Skip to content

GitLab

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
Trac
Trac
  • Project overview
    • Project overview
    • Details
    • Activity
  • Issues 246
    • Issues 246
    • List
    • Boards
    • Labels
    • Service Desk
    • Milestones
  • Operations
    • Operations
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value Stream
  • Wiki
    • Wiki
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Create a new issue
  • Issue Boards

GitLab is used only for code review, issue tracking and project management. Canonical locations for source code are still https://gitweb.torproject.org/ https://git.torproject.org/ and git-rw.torproject.org.

  • Legacy
  • TracTrac
  • Issues
  • #6874

Closed
Open
Opened Sep 17, 2012 by Isis Lovecruft@isis

Bridge Testing: Indirect Scans

These need to be further researched and tested. There may also be new methods discovered as time goes on, since some of these methods are pretty obscure.

Summary from [#6414 (closed) the parent ticket]:

  1. "Nmap stealth scan" style indirect scan: Send a TCP SYN with a forged IP address header to the bridge, the IP should should actually point to some in-country publicly observable service with sequential or otherwise predictable fields.
  2. Use any website which allows free content upload to give the bridge address as "content" and wait to see if the page times out. This is basically a variant of the vanilla TLS handshake test; however, a downside is that contact with the bridge is measured from wherever the localized server for the content upload site is and may not be in-country.
  3. Use FTP proxies or some similar weird bounce mechanism in-country to obfuscate the purpose of the connection.
  4. Use the canary to force probes to check for us, without the probes actually checking. I'm just going to start calling this idea "quis-custodiet-ipsos-custodes-now-f******?!?!?!"
  5. There were other ideas which were as entertaining as they were ridiculous, and there are probably a lot that I haven't thought of yet.
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
None
Due date
None
Reference: legacy/trac#6874