Confirmed on my side. Doesn't work on UniFi, works perfectly via SSH tunnel. Also, I've noticed that if I WHOIS the IP address of the CDN server, it's a TMNet address.
YouTube Deep Packet Inspection, All HTTP connections being MITMed
YouTube Deep Packet Inspection, All HTTP connections being MITMed
|
|
May 1 2013, 10:45 AM
Return to original view | Post
#1
|
![]()
Newbie
3 posts Joined: Oct 2010 |
Confirmed on my side. Doesn't work on UniFi, works perfectly via SSH tunnel. Also, I've noticed that if I WHOIS the IP address of the CDN server, it's a TMNet address.
|
|
|
|
|
|
May 1 2013, 12:11 PM
Return to original view | Post
#2
|
![]()
Newbie
3 posts Joined: Oct 2010 |
I've tried blocking TM's CDN
CODE iptables -A OUTPUT -d 58.27.108.142 -j DROP and making it directly go to Google (173.194.38.132), but looks like it's still blocked. |
|
|
May 1 2013, 11:10 PM
Return to original view | Post
#3
|
![]()
Newbie
3 posts Joined: Oct 2010 |
Can someone try sending the request for the YouTube video to some random other server? I want to see if that gets blocked.
Also, time to tunnel everything via SSH to my VPS in Las Vegas..... |
|
|
May 1 2013, 11:13 PM
Return to original view | Post
#4
|
![]()
Newbie
3 posts Joined: Oct 2010 |
|
|
|
May 1 2013, 11:22 PM
Return to original view | Post
#5
|
![]()
Newbie
3 posts Joined: Oct 2010 |
QUOTE(Enigmatic @ May 1 2013, 11:14 PM) For HTTPS channels, would there be anything which the ISPs can do to prevent access? Perhaps wKkay/prasys/rizvanrp may shed some light on this? From what I know, there's really no way to block specific content if it's going over HTTPS. You could block specific IPs, or even every site, but you can't block specific pages of an IP, or see what's being transmitted.AFAIK, there's only one way of monitoring the contents of an HTTPS connection, and if they did that, it would throw up a security warning on everyone's computers, unless there's some massive conspiracy to stick their SSL certificate on every PC. |
|
|
May 1 2013, 11:38 PM
Return to original view | Post
#6
|
![]()
Newbie
3 posts Joined: Oct 2010 |
|
|
|
May 2 2013, 01:04 PM
Return to original view | Post
#7
|
![]()
Newbie
3 posts Joined: Oct 2010 |
Just a note on this.
It shouldn't matter what DNS servers you're using, as the blocking method used here is more advanced and different than the method used for the file-sharing blocks. |
|
|
May 2 2013, 01:47 PM
Return to original view | Post
#8
|
![]()
Newbie
3 posts Joined: Oct 2010 |
QUOTE(Koki @ May 2 2013, 01:32 PM) Agreed. DNS doesn't work, only proxies do. No sure if GeoIP tracking or what, but automation is incredible It's not GeoIP. There's a computer between us and YouTube/Facebook, that literally looks at every piece of data being sent, and if one piece meets their criteria, the connection gets blocked. |
| Change to: | 0.0184sec
0.72
6 queries
GZIP Disabled
Time is now: 9th December 2025 - 11:50 PM |