VPN & Proxy Detection, Browser Spoof Detection using TCP - eBay Suspended & PayPal Limited Forums
eBay Suspension & PayPal Limited Forums  
Join Today
Register Subscribe
     

Registration is fast, simple and absolutely free so please, join our community today!


Go Back   Home > Stealth Topics > IP Address

IP Address Changing your IP address, multiple IPs, VPNs, hiding your IP, phone tethering, MiFi devices, hotspots and more.

Reply
 
Thread Tools
  #1  
Old 05-24-2018
Junior Member
 
Join Date: May 2018
Posts: 84
Thanks: 0
Thanked 1 Time in 1 Post
Activity: 0%
Longevity: 41%
iTrader: (0)
Exclamation VPN & Proxy Detection, Browser Spoof Detection using TCP

I recently came across this new tool that leaks a lot of information about your network and browser.

Please have a look at this http://witch.valdikss.org.ru/ and this article as well
https://medium.com/@ValdikSS/detecti...e-1bcc59742413


I'm 100% verified that PayPal uses TCP OS Fingerprinting using a software called NetScanTools. I saw PayPal IP requesting TCP OS Fingerprint.

Anyone knows how to spoof this TCP OS fingerprint?
Reply With Quote
The complete step-by-step guide to get back to selling today!

  #2  
Old 05-24-2018
phaz0rz's Avatar
Executive [VIP]
 
Join Date: Nov 2015
Posts: 11,058
Thanks: 2,141
Thanked 4,075 Times in 3,054 Posts
Activity: 58%
Longevity: 54%
iTrader: (2)
Send a message via ICQ to phaz0rz Send a message via AIM to phaz0rz Send a message via Yahoo to phaz0rz
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

Use virtual machines with a different OS and browser on each.
__________________
____________
_______
___
Reply With Quote
  #3  
Old 05-24-2018
Junior Member
Threadstarter  
 
Join Date: May 2018
Posts: 84
Thanks: 0
Thanked 1 Time in 1 Post
Activity: 0%
Longevity: 41%
iTrader: (0)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

Quote:
Originally Posted by phaz0rz View Post
Use virtual machines with a different OS and browser on each.
it does not work. This is TCP Fingerprint which uses your Router to get info.
Reply With Quote
  #4  
Old 05-24-2018
Junior Member
Threadstarter  
 
Join Date: May 2018
Posts: 84
Thanks: 0
Thanked 1 Time in 1 Post
Activity: 0%
Longevity: 41%
iTrader: (0)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

Quote:
Originally Posted by phaz0rz View Post
Use virtual machines with a different OS and browser on each.
Virtual Machine also can be detected using JavaScript Timing.
Reply With Quote
  #5  
Old 05-24-2018
phaz0rz's Avatar
Executive [VIP]
 
Join Date: Nov 2015
Posts: 11,058
Thanks: 2,141
Thanked 4,075 Times in 3,054 Posts
Activity: 58%
Longevity: 54%
iTrader: (2)
Send a message via ICQ to phaz0rz Send a message via AIM to phaz0rz Send a message via Yahoo to phaz0rz
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

Quote:
Originally Posted by iloveghosts View Post
it does not work. This is TCP Fingerprint which uses your Router to get info.
The virtual network adapter of my VMs DHCP it's own local IP from the router. So my router sees each VM as a different host. Unless TCP is sending info about all connected devices on my network I don't see why this would be an issue.
__________________
____________
_______
___
Reply With Quote
  #6  
Old 05-24-2018
phaz0rz's Avatar
Executive [VIP]
 
Join Date: Nov 2015
Posts: 11,058
Thanks: 2,141
Thanked 4,075 Times in 3,054 Posts
Activity: 58%
Longevity: 54%
iTrader: (2)
Send a message via ICQ to phaz0rz Send a message via AIM to phaz0rz Send a message via Yahoo to phaz0rz
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

Quote:
Originally Posted by iloveghosts View Post
Virtual Machine also can be detected using JavaScript Timing.
How?

I think using a bunch of different computers on different networks is the only workaround then.


