Sign in

Enderman

@enderman.ch
3.2K followers 2 following 42 posts

A software engineer, a malware enthusiast and most importantly, a weird tall creature. I poke tech and act surprised when it breaks. 💖 300K+ subs on YouTube 🐤 @endermanch 🌐 enderman.ch

PostsRepliesMedia
Enderman @enderman.ch · 13/08/2025
So desperate
4507
Reposted by Enderman
danooct1 @danooct1.bsky.social · 26/04/2025
Happy 27 years of the CIH virus! This anniversary sees my video on the virus officially becoming a teenager. Maybe that's a sign to get back to the video business. youtu.be/RrnWFAx5vJg?...
youtu.be
Virus.Win9x.CIH/Chernobyl Destroying a Physical Computer
YouTube video by danooct1
68319
Enderman @enderman.ch · 28/04/2025
Run this in your Chromium browser: chrome://inducebrowsercrashforrealz
5337
Enderman @enderman.ch · 22/04/2025
???
2361
Enderman @enderman.ch · 22/04/2025
...
4312
Enderman @enderman.ch · 01/09/2024
I've been seeing mixed reports about the blockage in Brazil. Some say the Twitter IP set is banned (which can't be fixed by a DPI bypass), while others say the DPI bypass helped. Another group of users claim switching from the provider's DNS was the solution. Trial and error. It depends on an ISP.
1332
Enderman @enderman.ch · 01/09/2024
Okay, that should be it for the thread. I'm out. Your digital freedom is important to the Internet. Please ask your questions under the first post of the thread if you have any. Also just in case, I am not suicidal.
0110
Enderman @enderman.ch · 01/09/2024
Now the idea is strikingly similar to that in the «undetectable» VPNs. The tools are also open-source and freely available, I'll list them here (OpenWRT as an example): • DNSCrypt-proxy • Stubby • HTTPS-DNS-proxy
1110
Enderman @enderman.ch · 01/09/2024
An ISP may very well hijack your DNS requests server-side and redirect them to their server. Or, they could just block any outgoing UDP traffic on port 53 without their servers as an endpoint. The solution to both of these digital rape cases is DNS over HTTPS or DNS over TLS.
130
Enderman @enderman.ch · 01/09/2024
Now it should be apparent the DNS server is also a weak link. Well, the best case scenario — you can directly set custom DNS-servers (1.1.1.1, 1.0.0.1, 8.8.8.8, 8.4.4.8) either network-wide or per device. Problem solved. However, this might not work!
130
Enderman @enderman.ch · 01/09/2024
Chances are you are using a DNS server provided by your ISP free of charge. Let's say the state asked the ISP to block shitter(.)com. The ISP might use DPI, but it also might resolve the domain name to localhost, for example, or in this case, RFC-private IPv4 10.20.30.40, as shown in the figure.
130
Enderman @enderman.ch · 01/09/2024
4. Let's talk about DNS. It's a very important subject, because a DNS server is what resolves domain names for you, and censorship can also be applied to it. That's what DNS does: x.com -> 104.244.42.129 google.com -> 108.177.14.139
x.com
x.com
130
Enderman @enderman.ch · 01/09/2024
Umm, yea. You probably won't ever need those. But keep that in mind, there's no way to censor the internet.
130
Enderman @enderman.ch · 01/09/2024
The bottom of the barrel, where everything else is literally banned: • Hysteria • KCP • Meiru • TUIC • Brook • Pingtunnel The state-of-art censorship circumvention is achieved by masking your VPN traffic as browsing a web page. There's almost no way to detect that.
130
Enderman @enderman.ch · 01/09/2024
There's no decent nomenclature for them, but: • VMess • VLess • Naive • Trojan The whole idea behind these protocols is to mask your VPN traffic as HTTPS. It is considerably slower than any of the VPN solutions shown before, but you gotta do what you gotta do.
