FINDING · DETECTION
Exploiting a commercial 回国VPN as a circumvention carrier requires the service to use a blacklist routing policy (tunnel only Chinese IPs) rather than a whitelist policy, and requires reverse-engineering the closed tunnel protocol. The combination of policy opacity and reverse-engineering overhead makes the approach impractical for general deployment even setting aside GFW data-center blocking.
From 2026-hellosummer61-possible-exploit-vpn — Possible to exploit 回国VPN? · Issue body · 2026 · net4people/bbs
Implications
- When designing carrier-piggybacking schemes, prefer services with open or documented tunnel protocols; closed commercial protocols require fragile reverse-engineering that breaks on any service update.
- Whitelist-routed carrier services will silently drop inner tunnels destined for non-whitelisted IPs without any censor involvement — audit the carrier's routing policy before relying on it.
Tags
Extracted by claude-sonnet-4-6 — review before relying.