<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3176544969102514202</id><updated>2011-04-21T22:31:32.797-04:00</updated><category term='SQUID'/><category term='HTTP PROXY'/><category term='Project-E'/><category term='secret'/><category term='portbunny'/><category term='SSH'/><category term='HTTPS'/><category term='dd'/><category term='PROXY'/><category term='security'/><category term='non-anonymous'/><category term='project R'/><category term='TOR'/><category term='hacker tool'/><category term='geheimplan'/><category term='UTM'/><category term='new tool'/><category term='HTTP'/><category term='division'/><category term='clone'/><category term='XTM'/><category term='disclosure'/><category term='tunnel'/><category term='hacker-tools'/><category term='network'/><category term='portscanner'/><title type='text'>Geheimpläne</title><subtitle type='html'>A blog about secret plans...</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://geheimplan.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://geheimplan.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Geheimplan</name><uri>http://www.blogger.com/profile/03928084108435247159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>10</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3176544969102514202.post-8711185433590268904</id><published>2008-11-21T02:40:00.000-05:00</published><updated>2008-11-21T07:37:05.997-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='division'/><category scheme='http://www.blogger.com/atom/ns#' term='SSH'/><category scheme='http://www.blogger.com/atom/ns#' term='geheimplan'/><category scheme='http://www.blogger.com/atom/ns#' term='HTTP PROXY'/><title type='text'>retested: HTTP proxy bypassing</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_FFtD1VZsjgA/SSaqbreP6GI/AAAAAAAAAAo/fUXkPIQKkVU/s1600-h/74.jpg"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 320px; height: 320px;" src="http://2.bp.blogspot.com/_FFtD1VZsjgA/SSaqbreP6GI/AAAAAAAAAAo/fUXkPIQKkVU/s320/74.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5271087806386530402" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;Today the division REtested the  (SSH tunnel through Proxy) method to bypass HTTP proxy,&lt;/p&gt;&lt;p&gt;CODENAME: "74" successfully blocked our test with "ssl_handshake: Input/output error"&lt;/p&gt;&lt;p&gt;That are good news for the division and bad news for bad people.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3176544969102514202-8711185433590268904?l=geheimplan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://geheimplan.blogspot.com/feeds/8711185433590268904/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3176544969102514202&amp;postID=8711185433590268904' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/8711185433590268904'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/8711185433590268904'/><link rel='alternate' type='text/html' href='http://geheimplan.blogspot.com/2008/11/retested-http-proxy-bypassing.html' title='retested: HTTP proxy bypassing'/><author><name>M.I.S.T.E.R.P.I.N.K.Y.T.H.E.B.R.A.I.N</name><uri>http://www.blogger.com/profile/12052103574238383955</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_FFtD1VZsjgA/SSaqbreP6GI/AAAAAAAAAAo/fUXkPIQKkVU/s72-c/74.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3176544969102514202.post-447004057014653227</id><published>2008-09-18T02:40:00.004-04:00</published><updated>2008-09-26T18:34:16.813-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='new tool'/><category scheme='http://www.blogger.com/atom/ns#' term='division'/><category scheme='http://www.blogger.com/atom/ns#' term='portbunny'/><category scheme='http://www.blogger.com/atom/ns#' term='hacker-tools'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='portscanner'/><title type='text'>tested new portscanner called: portbunny</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_FFtD1VZsjgA/SNIXA8F62vI/AAAAAAAAAAc/Mejrf5-b_zY/s1600-h/portbunny.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://2.bp.blogspot.com/_FFtD1VZsjgA/SNIXA8F62vI/AAAAAAAAAAc/Mejrf5-b_zY/s200/portbunny.png" alt="" id="BLOGGER_PHOTO_ID_5247281820738444018" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;The division tested a new portscanning tool called &lt;a href="http://portbunny.recurity.com/"&gt;portbunny&lt;/a&gt;,&lt;/p&gt;&lt;p&gt;"&lt;/p&gt;&lt;p&gt;PortBunny 1.0 is a Linux-kernel-based port-scanner created by Recurity Labs. Its aim is to provide a reliable and fast TCP-SYN-port-scanner...&lt;/p&gt;&lt;p&gt;"&lt;/p&gt;&lt;p&gt;The division results: &lt;/p&gt;&lt;p&gt;Yes it's fast, but  dramaticly slows down the initiating pc and freezes the division-initiating-pc two times!&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;But we warned: it might be an illegal hacker tool...