Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

List of missing VPNs - please help #64

Open
mineoturz opened this issue Feb 22, 2024 · 11 comments
Open

List of missing VPNs - please help #64

mineoturz opened this issue Feb 22, 2024 · 11 comments

Comments

@mineoturz
Copy link

Free VPNS that use servers not contained in this list:

  • TunnelBear
  • FreeVPN by [FreeVPN.org] (some servers) (IOS)
  • X-VPN by Free Connected Limited (IOS)
  • VPN 360: Fast & Private Proxy by Pango GmbH (IOS)
  • VPN Master - Unlimited VPN by All Connected Co.,Ltd (IOS)
  • VPN Hotspot Shield: Fast Proxy by AnchorFree Inc. (IOS)
@CameronMunroe
Copy link
Contributor

Any idea where we can find those IPs?

@mineoturz
Copy link
Author

Unfortunately, not. I was hoping you had a way to do that.

I had connected and run a packet capture on a few but there were so many networks that it connected to it needed to be automated. I don't have a way to do that, but interested in helping find a way if you don't have one.

@mineoturz
Copy link
Author

Also, I did want to ask. Have you encountered any issues when using the VPNs + datacenter lists as a firewall blacklist? I had set it and it ended up blocking a lot of common good servers. (Google, Microsoft, Apple, etc). Do you have any suggestions on how to get around that?

@splitice
Copy link
Member

Your problem is that the datacenter list blocked the datacenters of Google, Microsoft, Apple etc?

@mineoturz
Copy link
Author

Your problem is that the datacenter list blocked the datacenters of Google, Microsoft, Apple etc?

Haha, yes I suppose you're right. For some reason I thought it was a list of malicious/VPN hosting services blocks.

@splitice
Copy link
Member

Any webhost can host a VPN or non eyeball service. That doesnt make them malicious.

OpenVPN runs just as well on Azure/AWS/Google Cloud as it does on some sketchy Russian VPS provider (if not better)

@mineoturz
Copy link
Author

Understood. I guess I figured the majority of free VPN providers that have apps or software you can use are using a sketchy VPS, not just Azure/AWS/GCP. This seems to be the case in my small amount of testing but my research has been no where near comprehensive.

Lets say I'm an sysadmin at a school. I want to block VPNs so kids aren't accessing sites we've blocked during school hours. What's the best solution to this while also allowing for general web browsing and access to most common applications?

@splitice
Copy link
Member

Deep packet inspection will always be the best solution combined with flow analysis for spotting the tricky stuff.


As for the topic if this issue, ASNs or lists can be added.

For example it looks like Tunnelbear operates from general web service provider space, so unless they publish a list that might be hard to add to the VPN list (some of their providers though could be added to datacenters e.g AS201924)

A bit of sluething and others might be found. PRs welcome.

@mineoturz
Copy link
Author

Doesn't deep packet inspection require certs to be on every device to be inspected? How does this work in a BYOD environment?

Do any VPN providers publish the list of their servers?

@splitice
Copy link
Member

No. To a properly implemented system its rather irrelevant. And some do, but not many.

--

Please keep disucssions on topic. We are building two lists in this repository, not consulting on deep packet inspection for school applications i.e your job.

@mineoturz
Copy link
Author

I'd love to hear about your magical "properly implemented system" for inspecting encrypted BYOD traffic without certs.

Anyway, no prob. Sorry I can't help more with the networks related to the VPNs I provided. Do you have a somewhat automated way to collect the networks for them?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants