a><\/p>\n<h3>T\u00eb kuptojm\u00eb teknologjin\u00eb<\/h3>\n<p>Fillimisht, le t\u00eb sqarojm\u00eb disa nga konceptet baz\u00eb, n\u00eb m\u00ebnyr\u00eb q\u00eb t\u00eb gjith\u00eb t\u00eb ken\u00eb nj\u00eb ide se kush \u00ebsht\u00eb kush dhe p\u00ebrse \u00ebsht\u00eb e nevojshme kjo. Ne p\u00ebrmend\u00ebm mekanizmin e eSNI, funksionin e t\u00eb cilit do ta shqyrtojm\u00eb m\u00eb von\u00eb. Mekanizmi eSNI (encrypted Server Name Indication) \u00ebsht\u00eb nj\u00eb version i sigurt i SNI, i disponuesh\u00ebm vet\u00ebm p\u00ebr protokollin TLS 1.3. Thelbi \u00ebsht\u00eb t\u00eb kriptohet gjithashtu informata p\u00ebr at\u00eb se cilit domain i d\u00ebrgohet k\u00ebrkesa.<\/p>\n<p>Tani le t\u00eb shqyrtojm\u00eb funksionimin e mekanizmit eSNI n\u00eb praktik\u00eb.<\/p>\n<p>Supozoni se kemi nj\u00eb burim interneti q\u00eb bllokohet nga nj\u00eb zgjidhje moderne DPI (t\u00eb marrim p\u00ebr shembull, njohurin\u00eb e famshme torrent \u2014 rutracker.nl). Kur p\u00ebrpiqemi t\u00eb hyjm\u00eb n\u00eb faqen e torrentit \u2014 ne shohim nj\u00eb bllokim standard t\u00eb ofruesit se burimi \u00ebsht\u00eb bllokuar:<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/6a2aeccd290f9046efa799166ffa875f.jpg\" alt=\"Domain Fronting na baz\u00ebn e TLS 1.3\" \/><\/p>\n<p>N\u00eb faqen e RKN, ky domain \u00ebsht\u00eb me t\u00eb v\u00ebrtet\u00eb i regjistruar n\u00eb listat e bllokimit:<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/1c881e2c8403cf85f77d9d74cbf3f54e.jpg\" alt=\"Domain Fronting na baz\u00ebn e TLS 1.3\" \/><\/p>\n<p>Kur b\u00ebhet nj\u00eb k\u00ebrkes\u00eb whois \u2014 duket se vet\u00eb domeni \u00ebsht\u00eb \"fshehur\" prapa ofruesit cloud, Cloudflare.<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/55b472de20a6eb85162ffbba286b9487.jpg\" alt=\"Domain Fronting na baz\u00ebn e TLS 1.3\" \/><\/p>\n<p>Por diferencia de los \"especialistas\" de la RKN, los empleados m\u00e1s t\u00e9cnicos de Beeline (o aquellos que han aprendido por amarga experiencia de nuestro famoso regulador) no decidieron simplemente bloquear el sitio por direcci\u00f3n IP, sino que lo incluyeron en la lista de bloqueo precisamente por <a href=\"https:\/\/prohoster.info\/sq\/domain\/\">el nombre de dominio<\/a>. Esto se puede comprobar f\u00e1cilmente si miramos qu\u00e9 otros dominios se esconden detr\u00e1s de este mismo <a href=\"https:\/\/prohoster.info\/sq\/lir\/ipv4\/\">adres\u00ebn IP<\/a>, visitando uno de ellos y viendo que el acceso no est\u00e1 bloqueado:<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/fe7de472c9c5cc8abe4d4ed6cacdd21c.jpg\" alt=\"Domain Fronting na baz\u00ebn e TLS 1.3\" \/><\/p>\n<p>\u00bfC\u00f3mo es posible esto? \u00bfC\u00f3mo sabe el DPI del proveedor a cu\u00e1l de los dominios se dirige mi navegador, si todas las comunicaciones ocurren a trav\u00e9s del protocolo https y no hemos notado a\u00fan sustituciones de certificados https por parte de Beeline? \u00bfEs acaso un vidente o me est\u00e1n espiando?<\/p>\n<p>Intentemos responder a esta pregunta observando el tr\u00e1fico a trav\u00e9s de Wireshark.<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/330f05030e9edb066bf2fd80c935e0c3.jpg\" alt=\"Domain Fronting na baz\u00ebn e TLS 1.3\" \/><\/p>\n<p>En la captura de pantalla se puede ver que primero el navegador obtiene la direcci\u00f3n IP del servidor a trav\u00e9s de DNS, luego se realiza el apret\u00f3n de manos TCP est\u00e1ndar con el servidor de destino y despu\u00e9s el navegador intenta establecer la conexi\u00f3n ssl con el servidor. Para esto env\u00eda el paquete <a href=\"https:\/\/prohoster.info\/sq\/ssl-sertifikat\/\">SSL<\/a> Client Hello, que contiene el nombre del dominio de origen en texto claro. Este campo es necesario para que el servidor frontal de Cloudflare pueda enrutear la conexi\u00f3n correctamente. Es aqu\u00ed donde el DPI del proveedor nos atrapa, rompiendo nuestra conexi\u00f3n. En este caso, no recibimos ning\u00fan mensaje de error del proveedor, y vemos el error est\u00e1ndar del navegador como si el sitio estuviera desconectado o simplemente no funcionara:<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/9642c783158c0ace70c50fea917e7d9d.jpg\" alt=\"Domain Fronting na baz\u00ebn e TLS 1.3\" \/><\/p>\n<p>Ahora activemos el mecanismo eSNI en el navegador, como se indica en las instrucciones para <a href=\"https:\/\/miketabor.com\/enable-dns-over-https-and-encrypted-sni-in-firefox\/\" rel=\"nofollow\">Firefox <\/a>:<br \/>\nPara ello, abrimos la p\u00e1gina de configuraci\u00f3n de Firefox <b>about:config<\/b> y activamos las siguientes configuraciones:<\/p>\n<pre><code class=\"plaintext\">network.trr.mode = 2;\nnetwork.trr.uri = https:\/\/mozilla.cloudflare-dns.com\/dns-query\nnetwork.security.esni.enabled = true\n<\/code><\/pre>\n<p>Despu\u00e9s de esto, verificaremos la correcta operaci\u00f3n de las configuraciones en el sitio de Cloudflare en <a href=\"https:\/\/www.cloudflare.com\/ssl\/encrypted-sni\/\" rel=\"nofollow\">linkun<\/a> y volveremos a probar el truco con nuestro tracker de torrents.<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/4996a67993bd2f1b5ebeb1ac156ba29a.jpg\" alt=\"Domain Fronting na baz\u00ebn e TLS 1.3\" \/><\/p>\n<p>\u00a1Voil\u00e0! Nuestro querido tracker se abri\u00f3, sin ninguna VPN ni servidores proxy. Ahora observemos el volcado de tr\u00e1fico en Wireshark para ver qu\u00e9 sucedi\u00f3.<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/a7e305afbf29896f6ebb82e53c7fed88.jpg\" alt=\"Domain Fronting na baz\u00ebn e TLS 1.3\" \/><\/p>\n<p>Esta vez, el paquete ssl client hello no contiene expl\u00edcitamente el dominio de destino, y en su lugar ha aparecido un nuevo campo en el paquete: encrypted_server_name \u2013 all\u00ed se encuentra el valor rutracker.nl, y solo el servidor frontal de Cloudflare puede desencriptar este campo. As\u00ed que el DPI del proveedor no tiene otra opci\u00f3n m\u00e1s que lavarse las manos y permitir dicho tr\u00e1fico. No hay otras alternativas con cifrado.<\/p>\n<p>Pra ndaj, si funksionon teknologjia n\u00eb shfletues \u2014 ne e shqyrtuam. Tani le t\u00eb p\u00ebrpiqemi ta aplikojm\u00eb at\u00eb p\u00ebr gj\u00ebra m\u00eb specifike dhe interesante. Fillimisht, do ta m\u00ebsojm\u00eb curl t\u00eb p\u00ebrdor\u00eb eSNI p\u00ebr t\u00eb punuar me TLS 1.3 dhe gjithashtu do t\u00eb shohim se si funksionon domeni i frontimit bazuar n\u00eb eSNI.<\/p>\n<h3>Domeni i frontimit me eSNI<\/h3>\n<p>Duke marr\u00eb parasysh se curl p\u00ebr lidhjen p\u00ebrmes protokollit https p\u00ebrdor bibliotek\u00ebn standarde openssl, s\u00eb pari duhet t\u00eb sigurojm\u00eb mb\u00ebshtetje p\u00ebr eSNI pik\u00ebrisht aty. N\u00eb deg\u00ebt master t\u00eb openssl, mb\u00ebshtetje p\u00ebr eSNI nuk ekziston ende, k\u00ebshtu q\u00eb duhet t\u00eb shkarkojm\u00eb nj\u00eb deg\u00eb speciale openssl, ta kompilojm\u00eb dhe ta instalojm\u00eb at\u00eb.<\/p>\n<p>Klonojm\u00eb depozitat nga githubi dhe e kompilojm\u00eb si zakonisht:<\/p>\n<pre><code class=\"plaintext\">$ git clone https:\/\/github.com\/sftcd\/openssl\n$ cd openssl\n$ .\/config\n\n$ make\n$ cd esnistuff\n$ make\n<\/code><\/pre>\n<p>M\u00eb pas \u2014 klonojm\u00eb depozitat nga curl dhe e konfiguroni kompilimnin e saj duke p\u00ebrdorur bibliotek\u00ebn ton\u00eb t\u00eb nd\u00ebrtuar openssl:<\/p>\n<pre><code class=\"plaintext\">$ cd $HOME\/code\n$ git clone https:\/\/github.com\/niallor\/curl.git curl-esni\n$ cd curl-esni\n\n$ export LD_LIBRARY_PATH=\/opt\/openssl\n$ .\/buildconf\n$ LDFLAGS=\"-L\/opt\/openssl\" .\/configure --with-ssl=\/opt\/openssl --enable-esni --enable-debug\n<\/code><\/pre>\n<p>K\u00ebtu \u00ebsht\u00eb e r\u00ebnd\u00ebsishme t\u00eb specifikoni sakt\u00eb t\u00eb gjith\u00eb katalog\u00ebt ku ndodhet openssl (n\u00eb rastin ton\u00eb \u2014 kjo \u00ebsht\u00eb \/opt\/openssl\/) dhe t\u00eb sigurohemi q\u00eb procesi i konfigurimit kalon pa gabime.<\/p>\n<p>N\u00eb rast t\u00eb konfigurimit t\u00eb suksessh\u00ebm \u2014 do t\u00eb shohim rreshtin:<\/p>\n<p><b>WARNING: esni ESNI enabled but marked EXPERIMENTAL. Use with caution!<\/b><\/p>\n<pre><code class=\"plaintext\">$ make<\/code><\/pre>\n<p>Pas nd\u00ebrtimit t\u00eb suksessh\u00ebm t\u00eb paket\u00ebs do t\u00eb p\u00ebrdorim nj\u00eb skedar special bash nga p\u00ebrb\u00ebrja e openssl p\u00ebr t\u00eb konfiguruar dhe nisur curl. Do ta kopjojm\u00eb at\u00eb n\u00eb katalogun me curl p\u00ebr leht\u00ebsi:<\/p>\n<pre><code class=\"plaintext\">cp \/opt\/openssl\/esnistuff\/curl-esni <\/code><\/pre>\n<p>dhe do t\u00eb kryejm\u00eb nj\u00eb k\u00ebrkes\u00eb testuese https n\u00eb serverin cloudflare, duke regjistruar nj\u00ebkoh\u00ebsisht paketat DNS dhe TLS n\u00eb Wireshark.<\/p>\n<pre><code class=\"plaintext\">$ ESNI_COVER=\"www.hello-rkn.ru\" .\/curl-esni https:\/\/cloudflare.com\/<\/code><\/pre>\n<p>N\u00eb p\u00ebrgjigjen e serverit, p\u00ebrve\u00e7 shum\u00eb informacionit t\u00eb diagnostikimit nga openssl dhe curl, ne do t\u00eb marrim nj\u00eb p\u00ebrgjigje HTTP me kodin 301 nga cloudflare.<\/p>\n<pre><code class=\"plaintext\">HTTP\/1.1 301 Moved Permanently\n&lt;Date: Sun, 03 Nov 2019 13:12:55 GMT\n&lt;Transfer-Encoding: chunked\n&lt;Connection: keep-alive\n&lt;Cache-Control: max-age=3600\n&lt;Expires: Sun, 03 Nov 2019 14:12:55 GMT\n&lt;Location: https:\/\/www.cloudflare.com\/\n<\/code><\/pre>\n<p>gj\u00eb q\u00eb tregon se k\u00ebrkesa jon\u00eb u d\u00ebrgua me sukses n\u00eb serverin e destinacionit, u d\u00ebgjua dhe u p\u00ebrpunua.<\/p>\n<p>Tani le t\u00eb shohim dump-in e trafikut n\u00eb wireshark, pra \u00e7far\u00eb pa n\u00eb k\u00ebt\u00eb rast DPI i ofruesit.<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/25945e28e6ff5dec3ab92e018b91bab1.jpg\" alt=\"Domain Fronting na baz\u00ebn e TLS 1.3\" \/><\/p>\n<p>\u00cbsht\u00eb e qart\u00eb se fillimisht curl i \u00ebsht\u00eb drejtuar serverit DNS p\u00ebr t\u00eb marr\u00eb \u00e7el\u00ebsin publik eSNI p\u00ebr serverin cloudflare - pyetja DNS TXT p\u00ebr _esni.cloudflare.com (paketa nr. 13). M\u00eb pas, duke p\u00ebrdorur bibliotek\u00ebn openssl, curl d\u00ebrgoi nj\u00eb k\u00ebrkes\u00eb TLS 1.3 n\u00eb serverin cloudflare n\u00eb t\u00eb cil\u00ebn fusha SNI ishte e enkriptuar me \u00e7el\u00ebsin publik t\u00eb marr\u00eb n\u00eb hapin e m\u00ebparsh\u00ebm (paketa nr. 22). <b>Por, p\u00ebrve\u00e7 fush\u00ebs eSNI, n\u00eb paket\u00ebn SSL-hello u p\u00ebrfshi edhe nj\u00eb fush\u00eb me SNI t\u00eb zakonsh\u00ebm - t\u00eb hapur, t\u00eb cilin ne mund ta tregojm\u00eb n\u00eb nj\u00eb rend t\u00eb rast\u00ebsish\u00ebm (n\u00eb k\u00ebt\u00eb rast - <a href=\"http:\/\/www.hello-rkn.ru\" rel=\"nofollow\">www.hello-rkn.ru<\/a>). <\/b><\/p>\n<p>Kjo fush\u00eb e SNI-t t\u00eb hapur nuk u mor parasysh gjat\u00eb p\u00ebrpunimit nga serverat cloudflare dhe thjesht sh\u00ebrbente si mask\u00eb p\u00ebr DPI-n\u00eb e ofruesit. Serveri cloudflare pranoi paket\u00ebn ton\u00eb ssl-hello, e dekriptoi eSNI, nxorri SNI origjinal dhe e p\u00ebrpunoi at\u00eb sikur t\u00eb mos kishte ndodhur asgj\u00eb (e b\u00ebri gjith\u00e7ka ashtu si\u00e7 ishte planifikuar gjat\u00eb zhvillimit t\u00eb eSNI).<\/p>\n<p>E vetmja gj\u00eb p\u00ebr t\u00eb cil\u00ebn n\u00eb k\u00ebt\u00eb rast mund t\u00eb kapesh nga pik\u00ebpamja e DPI-s\u00eb \u00ebsht\u00eb k\u00ebrkesa fillestare DNS p\u00ebr _esni.cloudflare.com. Por ne e b\u00ebm\u00eb k\u00ebrkes\u00ebn DNS t\u00eb hapur vet\u00ebm p\u00ebr t\u00eb treguar se si funksionon ky mekaniz\u00ebm nga brenda.<\/p>\n<p>P\u00ebr t\u00eb hequr p\u00ebrfundimisht baz\u00ebn nga n\u00ebn k\u00ebmb\u00ebt e DPI-s\u00eb, ne p\u00ebrdorim mekanizmin e p\u00ebrmendur DNS-over-HTTPS. Nj\u00eb shpjegim i vog\u00ebl - DOH - protokoll q\u00eb lejon mbrojtjen nga sulmi \"njeri nd\u00ebrmjet\u00ebs\" duke d\u00ebrguar k\u00ebrkes\u00ebn DNS p\u00ebrmes protokollit HTTPS.<\/p>\n<p>Le t\u00eb realizojm\u00eb s\u00ebrish k\u00ebrkes\u00ebn, por k\u00ebt\u00eb her\u00eb \u00e7el\u00ebsat publik\u00eb eSNI do i marrim p\u00ebrmes protokollit https, e jo DNS:<\/p>\n<pre><code class=\"plaintext\">ESNI_COVER=\"www.hello-rkn.ru\" DOH_URL=https:\/\/mozilla.cloudflare-dns.com\/dns-query .\/curl-esni https:\/\/cloudflare.com\/<\/code><\/pre>\n<p>Dumpi i trafikut t\u00eb k\u00ebrkes\u00ebs \u00ebsht\u00eb paraqitur n\u00eb screenshot-in m\u00eb posht\u00eb:<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/284d1d8110b24c647a57e644d93a8142.jpg\" alt=\"Domain Fronting na baz\u00ebn e TLS 1.3\" \/><\/p>\n<p>\u00cbsht\u00eb e qart\u00eb se fillimisht curl i drejtohet serverit mozilla.cloudflare-dns.com p\u00ebrmes protokollit DoH (bashkimi https n\u00eb serverin 104.16.249.249), p\u00ebr t\u00eb marr\u00eb nga ata vlerat e \u00e7el\u00ebsave publik\u00eb p\u00ebr enkriptimin e SNI-s\u00eb, dhe pastaj drejt serverit t\u00eb destinacionit, duke u mbuluar n\u00eb k\u00ebt\u00eb rast me domenin <a href=\"http:\/\/www.hello-rkn.ru\" rel=\"nofollow\">www.hello-rkn.ru<\/a>.<\/p>\n<p>P\u00ebrve\u00e7 rezolutorit DoH t\u00eb p\u00ebrmendur m\u00eb par\u00eb mozilla.cloudflare-dns.com, ne mund t\u00eb p\u00ebrdorim edhe sh\u00ebrbime t\u00eb tjera t\u00eb njohura DoH, p\u00ebr shembull, nga korporata e njohur p\u00ebr t\u00eb keq.<br \/>\nLe t\u00eb realizojm\u00eb nj\u00eb k\u00ebrkes\u00eb t\u00eb till\u00eb:<\/p>\n<pre><code class=\"plaintext\">ESNI_COVER=\"www.kremlin.ru\" DOH_URL=https:\/\/dns.google\/dns-query .\/curl-esni https:\/\/rutracker.nl\/<\/code><\/pre>\n<p>Dhe do t\u00eb marrim p\u00ebrgjigje:<\/p>\n<pre><code class=\"plaintext\">&lt; HTTP\/1.1 301 Moved Permanently\n&lt;Date: Sun, 03 Nov 2019 14:10:22 GMT\n&lt;Content-Type: text\/html\n&lt;Transfer-Encoding: chunked\n&lt;Connection: keep-alive\n&lt;Set-Cookie: __cfduid=da0144d982437e77b0b37af7d00438b1a1572790222; expires=Mon, 02-Nov-20 14:10:22 GMT; path=\/; domain=.rutracker.nl; HttpOnly; Secure\n&lt;Location: https:\/\/rutracker.nl\/forum\/index.php\n&lt;CF-Cache-Status: DYNAMIC\n&lt;Expect-CT: max-age=604800, report-uri=&quot;https:\/\/report-uri.cloudflare.com\/cdn-cgi\/beacon\/expect-ct&quot;\n&lt;Server: cloudflare\n&lt;CF-RAY: 52feee696f42d891-CPH\n<\/code><\/pre>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2019\/11\/c77b8a396e7d20f0b4d74b61380595df.jpg\" alt=\"Domain Fronting na baz\u00ebn e TLS 1.3\" \/><\/p>\n<p>N\u00eb k\u00ebt\u00eb rast ne i kishim b\u00ebr\u00eb nj\u00eb k\u00ebrkes\u00eb serverit t\u00eb bllokuar rutracker.nl, duke p\u00ebrdorur nj\u00eb DoH-resolver dns.google (nuk ka gabim tipografik, tani kjo korporat\u00eb e shquar ka nj\u00eb domen t\u00eb nivelit t\u00eb par\u00eb) dhe u mb\u00ebshtet\u00ebm n\u00eb nj\u00eb tjet\u00ebr domen, bllokimi i t\u00eb cilit \u00ebsht\u00eb shprehur qart\u00eb se ndalohet nga t\u00eb gjith\u00eb DPI n\u00ebn k\u00ebrc\u00ebnimin e d\u00ebnimit m\u00eb t\u00eb ashp\u00ebr. Nga p\u00ebrgjigjja e marr\u00eb, mund t\u00eb kuptojm\u00eb se k\u00ebrkesa jon\u00eb \u00ebsht\u00eb p\u00ebrpunuar me sukses.<\/p>\n<p>Si nj\u00eb kontroll shtes\u00eb q\u00eb DPI po reagon n\u00eb SNI t\u00eb hapur, t\u00eb cilin ne e \u00e7ojm\u00eb si mbrojtje \u2014 mund t\u00eb b\u00ebjm\u00eb nj\u00eb k\u00ebrkes\u00eb n\u00eb rutracker.nl duke u mbrojtur prapa disa resurseve t\u00eb tjera t\u00eb ndaluara, p\u00ebr shembull nj\u00eb tjet\u00ebr \u2018torrent tracker\u2019 t\u00eb mir\u00ebnjohur:<\/p>\n<pre><code class=\"plaintext\">$ ESNI_COVER=\"rutor.info\" DOH_URL=https:\/\/dns.google\/dns-query .\/curl-esni https:\/\/rutracker.nl\/<\/code><\/pre>\n<p>Nuk do t\u00eb marrim asnj\u00eb p\u00ebrgjigje nga serveri, pasi k\u00ebrkesa jon\u00eb do t\u00eb bllokohet nga sistemi DPI.<\/p>\n<h3>Nj\u00eb p\u00ebrfundim i vog\u00ebl p\u00ebr pjes\u00ebn e par\u00eb<\/h3>\n<p>Pra, na arriti t\u00eb demonstronim funksionalitetin e eSNI me ndihm\u00ebn e openssl dhe curl dhe t\u00eb verifikojm\u00eb funksionin e domain-fronting bazuar n\u00eb eSNI. Po k\u00ebshtu, mund t\u00eb adaptojm\u00eb mjetet tona t\u00eb preferuara q\u00eb p\u00ebrdorin bibliotek\u00ebn openssl p\u00ebr t\u00eb punuar \u2018n\u00ebn mbrojtje\u2019 t\u00eb domeneve t\u00eb tjera. M\u00eb shum\u00eb p\u00ebr k\u00ebt\u00eb \u2014 n\u00eb artikujt tan\u00eb t\u00eb ardhsh\u00ebm.<\/p>\n<p>Burimi: <a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/475372\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0421\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0435 \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u044b\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430, \u043e\u0442 \u0442\u0430\u043a\u0438\u0445 \u0438\u043c\u0435\u043d\u0438\u0442\u044b\u0445 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u0435\u0439 \u043a\u0430\u043a Cisco, BlueCoat, FireEye \u0438\u043c\u0435\u044e\u0442 \u0434\u043e\u0432\u043e\u043b\u044c\u043d\u043e \u043c\u043d\u043e\u0433\u043e \u043e\u0431\u0449\u0435\u0433\u043e \u0441 \u0431\u043e\u043b\u0435\u0435 \u043c\u043e\u0449\u043d\u044b\u043c\u0438 \u0438\u0445 \u0441\u043e\u0431\u0440\u0430\u0442\u044c\u044f\u043c\u0438 \u2014 DPI \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0443\u0441\u0438\u043b\u0435\u043d\u043d\u043e \u0432\u043d\u0435\u0434\u0440\u044f\u044e\u0442\u0441\u044f \u043d\u0430 \u043d\u0430\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u043c \u0443\u0440\u043e\u0432\u043d\u0435. \u0421\u0443\u0442\u044c \u0440\u0430\u0431\u043e\u0442\u044b \u0438 \u0442\u0435\u0445 \u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e\u0431\u044b \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u044c \u0434\u043e\u0441\u043c\u043e\u0442\u0440 \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u0433\u043e \u0438 \u0438\u0441\u0445\u043e\u0434\u044f\u0449\u0435\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0438, \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0430\u043d\u0438\u0438 \u0447\u0435\u0440\u043d\u044b\u0445\/\u0431\u0435\u043b\u044b\u0445 \u0441\u043f\u0438\u0441\u043a\u043e\u0432, \u043f\u0440\u0438\u043d\u0438\u043c\u0430\u0442\u044c \u0440\u0435\u0448\u0435\u043d\u0438\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-52639","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0421\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0435 \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u044b\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/domen-fronting-na-baze-tls-1-3\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0414\u043e\u043c\u0435\u043d-\u0444\u0440\u043e\u043d\u0442\u0438\u043d\u0433 \u043d\u0430 \u0431\u0430\u0437\u0435 TLS 1.3 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0421\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0435 \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u044b\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/domen-fronting-na-baze-tls-1-3\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-12T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-05-20T17:54:20+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Domain-fronting mbi TLS 1.3 | ProHoster","description":"Hyrje Sistemet moderne korporative t\u00eb filtrimit.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/domen-fronting-na-baze-tls-1-3","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0414\u043e\u043c\u0435\u043d-\u0444\u0440\u043e\u043d\u0442\u0438\u043d\u0433 \u043d\u0430 \u0431\u0430\u0437\u0435 TLS 1.3 | ProHoster","og:description":"\u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0421\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0435 \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u044b\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/domen-fronting-na-baze-tls-1-3","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-12T21:00:00+00:00","article:modified_time":"2026-05-20T17:54:20+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"52639","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 04:19:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:39:27","updated":"2026-01-24 04:19:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/52639","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=52639"}],"version-history":[{"count":3,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/52639\/revisions"}],"predecessor-version":[{"id":173323,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/52639\/revisions\/173323"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=52639"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=52639"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=52639"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}