&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3176544969102514202-447004057014653227?l=geheimplan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://geheimplan.blogspot.com/feeds/447004057014653227/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3176544969102514202&amp;postID=447004057014653227' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/447004057014653227'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/447004057014653227'/><link rel='alternate' type='text/html' href='http://geheimplan.blogspot.com/2008/09/tested-new-portscanner-called-portbunny.html' title='tested new portscanner called: portbunny'/><author><name>M.I.S.T.E.R.P.I.N.K.Y.T.H.E.B.R.A.I.N</name><uri>http://www.blogger.com/profile/12052103574238383955</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_FFtD1VZsjgA/SNIXA8F62vI/AAAAAAAAAAc/Mejrf5-b_zY/s72-c/portbunny.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3176544969102514202.post-2395163201796493694</id><published>2008-09-18T02:40:00.002-04:00</published><updated>2008-09-18T04:16:31.428-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='division'/><category scheme='http://www.blogger.com/atom/ns#' term='dd'/><category scheme='http://www.blogger.com/atom/ns#' term='Project-E'/><category scheme='http://www.blogger.com/atom/ns#' term='geheimplan'/><category scheme='http://www.blogger.com/atom/ns#' term='secret'/><category scheme='http://www.blogger.com/atom/ns#' term='clone'/><title type='text'>success information regarding secret plan: project code E</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_FFtD1VZsjgA/SNIOW3IlA1I/AAAAAAAAAAU/Yf7d6wKmznc/s1600-h/e.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_FFtD1VZsjgA/SNIOW3IlA1I/AAAAAAAAAAU/Yf7d6wKmznc/s200/e.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5247272301759890258" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Today the division had success!&lt;/p&gt;&lt;p&gt;Phase1 from project code E is completed,&lt;/p&gt;&lt;p&gt;we successfully cloned the hdd and can now start the root-geeting-process,&lt;/p&gt;&lt;p&gt;Please stay tuned.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3176544969102514202-2395163201796493694?l=geheimplan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://geheimplan.blogspot.com/feeds/2395163201796493694/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3176544969102514202&amp;postID=2395163201796493694' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/2395163201796493694'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/2395163201796493694'/><link rel='alternate' type='text/html' href='http://geheimplan.blogspot.com/2008/09/success-information-regarding-secret.html' title='success information regarding secret plan: project code E'/><author><name>M.I.S.T.E.R.P.I.N.K.Y.T.H.E.B.R.A.I.N</name><uri>http://www.blogger.com/profile/12052103574238383955</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_FFtD1VZsjgA/SNIOW3IlA1I/AAAAAAAAAAU/Yf7d6wKmznc/s72-c/e.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3176544969102514202.post-9149452630644302704</id><published>2008-09-17T02:40:00.005-04:00</published><updated>2008-09-18T04:16:48.384-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='division'/><category scheme='http://www.blogger.com/atom/ns#' term='SSH'/><category scheme='http://www.blogger.com/atom/ns#' term='geheimplan'/><category scheme='http://www.blogger.com/atom/ns#' term='HTTP PROXY'/><category scheme='http://www.blogger.com/atom/ns#' term='UTM'/><title type='text'>HTTP proxy bypassing: SSH   (Part b)</title><content type='html'>&lt;p&gt;HTTP proxy bypassing: SSH   (Part b)&lt;/p&gt;&lt;p&gt;The division was assiduously and tried also a setup without an insane "outbound allow ssh"-packetfilter rule on its firewall config to bypass it's proxy. All the traffic should go through the proxy. &lt;/p&gt;&lt;p&gt;What does the division installed and configured therefor?&lt;/p&gt;&lt;p&gt;The tool for this purpose is called proxytunnel and the config is quite easy.&lt;/p&gt;&lt;p&gt;The division setup (/root/.ssh/config): &lt;/p&gt;&lt;p&gt;"&lt;br /&gt;Host mybypasssystem&lt;br /&gt;&lt;/p&gt;&lt;p&gt;      ProxyCommand /usr/local/bin/proxytunnel -p BIGACMEPROXYSERVER:8080 -d ip-address-of-ssh-server-which-is-owned-by-me:80&lt;/p&gt;&lt;p&gt;"&lt;/p&gt;&lt;p&gt;The division had to setup their outside SSH Server (ip-address-of-ssh-server-which-is-owned-by-me)&lt;/p&gt;&lt;p&gt;to listen for SSH at port 80,&lt;/p&gt;&lt;p&gt;this is because the proxy will normaly olny allow outgoing traffic via CONNECT to Port 80 and 443.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The last things man needs is to configure on his machine&lt;br /&gt;&lt;br /&gt;shell:   ssh -D 666 mybypasssystem&lt;br /&gt;&lt;br /&gt;browser-setup:   socks proxy with 127.0.0.1:666&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;So, does this help to bypass a HTTP proxy over the HTTP Proxy itself (in our test)?: yes&lt;/p&gt;&lt;p&gt;and with some  ulterior motives we can do even more than HTTP traffic ....