4G PROXY Fingerprint

manureverse

Newbie
Joined
Jul 22, 2019
Messages
30
Reaction score
5
Hello everyone, I have a question to ask.

Probably someone more knowledgeable than me will be able to answer or at least this can be a starting point for reflection.
These days I'm doing several tests on my mobile proxy 4g.
I tried to have my ip address analyzed by sites like browserleaks.com and others much more complex like http://www.f.vision
I began to notice that strange inconsistencies were detected.
Analyzing the IP masked with a proxy, you will notice that both web sites are able to read the real IP address to which you are connected, through WebRTC they are able to bypass the proxy and read the real IP.
The result is that the site detects two different IP addresses, the first given by the proxy and the second IP local which is the real IP address from which we are connected.
In particular, http://www.f.vision proves to be able to find many inconsistencies even if you try to disguise your WebRTC, resulting in Fake webrtc detected.
This site is also capable of detecting if we are using proxies and much more.
In the tests that I performed if I access http://www.f.vision by phone (without proxy) the test is passed perfectly with 0 percent of inconsistency!!
If I do the test with PC and proxy the test results with 75 percent of inconsistency!! Very bad.

Now I wonder, if this site is able to detect all this, do we really think that Instagram is not able to detect this inconsistency?
Have any of you tried to run these tests?
Can it be for this reason that using proxies profiles cannot perform all the daily actions that could be performed from inside the app manually?
 
Doesn't for me... - however, remember this is only showing you what would be seen if you were using the embedded browser.

Looks exactly the same as when i use my phone

(I've hidden details for privacy just in case)

You'd need to set up a MITM proxy to check what instagram is receiving natively.
 

Attachments

  • vision.jpg
    vision.jpg
    57.1 KB · Views: 208
  • Screen-Shot-2019-08-06-at-1.10.51-pm.jpg
    Screen-Shot-2019-08-06-at-1.10.51-pm.jpg
    159.7 KB · Views: 192
Doesn't for me... - however, remember this is only showing you what would be seen if you were using the embedded browser.

Looks exactly the same as when i use my phone

(I've hidden details for privacy just in case)

You'd need to set up a MITM proxy to check what instagram is receiving natively.
You need to change your API mate, that phone uses Android 8.0, not 8.1
 
Not if your software prevents this. Check with your developer.
 
Not if your software prevents this. Check with your developer.

@Frenzied which fingerprint is really able to detect instagram via API using Jarvee?
I did tests on Jarvee, with Embed browser, and Jarvee is true it hides almost everything, but some sites have been able to detect that I was using proxies.

@XX___XX Inside Jarve yes, Jarvee hide a lot of info, but try to chek with ip-check.info
yesterday it was able in the advanced search to detect that I was using proxies even from inside jarvee
 
@Frenzied which fingerprint is really able to detect instagram via API using Jarvee?
I did tests on Jarvee, with Embed browser, and Jarvee is true it hides almost everything, but some sites have been able to detect that I was using proxies.

@XX___XX Inside Jarve yes, Jarvee hide a lot of info, but try to chek with ip-check.info
yesterday it was able in the advanced search to detect that I was using proxies even from inside jarvee
you mean better using jarvee than MP ?
 
you mean better using jarvee than MP ?
I've never used MP, but you can test it. You will have to go in it's embed browser and use some website like ip-check.info or browserleaks
 
how i know. if the proxy safe for using or no?

good question, in my tests it almost never turned out that I was using a proxy, so I would say that consistency is certainly a very important aspect. I noticed that for example jarvee hides a lot of information to protect the identity of the user, it is certainly a positive thing, but at the same time instagram will detect that there is a difference from an average normal user, the average user does not use proxies, it does not hide its data, it hides nothing.
 
@Frenzied which fingerprint is really able to detect instagram via API using Jarvee?
I did tests on Jarvee, with Embed browser, and Jarvee is true it hides almost everything, but some sites have been able to detect that I was using proxies.

@XX___XX Inside Jarve yes, Jarvee hide a lot of info, but try to chek with ip-check.info
yesterday it was able in the advanced search to detect that I was using proxies even from inside jarvee
Hey dude, tried ip-check.info - mine still looks exactly like mobile phone.