Regardless, it's never been an issue for me.
__________________
____________
_______
___
Reply With Quote
  #7  
Old 05-24-2018
yankee's Avatar
Executive [VIP]
 
Join Date: Nov 2013
Posts: 8,981
Thanks: 2,744
Thanked 3,109 Times in 2,282 Posts
Activity: 0%
Longevity: 64%
iTrader: (2)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

This over the top paranoia for ebay and paypal is only for people trying to do some really sketchy stuff and hiding from the law.
Reply With Quote
  #8  
Old 05-24-2018
nate's Avatar
Senior Member
 
Join Date: Jul 2016
Posts: 990
Thanks: 169
Thanked 412 Times in 270 Posts
Activity: 0%
Longevity: 51%
iTrader: (0)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

MTU value for VPN is a known issue. You can see it on whoer.net under extended version > TCP/IP. Its been that way forever and nothing has come of it yet. There must not be enough solid info that comes from this to determine you are using a VPN unless are using LT2P/IPsec client to connect. The info LT2P/IPsec gives, gives you away.

If you build your own VPN servers like I do you can always set your own MTU value on the server side from 1500 MTU to something lower to make the MTU numbers different from your other accounts. But why. Its not necessary.
Reply With Quote
  #9  
Old 05-24-2018
Junior Member
Threadstarter  
 
Join Date: May 2018
Posts: 84
Thanks: 0
Thanked 1 Time in 1 Post
Activity: 0%
Longevity: 41%
iTrader: (0)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

Quote:
Originally Posted by phaz0rz View Post
The virtual network adapter of my VMs DHCP it's own local IP from the router. So my router sees each VM as a different host. Unless TCP is sending info about all connected devices on my network I don't see why this would be an issue.
You are using VM under host machine. I think this needs a special kind router to spoof TCP fingerprint with special firmware.

Regarding VM leak, Please do view following articles :

https://www.blackhat.com/docs/asia-1...-Detection.pdf

http://www.securitygalore.com/site3/...d_vm_detection

http://citeseerx.ist.psu.edu/viewdoc...=rep1&type=pdf

https://packetstormsecurity.com/file...-Browsers.html
Reply With Quote
  #10  
Old 05-24-2018
Junior Member
Threadstarter  
 
Join Date: May 2018
Posts: 84
Thanks: 0
Thanked 1 Time in 1 Post
Activity: 0%
Longevity: 41%
iTrader: (0)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

Quote:
Originally Posted by nate View Post
MTU value for VPN is a known issue. You can see it on whoer.net under extended version > TCP/IP. Its been that way forever and nothing has come of it yet. There must not be enough solid info that comes from this to determine you are using a VPN unless are using LT2P/IPsec client to connect. The info LT2P/IPsec gives, gives you away.

If you build your own VPN servers like I do you can always set your own MTU value on the server side from 1500 MTU to something lower to make the MTU numbers different from your other accounts. But why. Its not necessary.
it's not about MTU man, Look at this whole TCP thing. It has a lot of different things such as Uptime, TCP Time, Language.

I know Mullvad VPN fix TCP problem but their VPN IP's are easy can be detected.
Reply With Quote
  #11  
Old 05-24-2018
nate's Avatar
Senior Member
 
Join Date: Jul 2016
Posts: 990
Thanks: 169
Thanked 412 Times in 270 Posts
Activity: 0%
Longevity: 51%
iTrader: (0)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

Quote:
Originally Posted by iloveghosts View Post
it's not about MTU man, Look at this whole TCP thing. It has a lot of different things such as Uptime, TCP Time, Language.

I know Mullvad VPN fix TCP problem but their VPN IP's are easy can be detected.
Yea, but your talking about something that can be detected by a opensource program like the tools in Kali Linux. To build something like that on the scale that ebay, PayPal, and amazon need could take years... and that's if its even possible to incorporate in their system.
Reply With Quote
  #12  
Old 05-24-2018
Junior Member
Threadstarter  
 
Join Date: May 2018
Posts: 84
Thanks: 0
Thanked 1 Time in 1 Post
Activity: 0%
Longevity: 41%
iTrader: (0)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

Quote:
Originally Posted by nate View Post
MTU value for VPN is a known issue. You can see it on whoer.net under extended version > TCP/IP. Its been that way forever and nothing has come of it yet. There must not be enough solid info that comes from this to determine you are using a VPN unless are using LT2P/IPsec client to connect. The info LT2P/IPsec gives, gives you away.

