Skip to content

Domain-Fronting Configuration Guide

Domain-fronting involves obfuscating C2 traffic by masquerading it as legitimate traffic from a fronted service (e.g., Google, Facebook). This technique leverages TLS Server Name Indication (SNI) to make traffic appear as if it's destined for the fronted service, bypassing network filters. Below is a practical guide to setting up domain-fronting using nghttp2 (as an HTTP/2 client library) and custom TLS certificates for authorized testing.


Prerequisites

  1. Tools: nghttp2 (HTTP/2 client library for domain-fronting), OpenSSL (for certificate generation).
  2. Certificates: A valid TLS certificate for the fronted service (e.g., fronted.example.com). If unavailable, use a self-signed certificate for simulation (note: this will not bypass real network filters).

Step 1: Generate TLS Certificates

Create a custom certificate for the fronted domain (e.g., fronted.example.com). Replace fronted.example.com with the target domain.

openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes -subj "/CN=fronted.example.com"

This generates a self-signed certificate and private key. For production, replace this with a certificate from a trusted CA (e.g., Let's Encrypt) for the fronted domain.


Step 2: Configure nghttp2 for Domain-Fronting

Use nghttp2 to send HTTP/2 requests with a forged SNI header to mimic the fronted service. Ensure TLS is configured to use the custom certificate.

Example: Fronting Traffic to google.com

  1. Send Request with Forged SNI:
    nghttp2 -u https://fronted.example.com --sni google.com -H "Host: google.com" --tls-cert cert.pem --tls-key key.pem
    

This command instructs nghttp2 to send requests to fronted.example.com while forging the Host header to google.com and setting the SNI to google.com, mimicking traffic destined for the fronted service.

  1. Verify TLS Configuration: Ensure the custom certificate is used for TLS termination. The --tls-cert and --tls-key flags specify the certificate and private key for the fronted domain.

Step 3: Route Traffic Through nghttp2

Ensure your C2 server listens on a local port (e.g., 127.0.0.1:8080). Configure clients to connect to the fronted domain (e.g., https://fronted.example.com), which will forward traffic to the C2 server while spoofing the fronted domain.


Step 4: Validate the Setup

Use tools like tcpdump or Wireshark to capture traffic and verify the SNI matches the fronted service. For example:

tcpdump -i eth0 -nn -s 0 -vvv port 443

Look for SNI: google.com in the TLS handshake.


Key Takeaways

  • Certificate Requirements: Use a valid certificate for the fronted service; self-signed certs only simulate the setup.
  • nghttp2 Configuration: Ensure TLS is configured with the fronted domain's certificate and forged SNI headers are included in requests.
  • Testing: Validate traffic obfuscation with network analysis tools.
  • Legal Disclaimer: This technique is for authorized testing only; misuse is illegal and unethical.