过期域名预定抢注

 找回密碼
 免费注册

(轉帖)從國外代理論壇上看到的「反代理」措施。

[複製鏈接]
發表於 2005-9-13 09:12:38 | 顯示全部樓層 |閱讀模式
Anti-proxy: how to detect your IP if you are using an anonymous proxy server? . {6 a3 ?2 F; N& q
As you already know, there are anonymous proxy servers that can be used for surfing the web anonymously. It is also interesting to know, is there a way of tracking down a web-surfer behind an anonymous proxy server.
8 r3 U& Z& P& i$ P2 w# \Yes, there are a number of possibilities not only to detect a visitor using several anonymous proxy servers, but also to detect his real IP even if he is using an anonymous proxy server.
) _% C* j1 `; S6 _' M) @. N: Z$ D( f$ {( d
Cookies
$ k& j$ ]* U- j4 `# ]  P5 aAt first sight, cookies are not anyhow related to proxy servers. Cookies are used to transfer small portions of information from the web server to the client as an addition to the requested web page. This additional information is stored in the client s browser and is retrieved by the web server. Cookies can be both temporary (for one-time use during a web session; when the session is over, these cookies are deleted) and long-term (for continuous store on the client s machine).
3 u) W9 G5 s" I8 [/ KSo, why do we need cookies? For example, if the password is requested while checking your e-mail box. After you have entered the password, it is stored in cookies, so each time you browse from page to page, the web server would check the password in the cookies instead of asking for it on every page.& p- D" b- x* W" e- g, T
" N. ?7 @1 \  M2 D, A7 Z& n% `
How can a cookie help to detect a proxy? You cannot detect IP with the help of cookies. However, when you first visit a web site, the IP (i.e. your proxy server s IP) is detected by the web server and then stored in the cookies. When you re-visit this site, the web server detects your IP again and checks it with the one stored in the cookies. If the IPs are not the same, the web server can make certain conclusions. And if you don't disable cookies in your browser, no proxy will help you (anonymizers can disable cookies and stop relaying them to your machine).
4 ~2 A. t! j% |: ^" Z
. g, M! T9 E0 G: `% h# ~( pJavaScript / VBScript: a% E8 h5 N( Q* ?: @2 v( l. `. a: C
There are special subprograms (scripts) run by the client s browser. Therefore, no matter how hard you try to setup your browser (unless you disable these active scripts), you won't be able to hide your real IP. These scripts are actually classified as simple programs and have very limited number of functions, however they are able to detect your IP as well as many other settings of your browser. These scripts can change your browser settings too!
. E- k9 ?" E: C* `* N5 [* w8 ]7 l! s. z
There is a multilevel protection from these scripts. You can restrict a script from accessing your browser features. However, the best way to protect your browser is completely disabling active scripts. You can disable scripts directly in anonymizers.
( {' f  {9 h. s
+ D' ^5 {) |, h; VJava; o8 z, {  ?1 L! Z4 g
Unlike JavaScript, Java is a full-featured programming language. So Java scripts have many additional abilities (particularly, detecting or changing your browser settings). In other words, Java programs can easily detect your IP and partially the settings of your browser.
; q; W7 h* M7 x+ v. z  h
# k5 A1 {) m4 w9 u9 M& yAs far as it goes to protecting your IP from being detected by Java scripts, all is much more complicated: the most secure and probably the only way is to completely disable Java in browser settings, as long as Java has many network functions and it's quite difficult to switch them all off.
8 d8 a, d, W% y. v+ P6 X/ d* {
4 X6 W/ z8 K0 ~ActiveX and plug-ins
' o7 }$ a( w3 j4 j8 q' n0 gActiveX and plug-ins are various add-ons and modules of your browser. These modules are in fact real proper programs run on the client s machine and therefore they have wider capacities than Java and Javascript. They can easily detect your browser settings and track down your real IP address. What's more, they can even easily change your proxy server s settings!! E# G5 n4 _  d; h% |