&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3176544969102514202-9149452630644302704?l=geheimplan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://geheimplan.blogspot.com/feeds/9149452630644302704/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3176544969102514202&amp;postID=9149452630644302704' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/9149452630644302704'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/9149452630644302704'/><link rel='alternate' type='text/html' href='http://geheimplan.blogspot.com/2008/09/http-proxy-bypassing-ssh-part-b.html' title='HTTP proxy bypassing: SSH   (Part b)'/><author><name>M.I.S.T.E.R.P.I.N.K.Y.T.H.E.B.R.A.I.N</name><uri>http://www.blogger.com/profile/12052103574238383955</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3176544969102514202.post-2544828094384078970</id><published>2008-09-16T02:40:00.004-04:00</published><updated>2008-09-18T04:12:32.271-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='division'/><category scheme='http://www.blogger.com/atom/ns#' term='HTTP'/><category scheme='http://www.blogger.com/atom/ns#' term='SSH'/><category scheme='http://www.blogger.com/atom/ns#' term='geheimplan'/><category scheme='http://www.blogger.com/atom/ns#' term='PROXY'/><category scheme='http://www.blogger.com/atom/ns#' term='HTTP PROXY'/><category scheme='http://www.blogger.com/atom/ns#' term='UTM'/><title type='text'>HTTP proxy bypassing: SSH   (Part a)</title><content type='html'>&lt;p&gt;second technique tested: SSH&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Today the division tested another method to bypass HTTP proxy:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;a) with SSH&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The only thing man needs is to configure on his machine&lt;/p&gt;&lt;p&gt;shell:   ssh -D 666 username@ip-address-of-ssh-server-which-is-owned-by-me&lt;/p&gt;&lt;p&gt;browser-setup:   socks proxy with 127.0.0.1:666&lt;/p&gt;&lt;p&gt;So, does this help to bypass a HTTP proxy (in our test)?: yes, &lt;/p&gt;&lt;p&gt;because the division does have an insane "outbound allow ssh"-packetfilter rule on its firewall config.&lt;/p&gt;&lt;p&gt;All the HTTP-traffic form the bowser will be forwarded through port 666 to our SSH-Server and this server connects us to the www. &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;But there are more possibilities! Please stay tuned for Part b) of this article.&lt;/p&gt;&lt;p&gt;The division will check more and let you know &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3176544969102514202-2544828094384078970?l=geheimplan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://geheimplan.blogspot.com/feeds/2544828094384078970/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3176544969102514202&amp;postID=2544828094384078970' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/2544828094384078970'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/2544828094384078970'/><link rel='alternate' type='text/html' href='http://geheimplan.blogspot.com/2008/09/http-proxy-bypassing-ssh.html' title='HTTP proxy bypassing: SSH   (Part a)'/><author><name>M.I.S.T.E.R.P.I.N.K.Y.T.H.E.B.R.A.I.N</name><uri>http://www.blogger.com/profile/12052103574238383955</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3176544969102514202.post-4809857928262640112</id><published>2008-09-15T16:20:00.000-04:00</published><updated>2008-09-16T12:54:17.270-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='division'/><category scheme='http://www.blogger.com/atom/ns#' term='HTTP'/><category scheme='http://www.blogger.com/atom/ns#' term='HTTPS'/><category scheme='http://www.blogger.com/atom/ns#' term='UTM'/><category scheme='http://www.blogger.com/atom/ns#' term='TOR'/><title type='text'>Addition to the TOR setup test (HTTP proxy bypass)</title><content type='html'>So what happen if you surf over HTTPS? (yes, some people would like to do so...)&lt;br /&gt;&lt;br /&gt;A simple outbound rule "&lt;span style="font-style: italic;"&gt;from:Client to:ANY service:HTTPS&lt;/span&gt;" will help but also open TOR (there are only a few TOR router listening on 443, but enough for a successful connect). Also a simple HTTP proxy which just forwards the HTTPS connection does the job: TOR will work.&lt;br /&gt;&lt;br /&gt;But what if you UTM solution filters also HTTPS traffic?&lt;br /&gt;The division will test and let you know.