Tech News

What Is Domain fronting and How Does It Work?

Domain Fronting is a process that involves using different domain names in the Server Name Indication (SNI) header TLS field and the HTTP Title Host field. It is a useful way to bypass the internet ban, especially in third world countries. It actually hides your traffic from a particular website by hiding it as a separate domain. It is one of the ways in which an attacker can clarify his activities.

How does Domain Fronting work?

The client sends the HTTP request to the destination specified in the HTTP host title. DNS query and TLS-SNI contain a single domain (also known as a previous domain) while the HTTPs header, hidden in the test, by encrypting HTTPS, contains an invalid location. This avoidance process hides the true location of the client’s message by redirecting data through a content delivery network (CDN). So, from a firewall perspective, the HTTPS application appears to be going to an official website where it actually goes to a malicious site that is usually blocked. Domain prioritization uses different domain names in different layers.

What is a Content Delivery Network (CDN)?

CDN refers to “a group of locally distributed servers that work together to provide faster delivery of Internet content” (Cloudflare). Increases web page access to the user based on the information they request and where they are located.

The following lists examples of different CDNs:

  • Akamai
  • Cloudflare
  • ICloudFront

How does Domain Fronting work?

The client sends the HTTP request with the destination specified in the HTTP host title. DNS query and TLS-SNI contain a single domain (also known as a previous domain) while the HTTPs header, hidden in the test, by encrypting HTTPS, contains an invalid location. This avoidance process hides the true location of the client’s message by redirecting data through a content delivery network (CDN). So, from a firewall perspective, the HTTPS application appears to be going to an official website where it actually goes to a malicious site that is usually blocked. Domain prioritization uses different domain names in different layers.

The DNS and TLS-SNI requests are explicitly displayed in the previously approved domain domain. After all, if we look at the domain found in the HTTP layer, the forbidden domain, for example the forbidden, is here because it is not readable by the auditor. For the domain to work, both a malicious website and an official site must be hosted by the same CDN.

Application:

Text messaging applications such as Signal and Telegram use domain priorities to avoid research that allows people in countries like China, Russia, etc. With strict internet restrictions so they can use these programs. Those living in restricted countries can use domain placement to access restricted content.

How Can You Protect Yourself:

The best way to protect yourself against a domain is to “have a server that hosts all your Internet connections

Shadab

Shadab is a writer at bestopedia. He has a graduate degree in Computer Science Engineering and is really passionate about technology. You can find him cracking complex coding problems, and covering the latest happenings in the industry.

Share
Published by
Shadab

Recent Posts

Asus ROG Phone 6 image leaked; reveals Design details and more

Asus is all set to launch the upcoming gaming smartphone Asus ROG Phone 6 series…

9 months ago

Nothing Phone (1) offline sale at Reliance Digital stores in India starts soon; know the details

Nothing is all set to launch the upcoming Nothing Phone (1) which is the first…

10 months ago

Huawei Enjoy 50 Pro appears on TENAA certification website; revealed design details

Huawei is working to bring the upcoming Huawei Enjoy 50 series very soon. Moreover, the…

10 months ago

Vivo V25 series India launch timeline leaked; Vivo V25 Pro would launch later of Vivo V25

Vivo is working to bring the next V series Smartphone Vivo V25 series after launching…

10 months ago

Oppo Reno 8 series leaked launch date for India; Reno 8 Pro could be rebadged Reno 8 Pro Plus

The company is all set to launch the latest Oppo Reno 8 series in India…

11 months ago