{"repo":"infinet/xt_wgobfs","free":true,"listed":false,"github":"https://github.com/infinet/xt_wgobfs","clone":"git clone https://github.com/infinet/xt_wgobfs.git","description":"Iptables WireGuard obfuscation extension. Windows/Mac/BSDs see the fully compatible cross-platform CLI rs-wgobfs.","language":"C","stars":310,"topics":["kernel-module","linux-kernel","obfuscation","wireguard"],"license":"GPL-2.0","category":"networking-infra","readme_excerpt":"Iptables WireGuard obfuscation extension This is a Linux kernel module that runs on Linux. Users on Windows, Mac, BSD, and pfSense can use the fully compatible cross-platform CLI rs-wgobfs. How it works The sender and receiver share a secret key, which is used by chacha6 to hash the same input into identical pseudo-random numbers. These pseudo-random numbers are used in obfuscation. - The first 16 bytes of WG message is obfuscated. - The mac2 field is also obfuscated, if it is all zeros. - Padding WG message with random long random bytes. - Drop keepalive message with 80% probability. - Change the Diffserv field to zero. Chacha6 is chosen for its speed, as the goal is not encryption. Tested working on Alpine linux kernel 5.15, CentOS 7, Debian 10 to 13 and openSUSE 15.5. Build dependence - Alpine: alpine-sdk iptables-dev linux-lts-dev or linux-virt-dev - CentOS 7: iptables-devel kernel-devel - Debian 10 to 13 : autoconf libtool libxtables-dev linux-headers pkg-config - openSUSE 15: autoconf automake gcc kernel-default-devel libtool libxtables-devel make Build and install Build: Install: One may need run depmod -a && modprobe xt WGOBFS to load the kernel module. By default, openSUSE does not allow unsupported kernel modeule. To override, create or modify /etc/modprobe.d/10-unsupported-modules.conf , add the following line: DKMS To use DKMS, first generate a source tarball, then install it as superuser: Usage This extension takes two parameters. --key for a shared secret betwee","default_branch":null,"files":null,"tree":[],"storefront":"/r/infinet","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/infinet/xt_wgobfs/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}