If you build your own VPN servers like I do you can always set your own MTU value on the server side from 1500 MTU to something lower to make the MTU numbers different from your other accounts. But why. Its not necessary.
There are a lot of ways to detect VPN.

1. IP Network Intelligence.
2. IP Hostnames
3. They can also extract ISP name and scrape whole Google to find out who owns it. This can be done easily.

4. Ping Time: They can measure IP latency and detect VPN and Proxies.


I do not know much about TCP but I believe there are new TCP headers with additional info. Witch use p0f but p0f not updated since 2004 as I believe. TCP archived lot of advance since then. I can't find any new articles related to TCP fingerprinting.

There is one big company called TheartMetrix who heavily use TCP. PayPal also uses TheartMetrix as they defined in their Privacy Policy.

Last edited by iloveghosts; 05-24-2018 at 09:50 AM.
Reply With Quote
  #13  
Old 05-24-2018
Junior Member
Threadstarter  
 
Join Date: May 2018
Posts: 84
Thanks: 0
Thanked 1 Time in 1 Post
Activity: 0%
Longevity: 41%
iTrader: (0)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

Quote:
Originally Posted by nate View Post
Yea, but your talking about something that can be detected by a opensource program like the tools in Kali Linux. To build something like that on the scale that ebay, PayPal, and amazon need could take years... and that's if its even possible to incorporate in their system.
Why do you say that? It's already incorporated. I set up a small honeypot and PayPal does request TCP and ICMP details. It does not take years. It only takes about 1-2 days. Nowadays they use Big data and machine learning system to analyze everything under seconds. Both Amazon and PayPal heavily hire data scientists to build this impossible tools.

ML systems can be used to detect patterns. As an example how you move the mouse is only unique to you. Please see this new company who use Mouse and Behavior-based fingerprinting: www.biocatch.com
Reply With Quote
  #14  
Old 05-24-2018
Junior Member
Threadstarter  
 
Join Date: May 2018
Posts: 84
Thanks: 0
Thanked 1 Time in 1 Post
Activity: 0%
Longevity: 41%
iTrader: (0)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

I do not use VPN's. I use AT&T hotspots. I just need a way to spoof this TCP stuff.
Reply With Quote
  #15  
Old 05-24-2018
nate's Avatar
Senior Member
 
Join Date: Jul 2016
Posts: 990
Thanks: 169
Thanked 412 Times in 270 Posts
Activity: 0%
Longevity: 51%
iTrader: (0)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

A vpn shouldnt use a DNS name. There is an option to disable it. Its only needed if the IP of the server running the VPN software isnt static, or your behind a router.

The only way to get around these issues is to wait until they implement it, ban you, and try to find the loop hole with trial and error. Other wise its a waist of time and time is money.

Dont get me wrong. I appreciate the knowledge.... I've waisted hundreds if not thousands of hours working on VPN's to try and figure out everything there was to figure out. Problem is I think its never ending...

I literally wasted the whole day yesterday trying to fix my Chromebook because the built in Strongswan UI for OpenVPN got messed up by googles new update.

I tried all day to set up the VPN connection with Chrome OS's built in OpenVPN 2.4.4 through the command line in a shell. I was able to get connected but something was wrong with the DNS name server. I tried everything... Changing the name server on the VPN server that gets pushed by DHCP... I tried changing the DNS nameserver in /etc/resolv.config inside Chrome OS.... I tried pushing the DNS nameserver through the command line with echo "nameserver 8.8.8.8" >> "etc/resolv.config".... Nothing... it still took forever for the DNS to translate...

I ened up fixing the UI by disabling network config in Chrome OS by going to Chrome://flags/#disable-network-config-settings-config

That took me all the way up until 10pm to figure out. Waisted a whole day just to connect two of my accounts to their VPN's... Because I didnt want to use the built in Cisco (LT2P/IPsec) vpn client. Since it gives you away your behind a VPN.

