Giter Club home page Giter Club logo

Comments (13)

MoriMeina avatar MoriMeina commented on July 17, 2024

屏蔽阿里HTTPSDNS网段后依然露地址,怀疑新增HTTPSDNS地址

IOS端使用Stream抓包时并不会露地址,一旦关闭Stream并重启客户端后地址露的干干净净
动态、评论都露,在此之前测试仅评论露地址
尝试在网关设备进行抓包,后续跟进

很奇怪的点,我的主页没露地址(???

from anti-ip-attribution.

MoriMeina avatar MoriMeina commented on July 17, 2024

屏幕截图 2023-11-27 015629
草(一种植物

from anti-ip-attribution.

MoriMeina avatar MoriMeina commented on July 17, 2024

屏幕截图 2023-11-27 021315

POST /x/v2/reply/add HTTP/2
Host: api.bilibili.com
Cookie: _uuid=;
bili_ticket=
; bili_jct=; sid=
Content-Length: 991
Content-Type: application/x-www-form-urlencoded
X-Bili-Ticket:
App-Key: iphone
Session_id:
Env: prod
X-Bili-Trace-Id:
User-Agent: bili-universal/75600100 CFNetwork/1.0 Darwin/23.0.0 os/ios model/iPhone 13 mobi_app/iphone build/75600100 osVer/17.0.3 network/2 channel/AppStore
X-Bili-Aurora-Eid: U1wBT1MGUg==
Buvid: Y24BA523DB03521E430AA6B8AAB9769995A3
X-Bili-Mid: 28092263
Accept-Encoding: gzip, deflate
access_key=


评论的请求,隐藏了关键ID,应该不影响看

from anti-ip-attribution.

SunsetMkt avatar SunsetMkt commented on July 17, 2024

已更新,非常感谢。

ed95522

from anti-ip-attribution.

MoriMeina avatar MoriMeina commented on July 17, 2024

已更新,非常感谢。

ed95522

有一个问题,单reject了httpdns.bilivideo.com之后其实还是露,根据最新的抓包来看其实还有dns.google的httpsDNS
屏幕截图 2023-11-28 005102

在我抓包时就走了这几条请求去httpsDNS,但是一旦离开抓包环境,评论、动态地址直接完全泄露,排除了移动网络影响,目前还在跟进

from anti-ip-attribution.

MoriMeina avatar MoriMeina commented on July 17, 2024

已更新,非常感谢。
ed95522

有一个问题,单reject了httpdns.bilivideo.com之后其实还是露,根据最新的抓包来看其实还有dns.google的httpsDNS

屏幕截图 2023-11-28 005102
在我抓包时就走了这几条请求去httpsDNS,但是一旦离开抓包环境,评论、动态地址直接完全泄露,排除了移动网络影响,目前还在跟进

我的想法是正确的,肯定还有其他的httpsDNS存在,离开抓包环境(http代理)之后,直接从路由器接口抓取得到的包中目的地址是bilibili国内的CDN
62c3295faea538d3b5b134f9dfa3e1f
5c851a2f5bb5c7517d0616071d6c524

有没有大佬有IOS导出TLS证书的方案,我在路由器段抓包没法解密HTTPS:(

from anti-ip-attribution.

MoriMeina avatar MoriMeina commented on July 17, 2024

在重复抓包测试中发现,客户端与101.91.140.124通讯后才出现了国内的CDN地址,经过验证此ip的证书为*.bilivideo.com
image

在未获得地址的情况下直连了httpdns.bilivideo.com,在重复在各个DNS服务器查询域名后验证了我的猜想
image

目前应当先禁止以下地址通讯,后续跟进测试结果
-122.9.13.79
-122.9.15.129
-101.91.140.124
-101.91.140.224

from anti-ip-attribution.

MoriMeina avatar MoriMeina commented on July 17, 2024

它的第一个httpdns查询包竟然出现在了DNS查询之前
image
什么原理?难道写入了hosts?这么多IP???

from anti-ip-attribution.

MoriMeina avatar MoriMeina commented on July 17, 2024

增加

  • 122.9.13.79
  • 122.9.15.129
  • 101.91.140.224
  • 101.91.140.124
  • 117.144.238.29
  • 117.185.228.108
  • 122.9.7.134
  • 116.63.10.135
  • 114.116.215.110
  • 116.63.10.31
  • 112.65.200.117
  • 112.64.218.119

这个是最后的屏蔽ip,屏蔽完成后即可不露地址

from anti-ip-attribution.

MoriMeina avatar MoriMeina commented on July 17, 2024
  • DOMAIN-SUFFIX,bilibili.com
  • IP-CIDR,122.9.13.79
  • IP-CIDR,122.9.15.129
  • IP-CIDR,101.91.140.224
  • IP-CIDR,101.91.140.124
  • IP-CIDR,117.144.238.29
  • IP-CIDR,117.185.228.108
  • IP-CIDR,122.9.7.134
  • IP-CIDR,116.63.10.135
  • IP-CIDR,114.116.215.110
  • IP-CIDR,116.63.10.31
  • IP-CIDR,112.65.200.117
  • IP-CIDR,112.64.218.119

from anti-ip-attribution.

SunsetMkt avatar SunsetMkt commented on July 17, 2024

Android 端

bundle.putString(KEY_EXT_P2P_HTTPDNS_BILI_IP, "47.101.175.206;47.100.123.169;120.46.169.234;121.36.72.124;");
bundle.putString(KEY_EXT_P2P_BILIDNS_CMCC_IP, "116.63.10.135;122.9.7.134;117.185.228.108;117.144.238.29");
bundle.putString(KEY_EXT_P2P_BILIDNS_CT_IP, "122.9.13.79;122.9.15.129;101.91.140.224;101.91.140.124");
bundle.putString(KEY_EXT_P2P_BILIDNS_CU_IP, "114.116.215.110;116.63.10.31;112.64.218.119;112.65.200.117");

from anti-ip-attribution.

MoriMeina avatar MoriMeina commented on July 17, 2024

Android 端

bundle.putString(KEY_EXT_P2P_HTTPDNS_BILI_IP, "47.101.175.206;47.100.123.169;120.46.169.234;121.36.72.124;");
bundle.putString(KEY_EXT_P2P_BILIDNS_CMCC_IP, "116.63.10.135;122.9.7.134;117.185.228.108;117.144.238.29");
bundle.putString(KEY_EXT_P2P_BILIDNS_CT_IP, "122.9.13.79;122.9.15.129;101.91.140.224;101.91.140.124");
bundle.putString(KEY_EXT_P2P_BILIDNS_CU_IP, "114.116.215.110;116.63.10.31;112.64.218.119;112.65.200.117");

直接全禁止就好了:(
IOS是黑盒所以只能抓包测,估计也是跟安卓一样的

from anti-ip-attribution.

SunsetMkt avatar SunsetMkt commented on July 17, 2024

感谢贡献。
28aa5cd

from anti-ip-attribution.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.