Habr•July 30, 2026•🇷🇺Translated from Russian

Innovative Tunneling Techniques Leverage File Storage, IMAP, Meek, and NTP for Covert Connectivity

A fresh set of unconventional tunneling approaches has surfaced in the world of proxies and VPNs, expanding options for establishing covert network links through everyday services.

File Tunnel

The core idea is straightforward yet effective: when two hosts share access to the same file storage, ordinary files can serve as the medium for TCP connectivity. File-Tunnel listens on a local TCP port; incoming connections cause data to be appended to a file. The remote instance reads the same file, reconstructs the TCP stream, and forwards it to the intended destination. Return traffic flows through a second file. Files are periodically rotated to prevent unbounded growth.

Supported storage includes SMB or NFS shares, FTP servers, RDP or Citrix mounted disks, VirtualBox shared folders, WSL, Docker volumes, and Dropbox. Recent additions provide native S3 and WebDAV support. Because many providers offer inexpensive or free-tier S3-compatible buckets, the resulting tunnel traffic appears as routine object-storage requests. Example invocation on side A forwards RDP while side B acts as the remote endpoint:

  • ft.exe --s3 --bucket mybucket --region ru-moscow-1 --access-key XXXXXXXX --secret-key XXXXXXXX -L 5000:192.168.1.20:3389

Environment variables FT_S3_ACCESS_KEY and FT_S3_SECRET_KEY keep credentials off the command line. WebDAV works with services such as Mail.ru Cloud using a simple URL and credentials.

True IMAP Tunnel (Secure)

Building on earlier serverless experiments, True IMAP Tunnel (Secure) uses an IMAP mailbox as the transport. Both tunnel endpoints authenticate to the same account and designate dedicated folders for each direction. Data frames are wrapped as draft messages via the APPEND command; they never traverse SMTP. The receiving side monitors via IDLE or polling, extracts frames, marks messages deleted, and issues EXPUNGE in batches. Optional AES-256-GCM encryption protects frames, and message appearance (subject, attachment filename) can be customized to reduce suspicion. Tested providers include Gmail, Outlook, Seznam, Mail.ru, Yandex, Timeweb, and Rambler. The single Go binary supports SOCKS5, VLESS, SSH, and can run as a Shadowsocks SIP003 plugin.

Meek

Meek, a legacy Tor pluggable transport, offers an alternative when XHTTP fails against certain CDNs. Clients issue HTTP POST requests (up to 64 KB) carrying an X-Session-Id header; the server maps sessions to TCP connections and returns responses in HTTP bodies. Empty POSTs maintain polling intervals that grow from 100 ms to 5 s. Because of its simplicity, Meek functions through shared hosting with small PHP or Python reflectors. Standalone operation is achieved by manually setting TOR_PT_* environment variables, bypassing Tor entirely. A Python wrapper converts the ephemeral SOCKS listener into a fixed TCP port for direct use with tools such as SSH.

ntptun

Extending the ICMP and DNS tunneling lineage, ntptun carries IP or UDP payloads inside NTP mode-3/4 packets using extension fields. The Linux TUN mode provides full IP-over-NTP connectivity; the Windows UDP mode maps multiple clients via port offsets. Recommended deployment places GOST with KCP between the application and ntptun, yielding an HTTP/SOCKS5 proxy whose traffic hides inside NTP. Downstream modes include honest poll (client-driven) and push (server-initiated) with keep-alives; active-probing resistance drops unexpected packets that do not match expected session behavior.

Related articles

Habr•Privacy & Surveillance

CookieTin Extension Manages Partitioned Cookies Across Firefox, Chrome and Edge

Developer Perruer2 has released CookieTin, an open-source browser extension that fully supports partitioned cookies under Firefox Total Cookie Protection and Chrome CHIPS. The tool addresses limitations in older managers like Cookie Quick Manager by correctly retrieving and deleting cookies stored with partitionKey values. It works across Firefox, Chrome and Edge using a single Manifest V3 codebase written in TypeScript and Preact. Key features include accurate cookies.txt export compatible with curl and yt-dlp, protected cookies that survive explicit deletion, and pre-save validation of browser rules for __Host- prefixes and SameSite attributes. E2E tests using Puppeteer verify handling of HttpOnly, partitioned and container cookies in all three browsers.

AntiMalware•Privacy & Surveillance

Kaspersky Premium for macOS Gains App Uninstall Feature to Remove Residual Files

Kaspersky Premium now includes an App Uninstall tool for macOS that locates and deletes leftover files such as caches, cookies, settings, and logs after applications are removed. The feature also identifies duplicate copies of programs and lets users remove all instances or select specific ones while preserving shared components used by other software. Survey data from Kaspersky shows that only 44 percent of macOS users delete unused applications, even though 56 percent regularly clear browser data and 54 percent remove unwanted media files. Residual files can contain sensitive information including account tokens, passwords, IP addresses, event logs, and personal documents, creating privacy risks especially when a device is sold or accessed by unauthorized parties. Deleted files can be restored from the trash or directly within Kaspersky Premium before the application session ends. The company also warns that malicious programs are frequently disguised as legitimate macOS cleaning utilities.

Securitylab•Privacy & Surveillance

Bypassing VPN Detection on iPhone: Detailed Methods to Avoid App Blocks

Many iPhone users encounter apps that detect and block active VPN connections even after switching servers or protocols. The detection often occurs locally on the device by inspecting network interfaces rather than relying solely on external IP addresses. This guide explains how apps identify VPN tunnels through iOS network data and provides practical workarounds including moving the VPN to a router, configuring per-app exclusions, and using web versions of services. It also covers why protocol obfuscation and port changes fail to hide local VPN activity from applications. Additional troubleshooting addresses automatic VPN profiles, ad blockers, and iCloud Private Relay interference. The article emphasizes that no universal toggle exists in iOS to hide an active VPN from all apps.

Habr•Privacy & Surveillance

New Obfuscation Method Dissolves Personal Data Records in Layer of Plausible Variants

A Russian information security researcher has proposed a data protection technique that renders stolen personal records unusable even after full compromise. The approach mixes real data such as phone numbers, emails, passports, addresses, INN and SNILS with vast numbers of semantically valid alternatives. Attackers receive nearly complete information including a 361-character message containing PIN codes and word order, yet lack the secret vector space and reconstruction algorithm required to identify the correct record. Without these components, brute-force attempts produce millions of plausible results with no architectural method to verify accuracy. The method is presented as an alternative to traditional encryption when data must remain accessible yet protected against extraction. A public sandbox is available for testing the approach.