FINDING · DEFENSE

Domain shadowing makes all three traffic indicators — connecting URL, SNI, and Host header — appear to belong to an allowed shadow domain while fetching content from a blocked back-end domain via CDN. Unlike domain fronting, it exploits a legitimate CDN feature (arbitrary back-end binding) rather than a SNI/Host mismatch quirk, so CDNs cannot disable it by enforcing header consistency without breaking legitimate use cases such as third-party service outsourcing via CNAME. The technique was demonstrated successfully accessing www.facebook.com from a heavily censored country.

From 2021-wei-domainDomain Shadowing: Leveraging Content Delivery Networks for Robust Blocking-Resistant Communications · §3.3, §6.2 · 2021 · USENIX Security Symposium

Implications

Tags

censors
generic
techniques
sni-blockingdpiip-blockingdns-poisoning
defenses
domain-frontingtunneling

Extracted by claude-sonnet-4-6 — review before relying.