FINDING · DEFENSE

Obfsproxy (predecessor to obfs4) listens on randomized ports as an explicit defense against discovery by comprehensive Internet-wide scanning, because an adversary must scan all 65,535 ports to locate bridges rather than a single known port — multiplying scan cost by roughly 65,000× relative to a single-port sweep.

From 2013-durumeric-zmapZMap: Fast Internet-wide Scanning and its Security Applications · §4.4 · 2013 · USENIX Security Symposium

Implications

Tags

techniques
active-probingport-blocking
defenses
pluggable-transportobfs4bridges

Extracted by claude-sonnet-4-6 — review before relying.