Void Verge
Isn't it interesting that right when cloudflare has issues all traffic from Iran's is botnet 😅 I may guess e government is enforcihe cloudflare their polices to close the workers and warp with strong-arm. To update the term if you check the botnet range…
The cloudflare states the issue was the configuration of their database ...
and states that the bot that was handling the the determination of botnet has issues on that time so the data can not be trusted then .
and states that the bot that was handling the the determination of botnet has issues on that time so the data can not be trusted then .
👍6❤1
There is always a myth says :
the crypto is speaking tongue and a tv for bad politician decisions
the crypto is speaking tongue and a tv for bad politician decisions
👍3
GFW Update Report – November 2025
In the last GFW update (past ~2 weeks) we have some very interesting and bad changes:
- GFW gesture has completely changed since the last two weeks
- The main change is how DPI now reacts to TCP connections
- As we know, a TCP connection has a handshake and a keep-alive part
- Now the firewall does these gestures against every TCP connection:
→ When the connection is going to be established, it checks the SNI, matches it with the real certificate, and even reverses the IP to map it back to the domain
→ If the SNI does not match the IP in the firewall cache and whitelist → immediately timed out (RST)
→ If the SNI matches the IP, but the IP is in the gray list and the SNI is blocked → connection is dropped after a few packets
→ If the SNI is in the gray list or any trick on TLS handshake is recognized (fake SNI, weird extensions, forbidden fragments size,etc.) → active reset from firewall
The firewall also resets the whole gray IP list after a while.
This behavior is very clear on CDN V2Ray configs, Telegram calls, and any long connection that stays on the same IP range – they all die together when the gray list is wiped.(mostly happens from 6.pm to midnight)
- DoH is closed for all popular providers (Cloudflare 1.1.1.1, Google 8.8.8.8, Quad9, etc.)
- Fragmentation above certain packet numbers is ineffective now – old fragment tricks are mostly dead and need much more time and effort
- For the UDP side the firewall also blocks the connection after a few seconds if it can find a handshake.
QUIC protocol and WireGuard took most hits from this.
If the handshake is going to be established it mostly tries not to let you do it.
In second hand it makes a profile of your connection and if it sees normal Warp checking, it immediately blocks the connection to the endpoint – so no data passes through then.
On QUIC there is the same situation: the firewall is too cautious about handshake requests to Warp ranges no matter IPv4 or IPv6. The Warp connection to these IPs is immediately interrupted.
Overall we assess the internet situation in Iran as very frustrating for users right now.
One thing we noticed: CDN IP ranges are still less restricted than normal clean IPs.
But don’t count on them and don’t put all emergency configs behind CDNs only – this is exactly their trick!
Blocking the whole Cloudflare is much easier than finding unknown ASN/VPS provider IPs, so they keep CDN half-alive on purpose and poison clean IPs much faster.
Keep your non-CDN emergency configs ready at all times.
That’s the situation today.
©Atomic
#report #iran #gfw
In the last GFW update (past ~2 weeks) we have some very interesting and bad changes:
- GFW gesture has completely changed since the last two weeks
- The main change is how DPI now reacts to TCP connections
- As we know, a TCP connection has a handshake and a keep-alive part
- Now the firewall does these gestures against every TCP connection:
→ When the connection is going to be established, it checks the SNI, matches it with the real certificate, and even reverses the IP to map it back to the domain
→ If the SNI does not match the IP in the firewall cache and whitelist → immediately timed out (RST)
→ If the SNI matches the IP, but the IP is in the gray list and the SNI is blocked → connection is dropped after a few packets
→ If the SNI is in the gray list or any trick on TLS handshake is recognized (fake SNI, weird extensions, forbidden fragments size,etc.) → active reset from firewall
The firewall also resets the whole gray IP list after a while.
