Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Great Firewall of China: solutions? - Page 2
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Great Firewall of China: solutions?

24

Comments

  • netomxnetomx Moderator, Veteran

    @Chuck said:
    How long did you use it until Softether stopped working?

    Seconds

  • TammyTammy Member
    edited October 2014

    nice to see you here


    Welcome to China.I often use shadowsocks to fuck GFW.

    1.you must change your hosts
    https://raw.githubusercontent.com/txthinking/google-hosts/master/hosts

    2.if you want to fuck gfw on your phone,you can use fqrouter(android,http://fqrouter2.softonic.cn/android) or shadowscks (ios,http://itunes.apple.com/cn/app/shadowsocks/id665729974?mt=8)

    www.shadowsocks.net provide free public shadowsocks account,but it downs now.

    3.vpn also a good way to surf the real internet in CN,but if your network provider is CMCC,openvpn may be blocked,so Cisco IPSEC VPN.

    As for vpn.I recommend VPNGate.(download link:http://theinternet.kuphp.net/vpngate-client-2014.10.11-build-9505.130836.zip)

    I have never used paid vpn,so i do not have any idea for paid vpn.

    Sorry for my bad english.

  • @netomx said:
    Seconds

    that's expected, you will also get disconnect if you use the admin console.(warning, it appears to me your internet may degrade for a few days if you get disconnected by those action multiple times, but that's just my experience).

    tbh nothing is easier then bitvise + ssh, can work with most vps out of the box with 0 config.(other then change port)
    ss is the close second

    Thanked by 1netomx
  • the only PERFECT way to bypass GFW is shadowsocks

    shadowsocks is a multiOS , versatile tunneling encrypted proxy , it support all os , and it has client for all os ,windows , linux , mac , all smortphone device , android , iphone , etc ,

    installation: (Configure-Shadowsocks-with-Supervisor)
    https://github.com/clowwindy/shadowsocks/wiki/Configure-Shadowsocks-with-Supervisor

    note:installation is takes only 2 minutes of your time: ( i tested myself)

    download client:
    https://www.shadowsocks.com/client.html

    more info:
    http://shadowsocks.org/en/config/quick-guide.html

  • Why don't the people stop the GFW? Why find ways around it rather than putting a stop to it?

  • netomxnetomx Moderator, Veteran
    edited October 2014

    @soda said:
    the only PERFECT way to bypass GFW is shadowsocks

    shadowsocks is a multiOS , versatile tunneling encrypted proxy , it support all os , and it has client for all os ,windows , linux , mac , all smortphone device , android , iphone , etc ,

    installation: (Configure-Shadowsocks-with-Supervisor)
    https://github.com/clowwindy/shadowsocks/wiki/Configure-Shadowsocks-with-Supervisor

    note:installation is takes only 2 minutes of your time: ( i tested myself)

    download client:
    https://www.shadowsocks.com/client.html

    more info:
    http://shadowsocks.org/en/config/quick-guide.html

    And the DNS?

    EDIT 1: Nvm, fixed it adding dns to the config. It is working wonderfully! Thanks!

  • netomxnetomx Moderator, Veteran

    @Silvenga said:
    Why don't the people stop the GFW? Why find ways around it rather than putting a stop to it?

    Yeah, it is as easy es

    service gfw stop

    /sarcasm

  • @netomx said:
    Yeah, it is as easy es

    service gfw stop

    /sarcasm

    Cause we tried

    shitizen@China:~$ service gfw stop * Stopping Censorship (Inbound/Outbound) server: gfw start-stop-daemon: warning: failed to kill 20237: Operation not permitted rm: cannot remove /var/run/gfw.pid': Permission denied rm: cannot remove /var/run/gfw/gfw.sock': Permission denied

    So you probably need root to do this... But we are guests users on this machine...

  • I got this

    shitizen@China:~$ service gfw stop
    ***: unrecognized service
    
  • netomx said: Yeah, it is as easy es

    There are 1.36 billion people in China. Would it truly be that difficult? I confidant if the GFW happened in the EU or America that a government would be overthrown in a month.

  • @Silvenga said:
    There are 1.36 billion people in China. Would it truly be that difficult? I confidant if the GFW happened in the EU or America that a government would be overthrown in a month.

    First, no one has admitted the existence of gfw.

    Second, the China gov has the power. This doesn't happen in EU or America so your idea doesn't work in China.

    Thanked by 2netomx ihatetonyy
  • Hiya, just returned from China on Oct 9th, so just some input here...

    Was using China Mobile and China Telecom's networks, IMO CM has fewer restrictions than CT, though I have no idea about CU. On CT, PPTP does work but encryption has to be set to a maximum (on Windows, CHAP and MS-CHAPv2 bare minimum). L2TP (sort of) works to an extent, but I did get the experience of it working for a while and disconnecting thereafter a minute or so. SSL VPN did not really work, though it could be also due to Digital Ocean SG(there seems to be some issue connecting to Digital Ocean Singapore on CT). SOCKS5 has not much of an issue on either networks, and especially on China Mobile actually almost all of the protocols does work.

  • msg7086 said: First, no one has admitted the existence of gfw.

    It's general knowledge in America where there is a number of white papers about it. There's a Wikipedia article on it.

    Second, the China gov has the power. This doesn't happen in EU or America so your idea doesn't work in China.