240
Enderman @enderman.ch · 01/09/2024
Undetectable protocols in reality aren't 100% safe, but they're state-of-art as of 2024 and work as a bypass for the Great Firewall of China. Most of these aren't documented in English. You likely won't need those for at least the next 10 years, but let's go over them anyway.
130
Enderman @enderman.ch · 01/09/2024
Detectable protocols are usually obfuscated versions of the common protocols, e.g. AmneziaWG (WG + garbage packet spam during handshake initiation), OpenVPN over Cloak, Shadowsocks. They require much more scrutiny to be sifted out by the censorship systems.
130
Enderman @enderman.ch · 01/09/2024
3. Advanced VPNs. When the state goes rogue as described in a tweet above, the protocols separate out into three categories: easily detectable, detectable, and undetectable. All common protocols are easily detectable, thus easily bannable. A more complex solution is required.
130
Enderman @enderman.ch · 01/09/2024
It's open-source and based on WireGuard. It uses Docker to completely automate the process, which allows even your grandma to set it up easily. There are also options when the state goes hog wild and blocks connections per protocol — as an example, Russia and China.
130
Enderman @enderman.ch · 01/09/2024
The VPN servers only differ by protocol. So, the suggestions off the top of my head are WireGuard, OpenVPN, Outline. You'll need to read a lot and understand the UNIX terminal basics. There's a single free one-click automated option I know of right now. AmneziaVPN github.com/amnezia-vpn/...
github.com
GitHub - amnezia-vpn/amnezia-client: Amnezia VPN Client (Desktop+Mobile)
Amnezia VPN Client (Desktop+Mobile). Contribute to amnezia-vpn/amnezia-client development by creating an account on GitHub.
130
Enderman @enderman.ch · 01/09/2024
The biggest problem with hosting a VPN server yourself is that it costs money. However, you can find a cheap VPS ($3-5/mo range) with a 100Mbit/s throughput practically anywhere right now. If you can't afford it, unfortunately, you have to resort to using a free VPN.
150
Enderman @enderman.ch · 01/09/2024
A VPN client! Which one should you use? Well. Forget the free VPNs. These sell your data, show you ads, install malware and do other unspeakable things to keep their service free. The best way out is to host a VPN server yourself. The client and server always go in conjunction.
140
Enderman @enderman.ch · 01/09/2024
Personally, I have network-wide split tunnelling set up with the VPN interface used solely to bypass regional blocks. That's really advanced, and I suggest you starting by simply setting up a client and a server.
150
Enderman @enderman.ch · 01/09/2024
Yes, the figure above is fucking dumb. Don't murder me, network guys. It's a vast oversimplification. The problem with a VPN is that it adds a whole bunch of hops and overhead that comes with them for your packets to overcome. 99% of the time it slows the connection down.
160
Enderman @enderman.ch · 01/09/2024
2. The VPNs. If the above does not work, your next best option is a VPN. The VPNs aren't magic, they're virtual networks that coincidentally allow delegating sending packets to a different gateway.
160
Enderman @enderman.ch · 01/09/2024
As time goes on, the states will eventually fix their DPI software, so it's preferrable to know how the bypass strategies work to cook up fresh combinations they haven't defeated yet. Not guaranteed to work, but if it does, it's significantly faster than any VPN. So try it out.
160
Enderman @enderman.ch · 01/09/2024
There are many ways to break the DPI algorithm, and the cases above are just an example. That's the optimal way to avoid state censorship. Luckily, there's open-source software that already does it for you! github.com/bol-van/zapret github.com/ValdikSS/Goo... github.com/dovecoteesca...
github.com
GitHub - bol-van/zapret: DPI bypass multi platform
DPI bypass multi platform. Contribute to bol-van/zapret development by creating an account on GitHub.
180
Enderman @enderman.ch · 01/09/2024
For example, by spec, you can split an HTTP request into TCP segments. "GET / HTTP/1.1\r\nHost: google.com ..." -> "GET /", " HTTP/1.1\r\nHost: google.com ...". You can also alter the case of the header keys, as it's case insensitive: "Host:" -> "hOst:". You can also add a dot after the host.
