#DomainFronting
MITM-DomainFronting | 638 stars | 50 forks

Receiving unencrypted data with MITM, Then send it with DomainFronting
MITM-DomainFronting - Trending on te9.dev
Receiving unencrypted data with MITM, Then send it with DomainFronting
repotrend.com
September 26, 2026 at 2:37 PM
CDN Vulnerability 'Underminr' Enables Hidden Malicious Traffic via Trusted Domains

🤖 IA: It's not clickbait ✅
👥 Users: It's not clickbait ✅

#cdnvulnerability #cybersecurity #domainfronting

View full AI summary:
CDN Vulnerability 'Underminr' Enables Hidden Malicious Traffic via Trusted Domains
Security researchers have disclosed a serious vulnerability in shared content delivery network (CDN) infrastructure dubbed “Underminr,” which allows attackers to conceal malicious communications behind legitimate, trusted domains. The flaw affects an estimated 88 million domains and undermines key security mechanisms such as DNS filtering and protective DNS services. At the core of the issue is a mismatch between the Server Name Indication (SNI) and HTTP Host headers versus the actual IP address being contacted. In practice, attackers can present a legitimate domain in the SNI and HTTP Host fields while routing traffic to the IP address of a different tenant hosted on the same shared CDN edge infrastructure. This behavior effectively enables traffic to appear trustworthy while being redirected to malicious or unintended destinations. Security analysts note that the exploit resembles and expands on earlier domain fronting techniques, which were historically used to bypass censorship and network restrictions. However, “Underminr” goes further by exploiting shared CDN edge configurations, making detection significantly harder for traditional network security tools. Reports indicate that the vulnerability has already been leveraged in real-world attacks targeting large hosting providers, even those that have deployed mitigations against similar abuse patterns. Beyond immediate exploitation, researchers warn of broader implications, especially as threat actors increasingly integrate artificial intelligence into malware development. Experts suggest that once techniques like Underminr are incorporated into AI-generated attack chains, they could become widespread in malware designed specifically to evade protective DNS systems and other network defenses. This raises concerns about large-scale stealth command-and-control infrastructures that are difficult to detect or block using conventional security approaches.
en.killbait.com
May 24, 2026 at 12:38 PM
mhr-cfw: domain fronting con GAS para eludir DPI

mhr-cfw usa Google Apps Script y Cloudflare Workers para eludir DPI con domain fronting. Cómo funciona, sus límites reales y alternativas en 2026.

#domainfronting #dpi #evasióndecensura #cloudflareworkers #googleappsscript
mhr-cfw: domain fronting con GAS para eludir DPI - DonWeb News
mhr-cfw implementa domain fronting con Google Apps Script y Cloudflare Workers para evadir inspección profunda de paquetes. Arquitectura, instalación y estado real en 2026.
donweb.news
April 30, 2026 at 7:12 AM
Cyber attackers exploit domain fronting to tunnel malicious traffic through Google services like Meet & YouTube, evading detection. Stay vigilant! #CyberSecurity #DomainFronting #GoogleServices Link: thedailytechfeed.com/exploiting-t...
September 25, 2025 at 3:30 PM
#til bei #fdroid gibt es die #android #app "Wiki fronted". Das ist ein Fork der offiziellen #wikipedia App, aber mit einbindung des #wmf #dns #resolvers und #domainfronting. So kann Deep Packet Inspection und Zensur (zB in China) umgangen werden.

Ist natürlich auch von Vorteil, wenn der im […]
Original post on no-pony.farm
no-pony.farm
May 10, 2025 at 9:40 PM