    Your logic is flawed. If the government has the power, and it is the people who form the government, then doesn't the people have the power?

    “People shouldn't be afraid of their government. Governments should be afraid of their people.” - Alan Moore

    "Where the people fear the government you have tyranny. Where the government fears the people you have liberty." - John Basil Barnhill

    Thanked by 1Pwner
  • @Silvenga said:

    Talk is easy. Do it.

    Thanked by 1netomx
  • eLohkCalb said: Talk is easy. Do it.

    Talking is the start of all revolutions. Although this isn't my problem, rather the "Republic" of China's.

    Define Republic:

    A state in which supreme power is held by the people and their elected representatives

  • @Silvenga said:
    and it is the people who form the government

    No. It's the governmenters who form the government. That being said, people, did not form the government. That's completely 2 class of people in China, governmenters and shitizens.

  • netomxnetomx Moderator, Veteran

    @Silvenga said:

    A state in which supreme power is held by the people and their elected representatives

    You have no idea of how's the life here in China. Come and you'll see

  • @netomx said:
    You have no idea of how's the life here in China. Come and you'll see

    I have several LowEnd Boxes gotten from here LET, which run PPTP/L2TP/Shadowsocks/OpenConnectServer with radiusd/mysql authentication, for my personal/friends use to fuck the GFW.

    as it's not public and only <10 users so till now everything works well.
    If you have some interesting to try, pls PM me

    Thanked by 2netomx shrubbles
  • Silvenga said: Would it truly be that difficult?

    Well, I mean, they have these:

    image

    Thanked by 2deadbeef TriDoxiuM
  • netomxnetomx Moderator, Veteran

    @yywudi said:
    If you have some interesting to try, pls PM me

    Do you want me to try something? Or I don't get what you meant to say

  • yywudiyywudi Member
    edited October 2014

    @netomx said:
    Do you want me to try something? Or I don't get what you meant to say

    Edit: oops, I didn't read your reply earlier that you've setup shadowsocks and get it work. great job!

    Thanked by 1netomx
  • @yywudi said:

    You didn't catch the point!

  • yywudiyywudi Member
    edited October 2014

    @msg7086 said:
    You didn't catch the point!

    hmm, didn't read carefully for all the posts...

  • netomxnetomx Moderator, Veteran

    BTW, how can I enable ktll50?

  • @Tammy said:

    It is no accident that we have met here!
    Nice to see you ,too

  • since you are posting on this forum, so you probably know how to setup a small, cheap vps. then i have the following solutions

    (1) ssh socks tunnel (putty)
    the best in my opinion. fast, reliably, never blocked.

    (2) shadowsocks socks tunnel
    ok. mostly fine, but i have problems getting to some sites.

    (3) openvpn with scramble
    without scramble, it all depends. sometimes it is fine. but often not.
    i believe, gfw uses some kind of dpi. because as soon as i tried to connect, there is an unkown ip that also tries to connect to my vpn.
    with scramble, mostly fine. but sometimes, when i connect, the first try does not work. so need to let the client automatically try 2 or 3 times. then all is fine.

    (4) softether
    tried is once or twice. it is blocked. but perhaps i am not using the right protocal.
    i have not experimented much. but whatever the default setting, it does not work.

    (5) stunnel + any http proxy, such as squid
    works fine. never blocked.

    If anyone has any ideas about why my shadowsocks does not always work. or why openvpn with scramble might have to try a few times to connect. i am interested to hear.
    or if anyone knows how to set up softether correctly. i am happy to hear that too.

  • You mean these brave men that do not surrender in front of a fucking tank?

  • @freetochoose said:

    If anyone has any ideas about why my shadowsocks does not always work. or why openvpn with scramble might have to try a few times to connect. i am interested to hear.
    or if anyone knows how to set up softether correctly. i am happy to hear that too.

    try change port, happen to me that my linode ssh port just won't connect or drop after a few minute, change to another port and bling!

    Thanked by 1netomx
  • changing port on openvpn does not work because i do not use 1194 anyway. also i cannot get openvpn to work with tcp.

    my shadowsocks works for most sites. but there are a few sites it won't connect or just keep waiting, for example www.youtube.com and www.blogger.com.

    my ssh tunnel works great, never had a problem, even staying with port 22.
    of course, it is better to stay away from port 22 because you will see a lot of attacks on port 22, even they all fail, it is annoying. for me, the easiest way to defend against attacks on port 22 is to change to another port, second, disallow root in sshd, and only allow a few users to log in in sshd.

  • netomxnetomx Moderator, Veteran

    @freetochoose said:
    changing port on openvpn does not work because i do not use 1194 anyway. also i cannot get openvpn to work with tcp.

    I know, I can't make it work :(

    my shadowsocks works for most sites. but there are a few sites it won't connect or just keep waiting, for example www.youtube.com and www.blogger.com.

    You need to add the DNS entry to the shadowsocks, and enable forwrding DNS. Mine works flawlessly.

    my ssh tunnel works great, never had a problem, even staying with port 22.
    of course, it is better to stay away from port 22 because you will see a lot of attacks on port 22, even they all fail, it is annoying. for me, the easiest way to defend against attacks on port 22 is to change to another port, second, disallow root in sshd, and only allow a few users to log in in sshd.

    fail2ban solves it. But it also works wonderfully, 0 disconnects using ethernet cable.

Sign In or Register to comment.