This behavior is very clear on CDN V2Ray configs, Telegram calls, and any long connection that stays on the same IP range – they all die together when the gray list is wiped.(mostly happens from 6.pm to midnight)
- DoH is closed for all popular providers (Cloudflare 1.1.1.1, Google 8.8.8.8, Quad9, etc.)
- Fragmentation above certain packet numbers is ineffective now – old fragment tricks are mostly dead and need much more time and effort
- For the UDP side the firewall also blocks the connection after a few seconds if it can find a handshake.
QUIC protocol and WireGuard took most hits from this.
If the handshake is going to be established it mostly tries not to let you do it.
In second hand it makes a profile of your connection and if it sees normal Warp checking, it immediately blocks the connection to the endpoint – so no data passes through then.
On QUIC there is the same situation: the firewall is too cautious about handshake requests to Warp ranges no matter IPv4 or IPv6. The Warp connection to these IPs is immediately interrupted.
Overall we assess the internet situation in Iran as very frustrating for users right now.
One thing we noticed: CDN IP ranges are still less restricted than normal clean IPs.
But don’t count on them and don’t put all emergency configs behind CDNs only – this is exactly their trick!
Blocking the whole Cloudflare is much easier than finding unknown ASN/VPS provider IPs, so they keep CDN half-alive on purpose and poison clean IPs much faster.
Keep your non-CDN emergency configs ready at all times.
That’s the situation today.
©Atomic
#report #iran #gfw
❤7👍2
اخرین فیچر x داره غوعا میکنه نه !
طبق مطالعاتی که ما داشتیم و کامنت های نیکیتا بیر دولوپر ایکس که در پلتفرم قرار داده این داده ها خیلی دقیق هستن و شکی توی لوکیشنشون نیست .
نیکیتا در اوایل ۲۴ دسامبر اعلام کرد که این فیچر یه باگ در تشخیص داشت که دوازده ساعت بعد فیکس شد و مشکل اون برطرف شد
بر اساس صحبت های اون و الگوریتمی که ایکس در محاسبه ونمایش این مورد پی گرفته
مواردی که در عکس بالا اومده وبه طور خلاصه :
- اولین ایپی که شخص باهاش اکانت رو ساخته
-استوری که ازش دانلود کرده
- یک محاسبه روی ایپی هایی که به دفعات وارد اکانت شده توی اون دخیل بوده.
داخل ایکس خیلی ها به افراد دولتی ادعای سیمکارت سفید داشتن چسبودن .
شکی نیست :)
اما خیلی از افراد ایرانی دیگه هم لوکیشن ایران رو براشون نشون میده !
ایا همه سیمکارت سفید دارن ؟
نه لزوما .
تمامی کاربرانی که از پروتکل هایی استفاده کردن که میتونه فیلترینگ رو دور بزنه اما ایپی ایران به سمت سرور توییتر بده (مثال بارز و خیلی محبوب وارپ که در چین و ایران استفاده میشه) لوکیشنش کشور خودش میخوره .
طبق مطالعاتی که ما داشتیم و کامنت های نیکیتا بیر دولوپر ایکس که در پلتفرم قرار داده این داده ها خیلی دقیق هستن و شکی توی لوکیشنشون نیست .
نیکیتا در اوایل ۲۴ دسامبر اعلام کرد که این فیچر یه باگ در تشخیص داشت که دوازده ساعت بعد فیکس شد و مشکل اون برطرف شد
بر اساس صحبت های اون و الگوریتمی که ایکس در محاسبه ونمایش این مورد پی گرفته
مواردی که در عکس بالا اومده وبه طور خلاصه :
- اولین ایپی که شخص باهاش اکانت رو ساخته
-استوری که ازش دانلود کرده
- یک محاسبه روی ایپی هایی که به دفعات وارد اکانت شده توی اون دخیل بوده.
داخل ایکس خیلی ها به افراد دولتی ادعای سیمکارت سفید داشتن چسبودن .
شکی نیست :)
اما خیلی از افراد ایرانی دیگه هم لوکیشن ایران رو براشون نشون میده !
