Domain-Fronting Configuration Guide¶
Domain-fronting involves obfuscating C2 traffic by masquerading it as legitimate traffic from a fronted service (e.g., Google, Facebook). This technique leverages TLS Server Name Indication (SNI) to make traffic appear as if it's destined for the fronted service, bypassing network filters. Below is a practical guide to setting up domain-fronting using nghttp2 (as an HTTP/2 client library) and custom TLS certificates for authorized testing.
Prerequisites¶
- Tools:
nghttp2(HTTP/2 client library for domain-fronting),OpenSSL(for certificate generation). - Certificates: A valid TLS certificate for the fronted service (e.g.,
fronted.example.com). If unavailable, use a self-signed certificate for simulation (note: this will not bypass real network filters).
Step 1: Generate TLS Certificates¶
Create a custom certificate for the fronted domain (e.g., fronted.example.com). Replace fronted.example.com with the target domain.
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes -subj "/CN=fronted.example.com"
This generates a self-signed certificate and private key. For production, replace this with a certificate from a trusted CA (e.g., Let's Encrypt) for the fronted domain.
Step 2: Configure nghttp2 for Domain-Fronting¶
Use nghttp2 to send HTTP/2 requests with a forged SNI header to mimic the fronted service. Ensure TLS is configured to use the custom certificate.
Example: Fronting Traffic to google.com¶
- Send Request with Forged SNI:
This command instructs nghttp2 to send requests to fronted.example.com while forging the Host header to google.com and setting the SNI to google.com, mimicking traffic destined for the fronted service.
- Verify TLS Configuration:
Ensure the custom certificate is used for TLS termination. The
--tls-certand--tls-keyflags specify the certificate and private key for the fronted domain.
Step 3: Route Traffic Through nghttp2¶
Ensure your C2 server listens on a local port (e.g., 127.0.0.1:8080). Configure clients to connect to the fronted domain (e.g., https://fronted.example.com), which will forward traffic to the C2 server while spoofing the fronted domain.
Step 4: Validate the Setup¶
Use tools like tcpdump or Wireshark to capture traffic and verify the SNI matches the fronted service. For example:
Look for SNI: google.com in the TLS handshake.
Key Takeaways¶
- Certificate Requirements: Use a valid certificate for the fronted service; self-signed certs only simulate the setup.
- nghttp2 Configuration: Ensure TLS is configured with the fronted domain's certificate and forged SNI headers are included in requests.
- Testing: Validate traffic obfuscation with network analysis tools.
- Legal Disclaimer: This technique is for authorized testing only; misuse is illegal and unethical.