Enderman
โœ”
5.77K subscribers
388 photos
25 videos
7 files
140 links
A software engineer, a malware enthusiast and most importantly, a weird tall creature.

https://enderman.ch
https://youtube.com/endermanch
Download Telegram
The VPN servers only differ by their protocol. So, the suggestions off the top of my head are WireGuard, OpenVPN, Outline. You'll need to read a lot and understand the UNIX terminal basics. There's a single one-click automated option I know of right now โ€” AmneziaVPN. It's completely free, open-source and based on WireGuard. It uses Docker to completely automate the process, which allows even your grandma to set it up quickly and painlessly. It also offers options for when the state goes hog wild and blocks connections per protocol. (It's a thing in ๐Ÿ‡ท๐Ÿ‡บ / ๐Ÿ‡จ๐Ÿ‡ณ)

๐Ÿ”ป Advanced VPNs. When the state goes rogue as described above, the protocols separate out into three categories:
โ–ช๏ธ Easily detectable: all common VPN tunnel protocols โ€” WireGuard, OpenVPN, and so forth... They can be easily regulated by the state.
โ–ช๏ธ Detectable: commonly obfuscated versions of the common VPN tunnel protocols, e.g. AmneziaWG (WG + garbage packet spam during handshake initiation), OpenVPN over Cloak, Shadowsocks. They require much more scrutiny to be sifted out by the censorship systems.
โ–ช๏ธ Undetectable: while in reality not 100% safe, they're state-of-art as of September 2024 and make it past the Great Firewall of China. Most of these protocols aren't documented in English. If you live outside ๐Ÿ‡ท๐Ÿ‡บ, ๐Ÿ‡จ๐Ÿ‡ณ or ๐Ÿ‡ฎ๐Ÿ‡ท, you likely won't need those for at least the next decade.

Let's go over them anyway. There's no nomenclature for them, but I'll try my best to sort them:
โ–ช๏ธ VMess
โ–ช๏ธ VLess
โ–ช๏ธ Naive
โ–ช๏ธ Trojan
โ–ช๏ธ Hysteria

The whole idea behind those ยซundetectableยป protocols is to mask your VPN traffic as HTTPS (aka browsing a random web page). It is considerably slower than any of the VPN solutions shown before, but if there isn't any other option, that's what you're left with. Recent advancements include Xray + XTLS-REALITY, which has an ability to defeat Active Probing โ€” previously uncontested state censorship method.

The bottom of the barrel, where everything above fails:
โ–ช๏ธ KCP
โ–ช๏ธ Meiru
โ–ช๏ธ TUIC
โ–ช๏ธ Brook
โ–ช๏ธ Pingtunnel โ€” masks your traffic under ICMP! (pretty promising)

Umm, yea. You probably won't ever need those. But keep that in mind, there's no way to censor the internet.

๐Ÿ”ป DNS. It's a very important subject, because a DNS (Domain Name System) server is what resolves domain names into IP addresses for you, and censorship can also be applied to it.

That's what DNS does, and you can manually resolve domains using the nslookup utility, for instance:
C:\Windows\System32>nslookup google.com
Server: AX4200.lan
Address: fd21:4bd3:61a3::1

Non-authoritative answer:
Name: google.com
Addresses: 2a00:1450:4010:c0a::8b
2a00:1450:4010:c0a::66
2a00:1450:4010:c0a::65
2a00:1450:4010:c0a::8a
173.194.221.138
173.194.221.113
173.194.221.100
173.194.221.101
173.194.221.102
173.194.221.139


DNS is just like a hash-table, a dictionary of the Internet:
x.com โ†’ 104.244.42.129 A
google.com โ†’ 108.177.14.139 A

Chances are you are using a DNS server provided by your ISP free of charge. Let's say the state asked the ISP to block shitter.com. The ISP might restrict access to that resource via DPI, but it also might resolve the domain name to localhost, or some RFC-private IPv4, 10.0.0.0/8 for instance.