; @* a7 K0 S6 nTo secure your browser and IP address, disable ActiveX and plug-ins options in your browser settings.
; o9 |, I9 v, J" n0 p% K4 V2 Y
9 o; l9 L/ {0 X, }7 {' `Armour vs. bombs: B0 N  Y  J+ t1 q$ s
The war between those who want to stay anonymous web-surfers and those who want to know all about their clients and visitors will never end. There always will be new ways of hiding your life inside the web, likewise there always will be new technologies to hack or to pass this protection.
/ Z4 w9 f5 B; }) L3 t
. K7 {1 r+ N/ j% ^% ^! X- t+ DYou can secure your IP using several methods:
* ^& R, L9 {7 D4 A  z0 P  @' [
1 G9 ^& s% F% n8 V! ERestrictions
4 I9 a' S; K  {& e4 n( m6 \3 M, Wdisable cookies " }  [; L; _4 }7 d2 n1 s
disable active scripts
3 E2 [7 Q8 j3 S  }/ ~8 {& |, M' T+ ndisable Java
2 A) F' X1 ?1 r; O% b5 Ndisable ActiveX
# J% V1 t3 V6 TUse socksification in your browser. This will enable relaying all the information your browser or any other software sends and transfers to the proxy server. & e( i4 k( }  m
The first method of protection is very easy to pass: it only takes building a site based on Java/JavaScript/Cookies (for example, dynamic menus, etc.). In this case, if you switch off the active scripts, the site will not work (e.g. if you disable cookies, your access to web mail servers may be denied).
, w; L0 I8 ?1 B! m/ w0 p! y; x
2 f' O& h! o% h5 j' t$ Q) m3 KThe second method doesn't provide a 100% guarantee that your IP address will be really protected. Here's why. There are two methods to identify your IP:
$ h! \* p7 q- i7 {& B' G/ Y' ~7 `9 L7 ~  b- |6 A
A Java program connects directly to the Internet (without using proxy), even if your browser is set to work via proxy. So the server gets your real IP address from this Java program.
* D" h# V9 w- b2 R$ l1 O9 BYour Windows settings may be scanned for your real IP address. ( ^' I) G. Z3 `: a" T
So, socksification can guard you from the first method of IP tracing, but it's totally useless when dealing with the second method.( t5 J- f) ?# m* @
: J* E$ Q0 X8 X2 `3 P
What you need to do if you wish to stay anonymous with enabled Java/JavaScript/ActiveX: 8 [! z8 H* r, G. _8 y
What's the core of this task and what do you need to do in order to make it work?$ \* j( E" {" T' c
7 o, ~6 l+ M9 x* V2 R% b$ g4 k
hide real external IP address in Windows settings 5 f/ z, d) a5 E& a  B
disable direct connection to the Internet (route it only via an anonymous proxy server) $ p9 D  a' N7 @' D4 D" C
There are two options to solve this problem:
5 w+ C/ l; o: w; Y. q) _0 Y
6 _8 K% K0 |' \; u. d/ RYou need to set up LAN, local IP addresses (192.168.1.x or alike). A corporate proxy server should forwards ALL requests to a free anonymous proxy server (you need to have skills and rights of a system administrator in order to do that). It's impossible to connect to the Internet bypassing a corporate proxy, as long as external IP address is not assigned to local machines. It's also impossible to scan local machine's settings: even if Java/ActiveX applets detects and gives out your local IP address (192.168.1.x) to the web server, your anonymity will remain unbroken. So, basically, you can rate this option as 100% anonymity.
9 G5 m3 @/ I. p1 w2 dInstall Firewall on your machine and restrict all the connections to the Internet (except for the anonymous proxy server) from a browser. It's also recommended to use port mapping for this free anonymous proxy server and define the browser's proxy as 127.0.0.1 with the local port from port mapping. However, this option can be insecure, because your real external IP address can be transferred to the server (the script will scan the Windows settings and detect your real IP). . R/ b( K! X4 S) R( y* c
And finally: any proxy server, especially a free proxy, keeps logs (reports) with detailed information on every IP sending requests to it as well as on the time of requests. So, any person or organization authorized to access this information can always find out what places in the web you have visited and what you did there, even if you use a chaining of 10 anonymous proxy servers located in different parts of the world.
發表於 2005-9-13 09:31:43 | 顯示全部樓層
好東東
回復 给力 爆菊

使用道具 舉報

發表於 2005-9-13 09:35:33 | 顯示全部樓層
disable cookies
0 E3 q7 Z$ H6 C/ M7 Q! i& Y: Z* |disable active scripts
; _3 [8 W- c* }8 S! u! [( G" Odisable Java 6 G! p. u0 m  R, O  j  Q4 i
disable ActiveX
回復 给力 爆菊

