save-clip
EN
English
日本語
简体中文
繁體中文
한국어
Español
Português
Indonesia
Français
Deutsch
Русский
العربية
हिन्दी
Tiếng Việt
Home
Save YouTube, X videos to your phone
Community
Ask questions, AI replies
Cat Videos
Cat videos from around the world
Will it work?
Apps blocked by country
Beginner Guide
Learn VPN, security & censorship from scratch
VPN Quiz
Test your knowledge — 6 levels, win a certificate
Travel Info
China travel guide & flights
VPN News
VPN & blocks daily
Home
Community
Cat Videos
Will it work?
Beginner Guide
VPN Quiz
Travel Info
VPN News
⚔️
Level 2 — Advanced
20 questions · Pass: 16 correct
Question 1 of 20
0 / 20
1
How does DPI identify encrypted protocols when the payload is unreadable?
By analyzing packet size, timing patterns, and header metadata
By decrypting the payload using captured key material
By forcing the client to send plaintext protocol identifiers first
By examining only the TCP/UDP port numbers
2
What is active probing in the context of censorship infrastructure?
Sending test traffic to identify if a server supports circumvention tools
Passively monitoring all outbound connections for blocked domains
Using machine learning to predict censored content before blocking
Blocking all traffic from IPs that fail authentication twice
3
How does obfs4 disguise Tor traffic?
By masking packet patterns with noise and using a pluggable transport protocol
By routing all traffic through a commercial VPN endpoint first
By encrypting only the Tor control channel, not the data stream
By fragmenting packets below the DPI inspection threshold
4
What are pluggable transports in the Tor ecosystem?
Modular protocols that transform traffic before encryption to defeat fingerprinting
Alternative Tor relay nodes that accept unencrypted connections
Tools for switching between different VPN providers automatically
Middleware that routes traffic through multiple exit nodes simultaneously
5
How did meek use domain fronting, and why did this technique largely fail?
Using HTTPS SNI mismatch to hide destination; CDNs began filtering mismatched SNI/Host headers
Hiding the Tor bridge IP behind a DNS CNAME record; DNS resolvers started blocking CNAME chains
Routing through public WiFi hotspots; ISPs began blocking hotspot MAC addresses
Encrypting only the first packet; firewalls began stateful inspection of subsequent packets
6
What do Snowflake bridges do in Tor?
Relay traffic through volunteer-operated WebRTC proxies without revealing bridge IP
Accelerate Tor circuits by compressing data at the first hop
Distribute Tor directory information across decentralized storage nodes
Rotate exit node countries every 30 seconds to avoid IP blocking
7
What is WebTunnel and what problem does it solve?
A pluggable transport that mimics HTTPS traffic to bypass protocol-fingerprint blocking
A DNS-over-HTTPS resolver that masks query patterns from ISPs
A method to split VPN traffic across multiple carrier networks in parallel
A daemon that automatically switches between Tor and I2P based on latency
8
How does OONI measure internet censorship?
By running active tests for DNS blocking, TCP blocking, and HTTP interference from volunteer vantage points
By passively capturing ISP traffic logs and analyzing blocked domain lists
By sending fake copyright notices to networks to observe their response patterns
By correlating BGP route changes with reported outages from social media
9
What is the key difference between OONI Probe and OONI Explorer?
Probe is measurement software; Explorer is a web interface to visualize collected data
Probe detects only DNS blocks; Explorer detects TCP and HTTP blocks
Probe requires root access; Explorer runs in userspace only
Probe tests one country; Explorer aggregates results across all countries
10
What are V2Ray and Xray at a high level?
Modular proxy frameworks with pluggable protocol implementations for circumvention
Commercial VPN applications with built-in kill switches and IP leak protection
DNS filtering tools that block malware domains before resolution
Torrent client extensions that hide peer identities via DHT encryption
11
What is VMess in the V2Ray ecosystem?
A V2Ray proprietary protocol with optional obfuscation and dynamic port allocation
A cryptographic hash function used only for authentication, not encryption
A DNS protocol extension for resolving .onion addresses
A BGP hijacking technique used by V2Ray relay nodes
12
What does the Trojan-GFW protocol disguise itself as?
Normal TLS/SSL traffic by impersonating HTTPS handshakes
BGP routing updates between autonomous systems
NTP (Network Time Protocol) packets for time synchronization
ICMP echo requests that mimic standard ping utility behavior
13
What is Shadowsocks and where did it originate?
A lightweight SOCKS5 proxy with stream cipher encryption, created in China circa 2012
A commercial closed-source VPN protocol owned by a US corporation
An open academic research project funded by the Tor Project
A kernel-level packet filter built into Linux distributions
14
How is RST injection used by some firewalls for censorship?
Sending spoofed TCP RST packets to terminate connections to blocked destinations
Refusing to forward RST packets, causing connections to hang indefinitely
Injecting RST packets into unencrypted HTTP streams to corrupt payloads
Blocking only RST packets while allowing SYN and ACK to pass
15
What is MTProxy and what application is it associated with?
A Telegram proxy protocol designed to disguise Telegram traffic as HTTPS
A multi-threaded DNS proxy that caches recursive queries
A WebSocket tunneling protocol for TURN server traversal
A firewall middleware that inspects MQTT sensor network traffic
16
Why do TLS 1.3 and ECH together threaten SNI-based censorship?
ECH encrypts SNI before reaching the firewall, making site blocking via SNI impossible
TLS 1.3 removes all hostname information, forcing firewalls to block by IP alone
ECH allows clients to tunnel through proxy servers without any TLS negotiation
Together they enable out-of-band DNS queries that bypass firewall rules entirely
17
What is the CONNECT method in HTTP proxies?
A tunneling method that establishes a bidirectional byte pipe for arbitrary protocols
An HTTP verb used only for downloading files with resume capability
A mechanism to authenticate users before allowing any HTTP requests
A caching directive that prefetches resources for faster loading
18
What does a stateful packet inspection firewall track beyond simple ACLs?
Connection state, sequence numbers, and protocol-specific behavior patterns
Only source and destination IP addresses and port numbers
Only the TCP window size and MSS advertised in SYN packets
Only DNS query names and DNSSEC validation status
19
How does the Great Firewall handle fully encrypted unknown protocols?
Using flow fingerprinting and statistical analysis to identify and block by pattern
By decrypting all traffic using pre-shared government keys
By immediately blocking all unrecognized port numbers regardless of content
By requesting certificate pinning information from all upstream CAs
20
What does residual fingerprinting in WireGuard look like to a censor?
Fixed packet sizes and regular keepalive intervals that distinguish it from random traffic
Unencrypted IP addresses visible in the outer packet header after decryption
DNS queries in plaintext before the WireGuard tunnel is fully established
BGP announcements from the WireGuard interface revealing the tunnel endpoint
Finish test
×
⭐
Save save-clip!
Bookmark us for quick access to all video tools
Ctrl+D
Tap the share icon → Add to Home Screen