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3176544969102514202-4809857928262640112?l=geheimplan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://geheimplan.blogspot.com/feeds/4809857928262640112/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3176544969102514202&amp;postID=4809857928262640112' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/4809857928262640112'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/4809857928262640112'/><link rel='alternate' type='text/html' href='http://geheimplan.blogspot.com/2008/09/addition-to-tor-setup-test-http-proxy.html' title='Addition to the TOR setup test (HTTP proxy bypass)'/><author><name>Geheimplan</name><uri>http://www.blogger.com/profile/03928084108435247159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3176544969102514202.post-513165248172861399</id><published>2008-09-14T16:20:00.000-04:00</published><updated>2008-09-15T02:56:26.274-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='division'/><category scheme='http://www.blogger.com/atom/ns#' term='HTTP'/><category scheme='http://www.blogger.com/atom/ns#' term='network'/><category scheme='http://www.blogger.com/atom/ns#' term='UTM'/><category scheme='http://www.blogger.com/atom/ns#' term='TOR'/><title type='text'>HTTP proxy bypassing: TOR</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hwz6ygc2RLE/SM1523ZT1_I/AAAAAAAAABg/mNtcZrDPO4I/s1600-h/tor.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://2.bp.blogspot.com/_hwz6ygc2RLE/SM1523ZT1_I/AAAAAAAAABg/mNtcZrDPO4I/s320/tor.gif" alt="" id="BLOGGER_PHOTO_ID_5245983124446500850" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;First technique tested: &lt;a href="https://www.torproject.org/"&gt;TOR&lt;/a&gt;&lt;br /&gt;Because there is no Firefox extension with TOR support built in, the division installed the TOR package first, which includes a TOR based HTTP proxy: Privoxy.&lt;br /&gt;&lt;br /&gt;The only thing man needs then is to configure the network settings in Firefox to 127.0.0.1:8118 - that's it.&lt;br /&gt;Why installing an additional extension like &lt;a href="https://addons.mozilla.org/de/firefox/addon/2275"&gt;Torbutton&lt;/a&gt; or &lt;a href="https://addons.mozilla.org/en-US/firefox/addon/2464"&gt;FoxyProxy&lt;/a&gt;? (btw: &lt;a href="https://addons.mozilla.org/de/firefox/addon/5833"&gt;Tor-Proxy.NET&lt;/a&gt; forwards all traffic to 1 private server and later to TOR... (al least they claim so))&lt;br /&gt;&lt;br /&gt;So, does TOR help to bypass a HTTP proxy (in our test): nope.&lt;br /&gt;&lt;br /&gt;The division does not have an insane "&lt;span style="font-style: italic;"&gt;outbound allow all&lt;/span&gt;"-packetfilter rule on its firewall config, and that makes it very hard for the local tor-daemon to get a connect to his network. Configuring port 80 and activate "My firewal only lets me connect to certain ports" does not help, because the HTTP proxy of the UTM device does what it should do: filter out non-HTTP traffic.&lt;br /&gt;Last chance: activate "My ISP blocks connections to the TOR network" and configure a TOR-bridge.&lt;br /&gt;So, how should that work without "&lt;span style="font-style: italic;"&gt;outbound allow all&lt;/span&gt;"...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3176544969102514202-513165248172861399?l=geheimplan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://geheimplan.blogspot.com/feeds/513165248172861399/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3176544969102514202&amp;postID=513165248172861399' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/513165248172861399'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/513165248172861399'/><link rel='alternate' type='text/html' href='http://geheimplan.blogspot.com/2008/09/http-proxy-bypassing-tor.html' title='HTTP proxy bypassing: TOR'/><author><name>Geheimplan</name><uri>http://www.blogger.com/profile/03928084108435247159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_hwz6ygc2RLE/SM1523ZT1_I/AAAAAAAAABg/mNtcZrDPO4I/s72-c/tor.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3176544969102514202.post-4137465054855152234</id><published>2008-09-12T16:20:00.000-04:00</published><updated>2008-09-14T17:02:19.661-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='division'/><category scheme='http://www.blogger.com/atom/ns#' term='HTTP'/><category scheme='http://www.blogger.com/atom/ns#' term='non-anonymous'/><category scheme='http://www.blogger.com/atom/ns#' term='SSH'/><category scheme='http://www.blogger.com/atom/ns#' term='tunnel'/><category scheme='http://www.blogger.com/atom/ns#' term='secret'/><category scheme='http://www.blogger.com/atom/ns#' term='TOR'/><category scheme='http://www.blogger.com/atom/ns#' term='SQUID'/><title type='text'>HTTP proxy bypassing techniques disclosed</title><content type='html'>Today the division got non-anonymous hints about HTTP proxy bypassing:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;"cached"-mark requests not inspected again - mmhh... ??? (maybe a flaw in a prehistoric SQUID-based HTTP proxy)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.torproject.org/"&gt;TOR&lt;/a&gt; support built in in Firefox: nope...   but there are 3 extensions, actually only 2&lt;/li&gt;&lt;li&gt;SSH-based tunnel (yeah, not really new)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;extra-install-tools (for all those who think squid is something you can eat, tor is the reverse of rot and SSH is the secret service of Elbonia)&lt;/li&gt;&lt;/ul&gt;The division will check it and let you now.