使用道具 舉報

 樓主| 發表於 2005-9-13 09:42:57 | 顯示全部樓層
原帖由 雪狼孩 於 2005-9-13 09:31 發表  ~- w0 b9 q! h" [4 w7 }
好東東
; c+ M" G2 N$ K$ J
& [; o( r& q' u1 z  U- J" e- @
哈哈~~~東東好就來個精華哈,雖然是轉貼,但也搞的我手酸:
回復 给力 爆菊

使用道具 舉報

發表於 2005-9-13 10:47:57 | 顯示全部樓層
原帖由 道天 於 2005-9-13 09:42 發表7 Y( m2 k0 ?5 ]; I& F" ?+ n" s
) k6 g( e2 M" v! F2 y( m
3 [5 t) E$ M' }/ c( H- V8 a! I. g0 a
哈哈~~~東東好就來個精華哈,雖然是轉貼,但也搞的我手酸:

" W* A" K& u7 ?: e8 ^手酸?難道你打出來的?:
回復 给力 爆菊

使用道具 舉報

發表於 2005-9-13 11:22:45 | 顯示全部樓層
原帖由 kiss2008 於 2005-9-13 09:35 發表7 G- x& g% R* H% d  X, u' g
disable cookies
6 p% f6 r. }$ v, x; ndisable active scripts . T3 @! A" A5 V2 T, h0 j
disable Java
; u# r* J: }2 Y8 T! U9 Jdisable ActiveX

) Q0 ^7 r' K$ V0 G; S) `都禁止了,還有幾個網頁可以打開啊?
回復 给力 爆菊

使用道具 舉報

發表於 2005-9-13 11:23:23 | 顯示全部樓層
原帖由 道天 於 2005-9-13 09:12 發表
1 Z6 C7 a+ Y/ XAnti-proxy: how to detect your IP if you are using an anonymous proxy server?
( Y% L5 u1 B0 k) YAs you already know, there are anonymous proxy servers that can be used for surfing the web anonymously. It is also i ...

  j5 s) @& @1 J% q一看到英語就頭暈,怎麼辦,誰翻譯個大概。
回復 给力 爆菊

使用道具 舉報

發表於 2005-9-13 13:33:09 | 顯示全部樓層
道高一尺,魔高一丈
回復 给力 爆菊

使用道具 舉報

發表於 2005-9-13 13:41:57 | 顯示全部樓層
( 轉帖) 從國外代理論壇上看到的" 反代理" 措施.
2 O* C; e( i* w$ b( W' W, ^; X
. C' Y% l5 I  C, v" P反代理: 怎樣發現你的IP,如果你正使用一台匿名的代理服務器嗎? 2 D9 f4 _# o: |" b
正如已經的你所知,有匿名的代理服務器可能用於匿名在網上衝浪。 也有趣被知道,到那裡路的在匿名服務器代理後面追捕網上衝浪者的。 ( D  T' e% H; v( h$ D* z3 \
是的, 不僅有許多可能性使用幾台匿名的代理服務器發現一位參觀者, 而且發現他的真正的IP,即使他正使用一台匿名的代理服務器。   S, ^8 O0 W" ]/ c# g7 t4 N' W% ]