In the best case scenario you can directly set custom DNS servers (1.1.1.1, 1.0.0.1 โ€” CloudFlare; 8.8.8.8, 8.4.4.8 โ€” Google) either network-wide or per device. Problem solved. However, this might not work! An ISP may very well hijack your DNS requests server-side and redirect them to their DNS server. Or, they could just block any outgoing UDP traffic on the port 53 when their servers aren't listed as an endpoint.

The solution to both of these digital rape cases is DNS over HTTPS or DNS over TLS. Now the idea is strikingly similar to that in the ยซundetectableยป VPNs. The tools are also open-source and freely available, I'll list them here (OpenWRT packages as an example):
โ–ช๏ธ HTTPS-DNS-proxy
โ–ช๏ธ DNSCrypt-proxy
โ–ช๏ธ Stubby
๐Ÿ‘56๐Ÿ‘Ž2๐Ÿค”2โค1
Please ask your questions in the comments if you have any. Also just in case, I am not suicidal.
๐Ÿ‡ท๐Ÿ‡บ๐Ÿค๐Ÿ‡ง๐Ÿ‡ท
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘76โค9๐Ÿ˜ฑ5๐Ÿ‘Ž2
๐Ÿ“Ž An example schematic of the Active DPI implementation
๐Ÿ‘52๐Ÿค”3๐Ÿ˜ฑ3๐Ÿ‘Ž1
๐Ÿ’ฝ The Windows measurement system
๐Ÿคฌ91๐Ÿค”40โค20๐Ÿ‘12๐Ÿ˜ฑ9๐Ÿ˜ข4๐Ÿ‘Ž3๐ŸŽ‰1
Enderman
๐Ÿ’ฝ The Windows measurement system
๐ŸŽ‰163๐Ÿ˜ฑ65โค24๐Ÿ‘12๐Ÿค”8๐Ÿ‘Ž3
โค67๐Ÿ˜ฑ10๐Ÿ‘8๐Ÿ‘Ž3๐Ÿค”1
๐ŸŒ Discord has been officially banned in Russia!

The changes took effect on my side ~5 minutes ago. Here is the block list, insert the following domains into your split tunneling setup in order to continue using the platform:
discord.com
gateway.discord.gg
cdn.discordapp.com
discordapp.net
googleapis.com
discord-attachments-uploads-prd.storage.googleapis.com
dis.gd
discord.co
discord.design
discord.dev
discord.gg
discord.gift
discord.gifts
discord.media
discord.new
discord.store
discord.tools
discordapp.com
discordmerch.com
discordpartygames.com
discord-activities.com
discordactivities.com
discordsays.com
discordstatus.com
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ˜ข134๐Ÿคฌ44๐Ÿ‘9๐ŸŽ‰8๐Ÿ˜ฑ5โค4๐Ÿ‘Ž3
Forwarded from ะขะะกะก
โ—๏ธDiscord ะทะฐะฑะปะพะบะธั€ะพะฒะฐะฝ ะฒ ะ ะพััะธะธ ะทะฐ ะฝะฐั€ัƒัˆะตะฝะธะต ั‚ั€ะตะฑะพะฒะฐะฝะธะน ะทะฐะบะพะฝะพะดะฐั‚ะตะปัŒัั‚ะฒะฐ. ะžะฑ ัั‚ะพะผ ัะพะพะฑั‰ะธะปะธ ะขะะกะก ะฒ ะฟั€ะตัั-ัะปัƒะถะฑะต ะฒะตะดะพะผัั‚ะฒะฐ.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿคฌ110๐Ÿ˜ฑ9๐Ÿ˜ข6๐Ÿ‘Ž4๐Ÿ‘2๐ŸŽ‰1
Enderman
๐ŸŒ Discord has been officially banned in Russia! The changes took effect on my side ~5 minutes ago. Here is the block list, insert the following domains into your split tunneling setup in order to continue using the platform: discord.com gateway.discord.ggโ€ฆ
๐Ÿšจ DPI bypass for Discord RTC found

This bypass in form of a zapret config chunk will unblock the voice channels for you (๐Ÿ‡ท๐Ÿ‡บ) in no time! Confirmed working for me and a bunch of my friends.

