net4people / bbs

Forum for discussing Internet censorship circumvention
3.47k stars 82 forks source link

Fake sni in cloudflare #408

Open hamedbaftam opened 1 month ago

hamedbaftam commented 1 month ago

vless://[redacted]

please consider this config [redacted] not have any dns record!

wkrp commented 1 month ago

This is not the place for posting bridge information, please. This forum is for research and development discussions.

its0ka commented 1 week ago

@wkrp you misunderstood the meaning of the post. it's valid and shouldn't be closed. and the domain doesn't have a dns record probably because its used in cf workers, where dns records are not required, or the domain name servers have changed from cloudflare to something else, while still having dns records on cloudflare. so unfortunately it's probably not a fake sni on cloudflare

wkrp commented 1 week ago

@its0ka thank you for the additional context. The original post had a VLESS UUID, IP address, and sni=XXXX.cfd. Apparently, despite appearing in the bridge URL sni parameter, XXXX.cfd did not have a DNS record. (TIL there is a .cfd TLD, "clothing fashion design".)

So what is the point? That it's possible to configure DNS records in Cloudflare DNS and use them in sni, even if the Cloudflare resolvers are not the ones actually used globally to resolve the domain? Is this a way to make SNI more flexible for VLESS bridges hosted on Cloudflare? Is it possible to use any string for the sni parameter when using Cloudflare? Does it only work with Cloudflare workers? I'm missing the bigger picture.

mmmray commented 1 week ago

this is mostly a trick to not have to pay for the domain but still be able to use it after expiry. i don't think this is very interesting for anticensorship and it should not be encouraged to leak other people's configs on this forum just on the chance there's something interesting in them.