# \8 k. K  `& x- J! j, cCookie 2 f& d; M* c  F6 ?& u$ A
乍看起來,Cookie不無論如何與代理服務器有關。 Cookie用來作為被請求的網頁的增加從網服務器到客戶轉存信息的小的部分。 這附加信息被儲存在客戶s 瀏覽器裡並且被網服務器挽回。 Cookie可能兩暫時(供過去使用在一個網會議期間; 當會議結束時,這些Cookie被刪除),長期(對在客戶s機器身上的連續的商店來說)。
/ c$ h) @* P, z+ R因此,我們為什麼需要Cookie? 例如,如果口令在檢查你的電子郵件箱子時被請求。 在你已經輸入口令之後, 它被儲存在Cookie裡, 因此每當你從頁到頁瀏覽時,網服務器將在Cookie裡檢查口令而不是在每頁上要它。
5 P6 ]! ^7 F" v1 ^) ^; {: F: }6 ^$ r, W8 ]( S5 |" K
一Cookie怎樣能幫助發現一個代理人? 你不能借助於Cookie 發現IP。 但是, 當你首先訪問一個網站時, IP(即你的代理人服務器s IP)被網服務器發現然後儲存在Cookie裡。 當你重新訪問這個網站時,網服務器再次識別你的IP並且與儲存在Cookie裡的那個檢查它。 如果IPs不相同,網服務器能查明結論。 並且如果你不使在你的瀏覽器裡的Cookie無能力,沒有代理將幫助你(anonymizers 能使Cookie無能力並且停止轉播他們到你的機器)。
  Y: U) |, F7 v8 S6 q0 }. Z
$ V1 N& a/ D& w! N  o, d+ kJava腳本/ VBScript $ k' m: t( b+ f
有由客戶s 瀏覽器控制的特別的子程序(手稿)。 因此, 不管你對安裝試驗你的瀏覽器(除非你使這些活躍的手稿無能力)多麼嚴重,你將不能隱藏你的真正的IP。 手稿這些實際上被歸類當時簡單計劃並且有有限功能的數量, 但是他們能發現你的你的瀏覽器的IP和多其他設置。 這些手稿也能改變你的瀏覽器設置!   O) w. |5 f9 }& n5 S+ l9 G
5 J3 k& ]0 d( y* F
有來自這些手稿的一個多層的防護物。 你能從訪問你的瀏覽器特徵限制一篇手稿。 不過,保護你的瀏覽器的最好的方法正完全傷殘活躍的手稿。 你直接在anonymizers裡能使手稿無能力。 - y+ |$ I+ W2 h
/ h) O7 b, Q* k4 S; `
爪哇
7 b1 Q4 [0 C. G& z4 m: G$ u' ~與Java腳本不同,爪哇是一種充滿特色的程序語言。 因此Java 手稿有很多附加能力(尤其,檢測或者改變你的瀏覽器設置)。 換句話說,Java程序能容易發現你的IP 和部分你的瀏覽器的設置。 + ~0 c8 r) y3 c7 D/ b( Q

( A' z. p7 N: k& S& s只要保護你的IP以防被爪哇手稿發現去,全部都更錯綜複雜: 最安全和或許唯一的方式是完全使在瀏覽器設置裡的Java無能力, 只要Java有很多網絡功能並且關掉他們全部是十分困難的。 - L9 E; `- l  C3 @1 |1 T

& e) k# }- a: Q( D3 x. jActiveX和插頭
$ c2 j* h$ V8 jActiveX和插頭是你的瀏覽器的各種各樣的附加物和模件。 與Java和Javascript相比較,這些模件實際上是實的適當的程序在客戶s機器上運行,因此他們有更寬的能力。 他們能容易發現你的瀏覽器設置並且找出你的真正的IP 地址。 而且,他們甚至能容易改變你的代理人服務員s 底座! " ~3 _  }* q4 U: u

1 z( y; P) H" {* e6 _& v9 G5 A為了獲得你的瀏覽器和IP 地址,使ActiveX 和在你的瀏覽器設置裡的插頭選擇無能力。
. f4 K5 o# S3 S" p! Y
1 G5 u! i* J  R" |# B. o( d盔甲與炸彈 : X( R2 A% y* m$ R
在想保持匿名的網上衝浪者和想完全瞭解他們的客戶的那些人的那些人之間的戰爭和參觀者永遠不會結束。 有將新在網裡面隱藏你的生活的方式,有總是將是亂砍或者通過這保護的新技術。 " r# `& q; a  D3 j- A
2 L: n7 g, y; e# t
你能使用幾種方法獲得你的IP:
  t! P* p/ x. S5 S) E, S6 J& c3 W1 Y
限制
  \- m7 [. N2 \" d3 W4 }傷殘Cookie * U% L$ i* Y' X5 }) e
傷殘活躍的手稿 7 T" Z" I  _: Y6 ]
傷殘爪哇 # W" n; s3 U+ C! D' J" u; `
傷殘ActiveX
' I, U" e0 e  @/ k" t5 y+ C5 t在你的瀏覽器裡使用socksification。 這將使轉播你的瀏覽器或者任何其他軟件送並且轉存到代理服務器的全部信息成為可能。 ( n! k5 ~6 a! Y+ y6 P8 E& C: b( {
保護的第一個方法非常容易遞給: 它只帶建造一個基於Java / Java腳本/ Cookie(例如,動態的菜單,等等)的站點。 這樣的話, 如果你關掉活躍的手稿, 站點將不工作(例如你使Cookie無能力,你的網郵件的入口服務器可能被否認)。 6 W* \# s: f2 L* `5 E' p% g