Last edited by nate; 05-24-2018 at 10:04 AM.
Reply With Quote
  #16  
Old 05-24-2018
SBC SBC is offline
Subscribed [VIP]
 
Join Date: May 2018
Posts: 5
Thanks: 3
Thanked 1 Time in 1 Post
Activity: 0%
Longevity: 41%
iTrader: (0)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

Wow! Just read the "invisible challenges" on biocatch.
Reply With Quote
  #17  
Old 05-24-2018
nate's Avatar
Senior Member
 
Join Date: Jul 2016
Posts: 990
Thanks: 169
Thanked 412 Times in 270 Posts
Activity: 0%
Longevity: 51%
iTrader: (0)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

Quote:
Originally Posted by iloveghosts View Post
I do not use VPN's. I use AT&T hotspots. I just need a way to spoof this TCP stuff.
Why would you care. There are millions of people using a hotspot right this second for legitimate reasons.

You blend right in. A hotspot on a burner phone with no info connected to you is the best thing to hide behind.

Your best bet is to run Linux on the client side. then you can spoof MAC address and what ever else you are worried about.

Most people would think I'm lame using a Chromebook. They dont realize a Chromebook is a Linux machine that can do almost anything you can throw at it through the command line in shell. Just have to put the Chromebook in DEV mode.

Last edited by nate; 05-24-2018 at 10:27 AM.
Reply With Quote
  #18  
Old 05-24-2018
Junior Member
Threadstarter  
 
Join Date: May 2018
Posts: 84
Thanks: 0
Thanked 1 Time in 1 Post
Activity: 0%
Longevity: 41%
iTrader: (0)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

Quote:
Originally Posted by nate View Post
A vpn shouldnt use a DNS name. There is an option to disable it. Its only needed if the IP of the server running the VPN software isnt static, or your behind a router.

The only way to get around these issues is to wait until they implement it, ban you, and try to find the loop hole with trial and error. Other wise its a waist of time and time is money.

Dont get me wrong. I appreciate the knowledge.... I've waisted hundreds if not thousands of hours working on VPN's to try and figure out everything there was to figure out. Problem is I think its never ending...

I literally wasted the whole day yesterday trying to fix my Chromebook because the built in Strongswan UI for OpenVPN got messed up by googles new update.

I tried all day to set up the VPN connection with Chrome OS's built in OpenVPN 2.4.4 I was able to get connected but something was wrong with the DNS name server. I tried everything... Changing the name server on the VPN server that gets pushed by DHCP... I tried changing the DNS nameserver in /etc/resolv.config inside Chrome OS.... I tried pushing the DNS nameserver through the command line with echo "nameserver 8.8.8.8" >> "etc/resolv.config".... Nothing... it still took forever for the DNS to translate...

I ened up fixing the UI by disabling network config in Chrome OS by going to Chrome://flags/#disable-network-config-settings-config

That took me all the way up until 10pm to figure out. Waisted a whole day just to connect two of my accounts to their VPN's... Because I didnt want to use the built in Cisco (LT2P/IPsec) vpn client. Since it gives you away your behind a VPN.

They've already implemented everything. They spent millions of dollars to build these things. Trust me, Aspkin people still have problems because of this little stuff like TCP. PayPal's people are Javascript gurus. Look at their obfuscated javascript scripts from here :

https://www.paypalobjects.com/websta...prod.pp.min.js
https://c.paypal.com/webstatic/r/fb/...rod.pp2.min.js

FB does not mean Facebook. It's PayPal own way to trick people to think script related to Facebook.

This script also uses HTML5 file API :

HTML5 FileAPI can be used to extract your computer name and file paths. Some companies use HTML5 FileAPI to get VBOX name to detect VM's.

Right now, Chrome has protections against FileAPI but Firefox & many other browsers are not.
Reply With Quote
  #19  
Old 05-24-2018
Junior Member
Threadstarter  
 
Join Date: May 2018
Posts: 84
Thanks: 0
Thanked 1 Time in 1 Post
Activity: 0%
Longevity: 41%
iTrader: (0)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

Quote:
Originally Posted by nate View Post
Why would you care. There are millions of people using a hotspot right this second for legitimate reasons.

You blend right in. A hotspot on a burner phone with no data connection to you is the best thing to hide behind.

Your best bet is to run Linux on the client side. then you can spoof MAC address and whatever else you are worried about.