&lt;br /&gt;&lt;br /&gt;(If you have some secret information about HTTP proxy bypassing: let us (&lt;span style="font-style: italic;"&gt;geheimp@mailservice from google&lt;/span&gt;) know, we are the right division for it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3176544969102514202-4137465054855152234?l=geheimplan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://geheimplan.blogspot.com/feeds/4137465054855152234/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3176544969102514202&amp;postID=4137465054855152234' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/4137465054855152234'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/4137465054855152234'/><link rel='alternate' type='text/html' href='http://geheimplan.blogspot.com/2008/09/today-division-got-non-anonymous-hints.html' title='HTTP proxy bypassing techniques disclosed'/><author><name>Geheimplan</name><uri>http://www.blogger.com/profile/03928084108435247159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3176544969102514202.post-5847374468702100083</id><published>2008-09-11T16:20:00.000-04:00</published><updated>2008-09-12T09:28:14.917-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='division'/><category scheme='http://www.blogger.com/atom/ns#' term='XTM'/><category scheme='http://www.blogger.com/atom/ns#' term='UTM'/><category scheme='http://www.blogger.com/atom/ns#' term='project R'/><title type='text'>New secret project sketched</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hwz6ygc2RLE/SMl--ukMK7I/AAAAAAAAAA8/_GJXor3LQdM/s1600-h/whiteboard.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://2.bp.blogspot.com/_hwz6ygc2RLE/SMl--ukMK7I/AAAAAAAAAA8/_GJXor3LQdM/s320/whiteboard.gif" alt="Whiteboard screen shot" id="BLOGGER_PHOTO_ID_5244862857166465970" border="0" width="185" /&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:verdana;"&gt;Today the division sketched a new secret project (see whiteboard screen shot): project code "&lt;/span&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt;R&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Its not a security project, but security appliances, vile: UTM / XTM (Unified Threat Management / Extensible Threat Management) are involved.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Please stay tuned.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3176544969102514202-5847374468702100083?l=geheimplan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://geheimplan.blogspot.com/feeds/5847374468702100083/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3176544969102514202&amp;postID=5847374468702100083' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/5847374468702100083'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/5847374468702100083'/><link rel='alternate' type='text/html' href='http://geheimplan.blogspot.com/2008/09/new-secret-project-sketched.html' title='New secret project sketched'/><author><name>Geheimplan</name><uri>http://www.blogger.com/profile/03928084108435247159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_hwz6ygc2RLE/SMl--ukMK7I/AAAAAAAAAA8/_GJXor3LQdM/s72-c/whiteboard.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3176544969102514202.post-569856468508196411</id><published>2008-09-10T16:20:00.000-04:00</published><updated>2008-09-12T19:08:43.750-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='division'/><category scheme='http://www.blogger.com/atom/ns#' term='disclosure'/><category scheme='http://www.blogger.com/atom/ns#' term='network'/><category scheme='http://www.blogger.com/atom/ns#' term='hacker tool'/><category scheme='http://www.blogger.com/atom/ns#' term='secret'/><title type='text'>Secret network tool</title><content type='html'>&lt;span style="font-family:verdana;"&gt;Today the division disclosed our top secret network packet generation tool: &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.secdev.org/projects/scapy/"&gt;Scapy&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;But we warned: it might be an illegal &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://de.wikipedia.org/wiki/Hackerparagraf"&gt;hacker tool&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;...&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3176544969102514202-569856468508196411?l=geheimplan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://geheimplan.blogspot.com/feeds/569856468508196411/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3176544969102514202&amp;postID=569856468508196411' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/569856468508196411'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3176544969102514202/posts/default/569856468508196411'/><link rel='alternate' type='text/html' href='http://geheimplan.blogspot.com/2008/09/secret-network-tool.html' title='Secret network tool'/><author><name>Geheimplan</name><uri>http://www.blogger.com/profile/03928084108435247159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