0 E, Y) P2 S& b7 x第2 種方法不提供你的IP 地址將真的被保護的一個100%的保證。 這裡是為什麼。 有兩種方法鑒定你的IP: ; s6 N  S0 G8 ^* k7 z* x
2 E6 Q" C# i8 i7 v+ w
一個Java程序直接連接因特網(沒有使用代理), 即使你的瀏覽器被通過代理開始工作。 因此服務器從這個爪哇計劃得到你的真正的IP 地址。
: ?6 u% F$ i$ n, M" Y- I你的Windows設置可能被為你的真正的IP 地址掃瞄。
) f( q  P! F3 R' i4 s0 v- l因此, socksification 能保衛從跟蹤的IP的第一個方法那裡的你,經營第2 種方法是全部沒用的。 2 c0 S/ ]3 ?! A, z% Z: a

" R7 n: O0 S3 L8 k# k4 g0 L如果你希望與使保持匿名成為可能的爪哇/ Java腳本/ ActiveX,你需要做的: 0 o$ C! \) u7 q; o* N
這項任務的核心是什麼,並且為了使它工作,你需要做什麼? 5 M2 c: B! I. g4 N$ P2 ?6 K0 q

9 r$ x0 i: u5 E把真正的外部IP 地址隱藏在Windows設置裡 & {. d" C  `$ ]+ c$ X$ J% e: }
對因特網傷殘直接的連接(途經一台匿名的代理服務器運送只的它)
/ P' h* r8 V4 Y7 G有兩種選擇解決這個問題:
, |& j0 F4 V/ v7 _) d1 X5 f  N# R* x( |* X% v9 }6 X
你需要建立局域網,本地IP 地址(192.168.1.x或者一樣)。 一台共同的代理服務器應該把全部請求寄給一個免費匿名的代理服務員 (為了做那,你需要有一個系統管理員的技能和權利)。 連接為一個公司的代理人設旁路的因特網是不可能的,只要外部IP 地址沒被分配到本地機器。 掃瞄本地機器的底座也是不可能的: 即使Java/ActiveX小應用程序到網服務器發現並且宣佈你的本地IP 地址(192.168.1.x),你的匿名將保持不間斷。 因此,基本上,你能評價這種選擇為100%的匿名。
" n- I1 j& Z2 p1 Z/ K8 ]在你的機器上安裝防火牆並且從一個瀏覽器限制對因特網(除了匿名的代理服務器)的全部連接。 也推薦使用港口這個免費匿名的代理人菜盤的繪圖並且確定瀏覽器的委託書為有來自港口繪圖的局部的端口的127.0.0.1。 但是, 這種選擇可能是不安全的, 因為你的真正的外部IP 地址可能被轉到服務器(書寫將掃瞄Windows設置並且發現你的真正的IP)。
! r+ P3 Z2 }% J並且最後: 任何代理服務器, 一免費代理特別是,保持木材(報告)與送的在每IP上的詳細資料一起給它和關於請求的時間請求。 因此, 授權訪問這信息的任何人或者組織總是能查明在網裡你已經拜訪什麼地方和你那裡做的, 即使你使用位於世界的不同的部分的10台匿名的代理服務器的鏈接。
回復 给力 爆菊

使用道具 舉報

發表於 2005-9-13 13:58:32 | 顯示全部樓層
好貼 ,可以加精了 ! U. Q: h# N2 v' n( w

% K9 Y2 a3 ~2 M$ s% H& F" h; O& QCOOKIES不能關啊 關了之後你想用代理做些什麼呢?註冊也不計 點擊也不計……
回復 给力 爆菊

使用道具 舉報

您需要登錄後才可以回帖 登錄 | 免费注册

本版積分規則

过期高净值品牌域名预定抢注

4um點基跨境網編創業社區

GMT+8, 2024-11-24 05:18

By DZ X3.5

小黑屋

快速回復 返回頂部 返回列表