‹ BackHN Continuity

Thread

Xray-core concealed a certificate verification bypass vulnerability

75 points · 10 comments · timbill

  1. usernomdeguerre · · focus · HN ↗
    I get the impression that much of Xray's usage is in mainland China, do many other ecosystems use it? If not, why not?

    Naively I would expect solutions out of Mainland China to be more sophisticated due to the internet restrictions within the country and the number of people who are digitally-connected.

    But perhaps they cover for usecases one doesn't see outside the gfw.

    1. amritananda · · focus · HN ↗
      You can also use it to get around captive portals where some traffic is still allowed. Some Airline flights where messaging services are free only check the SNI, so setting the Xray domain to whatsapp.com or something similar usually works.
      1. ranger_danger · · focus · HN ↗
        What if ESNI/ECH is being used?
        1. amritananda · · focus · HN ↗
          I'm assuming you'll have to configure your DNS to use the captive portal DNS which would defeat ECH. The only time I was able to get this working as a captive portal bypass I was using a hardcoded remote IP as my Xray host so DNS wasn't an issue.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.