The problem is not fixed because no one cared. I do not need to spoof MAC address, I just want to fix TCP stuff to create better stealth accounts.

I know millions of people using a hotspot for legitimate stuff but I want it for Stealth accounts which are gray actually.
Reply With Quote
  #20  
Old 05-24-2018
aspkin's Avatar
Administrator
 
Join Date: Jan 2007
Posts: 11,399
Thanks: 3,100
Thanked 4,272 Times in 1,816 Posts
Activity: 8%
Longevity: 100%
iTrader: (24)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

If it's not broken, don't fix it.

Fresh VPNs work. I use VPN for all my accounts. Thousands of people on this forum use VPNs without any issue. It's more about the quality of that IP rather than whether you're using a VPN or not.

Mifi device works too and as you mentioned it's used by millions of people without issue.

We know about browser fingerprinting and there are ways around that as well. It's not in PayPal's interest to be overly strict about browser fingerprinting; it would block or give trouble to too many good people. Amazon is strict about it but VMs help here.

When things get harder we adjust.

I would be more concerned about other areas of stealth which you can't spoof. Everything else is easy.
Reply With Quote
  #21  
Old 05-24-2018
nate's Avatar
Senior Member
 
Join Date: Jul 2016
Posts: 990
Thanks: 169
Thanked 412 Times in 270 Posts
Activity: 0%
Longevity: 51%
iTrader: (0)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

Quote:
Originally Posted by iloveghosts View Post
The problem is not fixed because no one cared. I do not need to spoof MAC address, I just want to fix TCP stuff to create better stealth accounts.

I know millions of people using a hotspot for legitimate stuff but I want it for Stealth accounts which are gray actually.

I'm confused... with stealth, the nail that stands out gets hammered. If you hide all your TCP info you would stand out. If you spoofed it to look like a regular user. You would look like you do now.

There is no one single finger print for a PC that I know of. There are only odds of how many other PC's have the same finger print. The more PC's have the same finger print the better off you are.

If you want to kill all this, why dont you run Windows or Linux with a GUI on a VPS and remote into it with teamviewer or something similar.
Reply With Quote
  #22  
Old 05-24-2018
Junior Member
Threadstarter  
 
Join Date: May 2018
Posts: 84
Thanks: 0
Thanked 1 Time in 1 Post
Activity: 0%
Longevity: 41%
iTrader: (0)
Default Re: VPN & Proxy Detection, Browser Spoof Detection using TCP

Quote:
Originally Posted by aspkin View Post
If it's not broken, don't fix it.

Fresh VPNs work. I use VPN for all my accounts. Thousands of people on this forum use VPNs without any issue. It's more about the quality of that IP rather than whether you're using a VPN or not.

Mifi device works too and as you mentioned it's used by millions of people without issue.

We know about browser fingerprinting and there are ways around that as well. It's not in PayPal's interest to be overly strict about browser fingerprinting; it would block or give trouble to too many good people. Amazon is strict about it but VMs help here.

When things get harder we adjust.

I would be more concerned about other areas of stealth which you can't spoof. Everything else is easy.
It's broken that's why we have to fix it. Your account maybe running but my accounts getting worse every day. They actually can fingerprint your whole router with this stuff.

Like I said, I do not care about browser fingerprinting, because I already fixed that one myself.
Reply With Quote
Reply




Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
MAC address detection by eb/pp.. Possible? PolMart PayPal Talk 48 05-25-2018 02:02 PM
Amazon have 'different' methods of detection? starengine Amazon 2 04-10-2018 12:30 PM
I.P. Address Detection? yellowrotorway eBay Tracking 52 04-13-2015 08:57 AM
new detection method on amazon? Speeder33 Amazon X 36 02-29-2012 11:00 AM
New detection methods? KingDog Amazon 22 01-08-2012 10:26 PM


All times are GMT -5. The time now is 06:19 AM.


Stop the guessing games and learn how you can quickly and easily get back on eBay today!
Read the best selling step-by-step eBay Suspension guide eBay Stealth!
Rotating Residential Proxies? Head to IPBurger for Residential Proxies
vBulletin® Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
Ad Management by RedTyger
no new posts