ایا همه سیمکارت سفید دارن ؟
نه لزوما .
تمامی کاربرانی که از پروتکل هایی استفاده کردن که میتونه فیلترینگ رو دور بزنه اما ایپی ایران به سمت سرور توییتر بده (مثال بارز و خیلی محبوب وارپ که در چین و ایران استفاده میشه) لوکیشنش کشور خودش میخوره .
👍13❤3👏2
vWarp v2.1.1
بعد از چند ماه توسعه و تست سنگین در شرایط واقعی (ایران، چین و شبکههای شرکتی بسته)، نسخه ۲.۱.۰ آماده شد.
هدف اصلی این آپدیت یکپارچه سازی دو تا پورتکل وایرگارد و کوییک در یک هسته بوده و همینطور برای رفع فیلتر اون ها تمرکز داشته.
تمرکز اصلی دو بخش بوده:
تونل MASQUE کامل (QUIC روی HTTP/3) از طریق کلادفلر
موتور Noize؛ قویترین سیستم obfuscation متنباز فعلی که مخصوص شکستن DPI پیشرفته و فیلترهای مبتنی بر یادگیری ماشین ساخته شده.
چه چیزهایی اضافه شده:
• MASQUE پایدار + فالبک خودکار به WireGuard
• مخفیسازی چندلایه: junk packet، تقلید پروتکل، تصادفیسازی تایمینگ، خرد کردن پکت، پدینگ هوشمند
• پرستهای آماده: light • medium • heavy • stealth • gfw • firewall
• کانفیگ کامل JSON (هر پارامتر قابل تنظیم)
• سربار ۵-۱۰٪ در حالت light، حداکثر ۵۰٪ در حالت stealth
• بهینهسازی اختصاصی برای شرایط ایران و چین
فعلاً اسکنر خودکار رو کنار بذارید؛ از endpointهای تستشده و ثابت استفاده کنید.
چون برای وی وارپ فیلتر معنی نداره
اجرای پیشنهادی:
میتونید اگه روی اینترنتتون کانفیگ های پریست جواب نداد دستی اونو کانفیگ کنید
موفق باشید.
void
#vwarp
#warp
بعد از چند ماه توسعه و تست سنگین در شرایط واقعی (ایران، چین و شبکههای شرکتی بسته)، نسخه ۲.۱.۰ آماده شد.
هدف اصلی این آپدیت یکپارچه سازی دو تا پورتکل وایرگارد و کوییک در یک هسته بوده و همینطور برای رفع فیلتر اون ها تمرکز داشته.
تمرکز اصلی دو بخش بوده:
تونل MASQUE کامل (QUIC روی HTTP/3) از طریق کلادفلر
موتور Noize؛ قویترین سیستم obfuscation متنباز فعلی که مخصوص شکستن DPI پیشرفته و فیلترهای مبتنی بر یادگیری ماشین ساخته شده.
چه چیزهایی اضافه شده:
• MASQUE پایدار + فالبک خودکار به WireGuard
• مخفیسازی چندلایه: junk packet، تقلید پروتکل، تصادفیسازی تایمینگ، خرد کردن پکت، پدینگ هوشمند
• پرستهای آماده: light • medium • heavy • stealth • gfw • firewall
• کانفیگ کامل JSON (هر پارامتر قابل تنظیم)
• سربار ۵-۱۰٪ در حالت light، حداکثر ۵۰٪ در حالت stealth
• بهینهسازی اختصاصی برای شرایط ایران و چین
فعلاً اسکنر خودکار رو کنار بذارید؛ از endpointهای تستشده و ثابت استفاده کنید.
چون برای وی وارپ فیلتر معنی نداره
اجرای پیشنهادی:
vwarp.exe --masque --masque-noize --masque-noize-preset light --endpoint 162.159.198.1:443کانفیگهای آماده و راهنمای کامل در پوشه docs هست.