180
Enderman @enderman.ch · 01/09/2024
Active DPI, which is used in Russia and China (Passive DPI times are over for us), on the other hand, can block the packets. The only way to bypass it is by breaking its detection algorithm. The algorithm is possible to break by sending data the DPI software doesn't expect to process.
170
Enderman @enderman.ch · 01/09/2024
Passive DPI cannot block the packets, but can inject them. Usually an RST packet. If it is being injected client-side, it's possible to configure iptables to drop it, but the conditions are different for different ISPs. If RST is also sent to the server, configuring iptables will not be enough.
170
Enderman @enderman.ch · 01/09/2024
1. No VPN necessary! State restrictions are commonly implemented via DPI (Deep Packet Inspection). The software on the ISP's routing devices filters out packets based on certain conditions, and most of the time they are hardcoded. Which means there's room to contest it.
180
Enderman @enderman.ch · 01/09/2024
🇧🇷 Brazilian friends who have been forced to migrate here from Twitter, you should give this a read. There have been a lot of anti-censorship advancements in the past couple of years. There are solutions superior to a simple VPN. Let's take a look at them! 🧵
78821
Enderman @enderman.ch · 28/07/2024
An updated video documentary! Dave Plummer: The Man Who Scammed Millions (in 2006) youtu.be/1GeF9AjlqP8
youtu.be
Dave Plummer: The Man Who Scammed Millions (in 2006)
Hello, my friends! Let's hit 20K likes? Check out my website! https://enderman.chToday I am going to tell you a tale of SoftwareOnline.com, the website the o...
080
Enderman @enderman.ch · 21/07/2024
@zeealeid.bsky.social released an updated version of the BSOD concept. Looks functional to me. What do you think?
BSOD concept
2324
Enderman @enderman.ch · 20/07/2024
This critique is valid for any BSOD design concept, not just this particular one. I'm worried for the future of «Something happened» that Microsoft embraced. This is a trend that they started and should put a stop to immediately. Things should be functional before looking cool.
050
Enderman @enderman.ch · 20/07/2024
I much rather see the module that crashed, the parameters and a stack trace than a cool looking nothingburger. This isn't about design; this is about showing necessary debug output to prevent further crashes.
WinDbg — stack trace
180
Enderman @enderman.ch · 20/07/2024
Noticed an unofficial BSOD design concept tonight. I'm afraid we're going down the terrible downgrade path in software... Looks great, but that's about it. The cleaner it looks, the more calls it requires → the more likely it is to crash itself and leave user without any information at all.
Windows XP/Vista/7 BSOD: Stop code, parameters, module, module debug infoWindows 8/10 BSOD: Stop code, module, hidden parameters by defaultProposed concept: Just the stop code
2111
Enderman @enderman.ch · 20/07/2024
Yeah, you kinda reminded me of this account. I almost forgot
110
Enderman @enderman.ch · 20/07/2024
hahahah, that's so based
030
Enderman @enderman.ch · 20/07/2024
Hey guys. Got reminded by Elon I should post here more often. Twitter must be the only platform you pay for and still get a full amount of ads. It feels so surreal... ☹️
X Basic — Ads in For You and Following: Full
2172
Enderman @enderman.ch · 10/03/2024
Renaming a file in Windows
1151
Enderman @enderman.ch · 09/03/2024
The only problem with that code is ULL → integer conversion, it will probably give you a warning. I think it's %ull for unsigned 64-bit integers in CRT?
000
Enderman @enderman.ch · 09/03/2024
int wmain(int argc, wchar_t *argv[], wchar_t* envp[]) { ULONG64 t = GetTickCount64(); wprintf(L"Hello 🦋!\r\nSpawn tick: %d\r\n", t); return 0; }
2210