1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
|
.TH DPIBREAK 1 "February 2026" "DPIBreak {{VERSION}}" "User Commands"
.nh
.ad l
.SH NAME
dpibreak \- simple and efficient DPI circumvention tool in Rust.
.SH SYNOPSIS
.B dpibreak
.RI [ OPTIONS ]
.SH DESCRIPTION
.B DPIBreak
is a simple and efficient tool for circumventing Deep Packet
Inspection (DPI), especially on HTTPS connections. It fragments the
TCP packet carrying the TLS ClientHello so that certain DPI devices
cannot extract the Server Name Indication (SNI) field and identify the
destination site.
It only applies to the first outbound segment that carries the TLS
ClientHello; Other packets are not queued to userspace and pass
through the kernel normally, unmodified. UDP/QUIC (HTTP/3) is not
affected.
This program is cross\-platform and runs the same way on both Linux
and Windows. No manual firewall configuration is required: starting
the program enables it system\-wide; stopping it disables it.
.SH REQUIREMENTS
.TP
\fBLinux\fR
Root privileges (or capabilities
.BR CAP_NET_ADMIN
and
.BR CAP_NET_RAW )
are required to install rules and attach to NFQUEUE. The
.B nft
command should be available. If it is not,
.B dpibreak
try to fallback
.B iptables
and
.B ip6tables.
Kernel support for
.BR nfnetlink_queue
and
.BR xt_u32
(when
.B nft
is not available)
is required. (these modules are typically auto\-loaded)
.TP
\fBWindows\fR
Administrator privilege is required to open the
WinDivert driver; the program opens the driver automatically at
startup.
.SH OPTIONS
.TP
.BR \-D ", " \-\-daemon
Run as a background daemon. Logs are written to
.B /var/log/dpibreak.log.
If a daemon is already running, it will fail with "unable to lock pid
file". To stop it, run
.B kill \(gacat /run/dpibreak.pid\(ga
as root.
.RS
.PP
On Windows, this option enters the service controller entry
point. Example:
.B sc create dpibreak binPath= \(dqdpibreak.exe \-D\(dq start= auto; sc start dpibreak
.RE
.TP
.B \-\-delay\-ms \fI<u64>\fR
Delay in milliseconds to apply between fragmented pieces of the
ClientHello. Typical values are 0–1000; larger values may increase
handshake latency. (Default: {{DEFAULT_DELAY_MS}})
.TP
.B \-\-fake
Enable
.B fake
ClientHello packet injection before sending each packet
fragmented. TCP/IP header fields follow the original packet unless you
override it using the
.B \-\-fake\-*
options described below. Packets are transmitted in an interleaved
order: (fake 1), (orig 1), (fake 2), (orig 2), ...
.TP
.B \-\-fake\-ttl \fI<u8>\fR
Override ttl (IPv4) / hop_limit (IPv6) of
.B fake
packet. Implicitly enables
.BR \-\-fake .
(Default: {{DEFAULT_FAKE_TTL}})
.TP
.B \-\-fake\-autottl
Automatically infer the hop count (TTL/Hop Limit) to the destination by
analyzing the SYN/ACK packet. It assumes the server's initial TTL is
either 64, 128, or 255. The inferred value is used for
.B fake
packet transmission to ensure they reach the censor but not the
destination. By default, it uses a delta of 1. If the hop count cannot
be determined, it falls back to the value specified by
.BR \-\-fake\-ttl .
Implicitly enables
.BR \-\-fake .
.TP
.B \-\-fake\-badsum
Corrupts the TCP checksum of
.B fake
packets. When enabled,
.B fake
packets cannot pass through most routers and will not behave as
expected. It can be useful if your router/firewall provides an option
to disable TCP checksum verification. Implicitly enables
.BR \-\-fake .
.TP
.B \-\-queue\-num \fI<u16>\fR
.Linux only.
NFQUEUE number to attach to. The same queue number is
used for IPv4 and IPv6. (Default: {{DEFAULT_QUEUE_NUM}})
.TP
.B \-\-nft\-command \fI<string>\fR
.Linux only.
Custom nftables command to be executed. (Default: {{DEFAULT_NFT_COMMAND}})
.TP
.B \-\-log\-level \fI<debug|info|warning|error>\fR
Set the logging level (Default: {{DEFAULT_LOG_LEVEL}}).
Aliases:
.BR warn " \-> " warning ,
.BR err " \-> " error .
.TP
.B \-\-no\-splash
Disable splash messages at startup.
.TP
.BR \-h ", " \-\-help
Show usage information and exit.
.SH EXAMPLES
.PP
Run with default options:
.PP
.RS
.B dpibreak
.RE
.PP
Run as daemon with
.B fake
feature:
.PP
.RS
.B dpibreak \-D \-\-fake\-autottl
.RE
.PP
Run with a 10 ms delay and verbose logging:
.PP
.RS
.B dpibreak \-\-delay\-ms 10 \-\-loglevel debug
.RE
.PP
Use a custom NFQUEUE on Linux:
.PP
.RS
.B dpibreak \-\-queue\-num 3
.RE
.PP
Run with
.B fake
feature:
.PP
.RS
.B dpibreak \-\-fake\-autottl
.RE
.PP
.SH BUGS
Although the program works reliably in the author's region and ISP,
different regions, ISPs, or organizations may deploy different DPI
equipment. In such cases, there is a chance that
.B dpibreak
does not function as expected. If you encounter such issue, please
report symptoms and, if possible, packet capture logs (e.g., collected
with Wireshark) or hints such as cases where alternative tools like
GoodByeDPI succeed with specific settings to the bug tracker listed
below.
.PP
When sharing packet capture logs, please make sure they do not contain
sensitive personal information (e.g., passwords or session cookies).
It is usually enough to capture only the initial handshake packets
showing the issue, rather than full sessions.
.PP
Any other problems not covered above are also appreciated.
Report bugs at <https://github.com/dilluti0n/dpibreak/issues>.
.SH SECURITY AND PRIVACY
The program does not store or transmit your traffic. Fragmentation is
performed locally on the host; no external proxy or relay is used.
.SH EXIT STATUS
Normally, \fBdpibreak\fR runs continuously until interrupted by the
user (e.g. with Ctrl+c) or the system. In such cases it exits with
status 0. Non\-zero exit codes are returned if the program fails to
start (for example, due to insufficient privileges, missing
iptables/WinDivert, or invalid options).
.SH SEE ALSO
.BR nft (8),
.BR iptables (8),
.BR ip6tables (8),
.BR tcpdump (1),
.BR wireshark (1)
.PP
GoodByeDPI <https://github.com/ValdikSS/GoodbyeDPI>
.SH AUTHOR
Written by Dilluti0n <[email protected]>.
|