FINDING · DETECTION

Ultrasurf's DNS bootstrapping phase uses subdomain names that are always exactly 16 characters between delimiters and exclusively target .info TLDs, producing a constant byte-width network signature. The paper concludes that filtering this bootstrapping traffic is straightforward even without reverse engineering the client binary, as the client itself acts as a network discovery oracle for censors observing its connections.

From 2012-appelbaum-technicalTechnical analysis of the Ultrasurf proxying software · §5.6, §6.8 · 2012 · The Tor Project

Implications

Tags

censors
cn
techniques
dpidns-poisoning

Extracted by claude-sonnet-4-6 — review before relying.