میتونید اگه روی اینترنتتون کانفیگ های پریست جواب نداد دستی اونو کانفیگ کنید
موفق باشید.
void
#vwarp
#warp
GitHub
Release v2.1.1-latest · voidr3aper-anon/Vwarp
What's Changed
hot-fix-config-save-interface-issue by @voidr3aper-anon in #7
Full Changelog: v2.1.0...v2.1.1
hot-fix-config-save-interface-issue by @voidr3aper-anon in #7
Full Changelog: v2.1.0...v2.1.1
❤19⚡2
Void Verge
vWarp v2.1.1 بعد از چند ماه توسعه و تست سنگین در شرایط واقعی (ایران، چین و شبکههای شرکتی بسته)، نسخه ۲.۱.۰ آماده شد. هدف اصلی این آپدیت یکپارچه سازی دو تا پورتکل وایرگارد و کوییک در یک هسته بوده و همینطور برای رفع فیلتر اون ها تمرکز داشته. تمرکز اصلی…
این نسخه که داده شد برای بعضی از دوستان مشکل رجیستر روی دستگاه ها داشت که توی اپدیدت اخر(v2.1.1) حل شده . افرادی که مسک رو نمیتونستن وصل بشن حتما دوباره امتحان کنن
❤11👍2
GFW-Slayer Update !
What's New:
- Irancell DPI blocks FIXED - High DPI censorship bypassed
- IP Block Proxy - New prototype for hard IP blocks (like telegram)
we also reconstruct the projec . from next update the old sub links will be ofw. follow the readme in the project to update the subs.
📥 Quick Links:
Iran Users (Irancell fix)
also for chiana and russia we made a all in one config and we estimate this works on youre country too . please try and feedback us for imrpvement.
V-Force Power Users(or scan Qr code above):
🔄 How to Update:
Update subscriptions in V2RayNG/V2RayN
Try Iran configs first if you're on Irancell or MCI (config below the config named irancell are the best)
Use V-Force for maximum performance
GitHub: https://github.com/voidr3aper-anon/GFW-slayer
Break free from censorship!
#GFWSlayer #V2Ray #AntiCensorship #serverless
What's New:
- Irancell DPI blocks FIXED - High DPI censorship bypassed
- IP Block Proxy - New prototype for hard IP blocks (like telegram)
we also reconstruct the projec . from next update the old sub links will be ofw. follow the readme in the project to update the subs.
📥 Quick Links:
Iran Users (Irancell fix)
also for chiana and russia we made a all in one config and we estimate this works on youre country too . please try and feedback us for imrpvement.
V-Force Power Users(or scan Qr code above):
https://raw.githubusercontent.com/voidr3aper-anon/GFW-slayer/main/configs/general/V-force.json
🔄 How to Update:
Update subscriptions in V2RayNG/V2RayN
Try Iran configs first if you're on Irancell or MCI (config below the config named irancell are the best)
Use V-Force for maximum performance
GitHub: https://github.com/voidr3aper-anon/GFW-slayer
Break free from censorship!
#GFWSlayer #V2Ray #AntiCensorship #serverless
❤15⚡1🥱1
Void Verge
GFW-Slayer Update ! What's New: - Irancell DPI blocks FIXED - High DPI censorship bypassed - IP Block Proxy - New prototype for hard IP blocks (like telegram) we also reconstruct the projec . from next update the old sub links will be ofw. follow the…
for telegram and ip block issues we have made a template that you can place a free socks proxy to use that for telegram for now . you can find the configuration at the end of the telegram configs.
even some blocked socks can be used again in this mode .
even some blocked socks can be used again in this mode .
👍8❤4
We have updated the Vwarp with some user-friendly features that are helpful in place.
— The noise obfuscation was tricky for some, and we made a config file for it. now you can just give the vwarp a config file and it will do its rest!