You might want to check how you configured your proxy
 
This issue that you have arises when you are using transparent proxies.

Where do you get your 4g proxies?
 
You're having this issue because you're only masking the IPv4 address with your proxy most likely. Javascript however can request the IPv6 address of a device to be sent to the domain's server. When IG compares the geolocation of the two addresses and sees there's a difference, it can safely assume that you're using a proxy. You can either disable your IPv6 protocol (check to see if it's safe for your OS/ISP first) or proxify your entire system to run through the proxy. Either should do the trick.
 
Hey dude, tried ip-check.info - mine still looks exactly like mobile phone.

You might want to check how you configured your proxy

In f.vision you have to do advanced test.

You can check also in whatleaks.com this site, when used within Jarvee, detects a difference between operating systems. Jarvee's fake user agent says you are using Android, but from the system it transpires that you are using windows, and everything is detected.

You can try also on privacy.net it has advanced method of fingerprinting analisys and canvas fingerprinting.
Also ipx.ac have really nice tests.
The problem starts with more in-depth analysis, as in many sites the persistent problem is that an operating system inconsistency is detected. (analyzed with whatleaks.com) An android for user agent and a Windows for requests. Using proxies. Analyzing my phone without proxy and without Jarvee (normal condition of the average user on instagram) a perfect congruence is detected, android- android. Inside Jarvee if I use hotspots a difference is detected in the passive os fingerprint, because with hotspots it is windows / linux, with proxy 4g inside Jarvee the passive os fingerprint is consistent linux / linux (as if I used the phone rightly without proxy).

@Jibri Wright The only real inconsistency that is always detected is the inconsistency between operating systems, in Jarvee Windows / linux is detected instead of Linux / linux as by phone. Geolocation is always ok.
 
In f.vision you have to do advanced test.

You can check also in whatleaks.com this site, when used within Jarvee, detects a difference between operating systems. Jarvee's fake user agent says you are using Android, but from the system it transpires that you are using windows, and everything is detected.

You can try also on privacy.net it has advanced method of fingerprinting analisys and canvas fingerprinting.
Also ipx.ac have really nice tests.
The problem starts with more in-depth analysis, as in many sites the persistent problem is that an operating system inconsistency is detected. (analyzed with whatleaks.com) An android for user agent and a Windows for requests. Using proxies. Analyzing my phone without proxy and without Jarvee (normal condition of the average user on instagram) a perfect congruence is detected, android- android. Inside Jarvee if I use hotspots a difference is detected in the passive os fingerprint, because with hotspots it is windows / linux, with proxy 4g inside Jarvee the passive os fingerprint is consistent linux / linux (as if I used the phone rightly without proxy).

@Jibri Wright The only real inconsistency that is always detected is the inconsistency between operating systems, in Jarvee Windows / linux is detected instead of Linux / linux as by phone. Geolocation is always ok.
Look up Passive OS Fingerprinting and how the TTL varies between devices. This can be used to cold-read an operating system in a sense. A lot of the signals that are given off however can be changed in Windows' Registry Editor if you know exactly what you're looking for.
 
Look up Passive OS Fingerprinting and how the TTL varies between devices. This can be used to cold-read an operating system in a sense. A lot of the signals that are given off however can be changed in Windows' Registry Editor if you know exactly what you're looking for.

Using my 4g proxies inside Jarvee I did a lot of tests and the result is always consistent as passive os fingerprint.
The result is Linux / Linux.
The same result as if I were using the smartphone without proxy without jarvee.
So fortunately there is no problem with the passive os fingerprint.
Instead I noticed that there is a difference between the detected operating system running the web page and the fake user agent that jarvee assigns, in this case Windows / Android
 
Using my 4g proxies inside Jarvee I did a lot of tests and the result is always consistent as passive os fingerprint.
The result is Linux / Linux.
The same result as if I were using the smartphone without proxy without jarvee.
So fortunately there is no problem with the passive os fingerprint.
Instead I noticed that there is a difference between the detected operating system running the web page and the fake user agent that jarvee assigns, in this case Windows / Android
lol this is because of Passive OS Fingerprinting through the browser. You also have to look at screen resolution which may be giving you away to an extent.
 
Back
Top