QUIC_PORTS=50000-65535
MODE_QUIC=1
NFQWS_OPT_DESYNC_QUIC="--dpi-desync=fake,tamper --dpi-desync-any-protocol"
๐Ÿ‘85โค20๐Ÿค”10๐Ÿ‘Ž4
๐Ÿ“š Archive.org has just been hacked

It's offline as of right now, but the message speaks for itself...
๐Ÿ˜ข193๐Ÿ˜ฑ21๐Ÿคฌ15๐Ÿค”5๐Ÿ‘3
๐Ÿค” The YouAreAnIdiot incident

Let me preface this by saying yes, I do own YouAreAnIdiot for many years now.
A couple days ago some actual living breathing human reported the infamous joke website for phishing. This is an attack on Internet history and can be sort of compared to the Internet Archive breach. We all get attacked this often for... preserving history, but this is kind of the first time it went through for both projects.

Due to the modern nature of any and all requests being processed by AI, this caused some insignificant downtime and automatically made the service display a false scare warning about phishing.

And obviously we're left with a rhetorical question of where any kind of phishing could occur on a page with a bunch of flashing shapes and not a single POST request...
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿคฌ148๐Ÿ˜ข14๐Ÿ‘13๐Ÿค”6๐Ÿ˜ฑ3
๐ŸŒ Presumption of guilt

We're living in an Internet era where you get censored and banned by AI algorithms being forced to prove your innocence in an appeal with a hopefully real human being. In case with YouTube appeals are reviewed by AI as well.

It's called the presumption of guilt. Digital tyranny.
12๐Ÿคฌ125๐Ÿ˜ข11๐Ÿ‘7๐Ÿ‘Ž5๐Ÿ˜ฑ4โค3๐Ÿค”1๐ŸŽ‰1
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿค”62๐Ÿ˜ฑ14โค9๐Ÿ‘7
4โค122๐Ÿ˜ฑ16๐Ÿ‘11๐Ÿค”4๐ŸŽ‰4๐Ÿ˜ข2
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ˜ฑ87โค13๐Ÿ‘6๐Ÿ˜ข3
๐ŸŒ Regarding TikTok

I had an account there for quite some time. Recently I finally found time to install an actually usable application to try to consume, understand and maybe publish some content. All the previous times have been rather sporadic and happened solely because someone reminded me I actually have a TikTok account.

Now I wonder, do you guys even watch TikTok? Would you even care to watch my content there? I'm quite intrigued to explore the ยซshortยป niche, as I myself have serious troubles being concise and condensing the content to be digestible even when talking in real life. So it looks like a worthwhile venture for my sake.

Now if you would like to see me upload on TikTok, please tell me what kind of content you generally watch on the platform that happens to coincide with technology and maybe, just maybe, with what I do.

Thank you!
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘Ž89โค16๐Ÿ‘9๐Ÿค”6
๐Ÿค”33๐Ÿ˜ฑ5๐Ÿ‘Ž4โค2๐ŸŽ‰2
๐Ÿค”130โค27๐Ÿ˜ฑ12๐Ÿ˜ข11๐Ÿคฌ3๐ŸŽ‰2๐Ÿ‘1
Please open Telegram to view this post
VIEW IN TELEGRAM
โค52๐Ÿ˜ฑ28๐Ÿค”3๐Ÿ‘1
Just read the docs man, it's not that complicated!

The docs:
๐Ÿ‘113๐Ÿคฌ21โค14๐Ÿ˜ฑ6๐Ÿ˜ข5๐Ÿค”3๐ŸŽ‰1