— For the connection, we observe that firewalls in Iran and China are extremely prone to reset, break, or time out the long VPN-like connections to any outside entity. We manage this issue with smart handling now, and the VPN, in the worst case, will reconnect automatically. It observes the transport layer communication and its performance, making it more robust against these firewall tricks. This feature is beneficial on servers too; you don't need to restart the VPN manually to restore the connection. The benchmarks showed stability up to one week.
We also have made a document (https://github.com/voidr3aper-anon/Vwarp/blob/voidr3aper-anon-readme-enhance/docs/CONFIG_FORGE.md) and describe every field that is customizable by the user to make it super adaptive with the connection it has.
All of these can be found in the project
— The noise obfuscation was tricky for some, and we made a config file for it. now you can just give the vwarp a config file and it will do its rest!
— For the connection, we observe that firewalls in Iran and China are extremely prone to reset, break, or time out the long VPN-like connections to any outside entity. We manage this issue with smart handling now, and the VPN, in the worst case, will reconnect automatically. It observes the transport layer communication and its performance, making it more robust against these firewall tricks. This feature is beneficial on servers too; you don't need to restart the VPN manually to restore the connection. The benchmarks showed stability up to one week.
We also have made a document (https://github.com/voidr3aper-anon/Vwarp/blob/voidr3aper-anon-readme-enhance/docs/CONFIG_FORGE.md) and describe every field that is customizable by the user to make it super adaptive with the connection it has.
All of these can be found in the project
GitHub
Vwarp/docs/CONFIG_FORGE.md at voidr3aper-anon-readme-enhance · voidr3aper-anon/Vwarp
an anti censorship utility for people who dont have access to free internet - voidr3aper-anon/Vwarp
❤5🥴1
We have updated the Vwarp (v2.2.2) with some user-friendly features that are helpful in place:
— The noise obfuscation was tricky for some, and we made a config file for it. now you can just give the Vwarp a config file and it will do its rest!
— For the connection, we observe that firewalls in Iran and China are extremely prone to reset, break, or time out the long VPN-like connections to any outside entity. We manage this issue with smart handling now, and the VPN, in the worst case, will reconnect automatically. It observes the transport layer communication and its performance, making it more robust against these firewall tricks.
This feature is beneficial on servers too; you don't need to restart the VPN manually to restore the connection. The benchmarks showed stability up to one week for restricted areas
We also have made a document and describe every field that is customizable by the user to make it super adaptive with the connection it has.
All of these can be found in the project
#vwarp
— The noise obfuscation was tricky for some, and we made a config file for it. now you can just give the Vwarp a config file and it will do its rest!
— For the connection, we observe that firewalls in Iran and China are extremely prone to reset, break, or time out the long VPN-like connections to any outside entity. We manage this issue with smart handling now, and the VPN, in the worst case, will reconnect automatically. It observes the transport layer communication and its performance, making it more robust against these firewall tricks.
This feature is beneficial on servers too; you don't need to restart the VPN manually to restore the connection. The benchmarks showed stability up to one week for restricted areas
We also have made a document and describe every field that is customizable by the user to make it super adaptive with the connection it has.
All of these can be found in the project
#vwarp
GitHub
Release v2.2.2 · voidr3aper-anon/Vwarp
What's Changed
Autonomous connection management by @voidr3aper-anon in #12
Full Changelog: v2.2.1...v2.2.2
Autonomous connection management by @voidr3aper-anon in #12
Full Changelog: v2.2.1...v2.2.2
👍9❤3😢2🥴1
config-masque.json
2.2 KB
👍10❤4😢3🥴1
We have been informed that atomic_anon , the researcher of team has been arrested.
First we inform all the projects in his account are guaranteed and all activites been transferred to the team in a safe place.
We will continue his way of freedom, and we do not stand aside watching this pity!
Revenge is a must, and we do not forgive and we do not forget.
First we inform all the projects in his account are guaranteed and all activites been transferred to the team in a safe place.
We will continue his way of freedom, and we do not stand aside watching this pity!
Revenge is a must, and we do not forgive and we do not forget.
😢26❤8❤🔥2🔥2🤣1
We have worked on a blog and started sharing the analytics of firewall .
From now on we try to share our post mainly there
https://voidr3aper-anon.github.io/Void-Blog/
#blog
From now on we try to share our post mainly there
https://voidr3aper-anon.github.io/Void-Blog/
#blog
Void Blog - Network Analysis, Hacking & GFW Bypass
Professional resource for network analysis, security research, and internet freedom techniques.
👍9❤5🥴1
We have updated the serverless configurations for Iran.
Tests show that they work on both TCI and MCI.
However, the general internet environment is inconsistent, so these configurations may inherit the same issues.
But overall they are robust.
#gfw_slayer
#serverless
Sub link:
https://raw.githubusercontent.com/voidr3aper-anon/GFW-slayer/refs/heads/main/configs/regional/iran/emergency-add-on-for-iran.json
Tests show that they work on both TCI and MCI.
However, the general internet environment is inconsistent, so these configurations may inherit the same issues.
But overall they are robust.
#gfw_slayer
#serverless
Sub link:
https://raw.githubusercontent.com/voidr3aper-anon/GFW-slayer/refs/heads/main/configs/regional/iran/emergency-add-on-for-iran.json
❤25👍5❤🔥2🥴2
https://voidr3aper-anon.github.io/Void-Blog/network%20monitoring/Psiphon-The-Last-Bastion-fa/
سایفون: آخرین سنگر در برابر دیوار بزرگ اینترنت ایران | Void Blog - Network Analysis, Hacking & GFW Bypass
سایفون: آخرین سنگر در برابر دیوار بزرگ اینترنت ایران | Void Blog - Network Analysis, Hacking & GFW Bypass
Void Blog - Network Analysis, Hacking & GFW Bypass
سایفون: آخرین سنگر در برابر دیوار بزرگ اینترنت ایران
گزارش تحلیلی از وضعیت سایفون و استراتژی جدید فیلترینگ برای بلاک کردن آخرین ابزار دسترسی آزاد به اینترنت در ایران
❤25👍2🥱1
Void Verge
https://voidr3aper-anon.github.io/Void-Blog/network%20monitoring/Psiphon-The-Last-Bastion-fa/ سایفون: آخرین سنگر در برابر دیوار بزرگ اینترنت ایران | Void Blog - Network Analysis, Hacking & GFW Bypass
سلام!
ما در آپدیدت جدید بلاگ نسخه ترجمه شده به فارسی گزارش های خود را هم منتشر میکنیم .
این شاید به دنبال کنندگان فارسی کمک بکند !
ما در آپدیدت جدید بلاگ نسخه ترجمه شده به فارسی گزارش های خود را هم منتشر میکنیم .
این شاید به دنبال کنندگان فارسی کمک بکند !
❤58👍9⚡1🥱1
👍19❤🔥6🥱2🎃2
New update on serverless to add faster configs.
There are now two new configs for hamrah and irancell both work.
This is worth saying that they are much better on pc v2ray core
https://raw.githubusercontent.com/voidr3aper-anon/GFW-slayer/refs/heads/main/configs/regional/iran/emergency-add-on-for-iran.json
There are now two new configs for hamrah and irancell both work.
This is worth saying that they are much better on pc v2ray core
https://raw.githubusercontent.com/voidr3aper-anon/GFW-slayer/refs/heads/main/configs/regional/iran/emergency-add-on-for-iran.json
👍26❤12🥱3❤🔥2👌1
Among everything telegram could open to help people of iran,they choose story!
Not the sheild to make them connect easier,
Not the free api proxies made for such situation
Just A slap in the face :)
Not the sheild to make them connect easier,
Not the free api proxies made for such situation
Just A slap in the face :)
👍73❤14❤🔥2👏1🥱1
By by aparat.com!!
Bullshit self choosing content
Bullshit self choosing content
👍96❤🔥18❤9😁7🔥2