What's new

Closed Full and complete guide for making your own ehi configs

Status
Not open for further replies.

ConquerorXXX

Forum Guru
Joined
Apr 19, 2017
Posts
5,954
Reaction
4,682
Points
1,881
Para sa Palaging Nagtatanung kung paano gumawa ng Configs
kahit na marami na ang nag post nito dito. Sila ay walang sawa parin sa pagtatanung:

Para ma refresh naman tayo.


Full and Complete Tutorials

How To Make Your Own HTTP Injector Configs




About HTTP Injector

HTTP Injector is an Android App developed by Evozi. It is currently only available on the Android platform. It is compatible with android versions 4.0 to 7.0. HTTP Injector is used to connect to SSH, and proxy servers, using custom HTTP headers. Http Injector is primarily designed to circumvent censorship, and provide secure, private browsing. The unique feature that sets HTTP Injector apart from other Tunneling Apps is it’s ability to set custom HTTP headers on HTTP requests that are being transmitted though a network. Another major difference is that HTTP Injector tunnels over SSH and not VPN.

Uses For HTTP Injector

1. HTTP Injector can be used to circumvent censorship, in countries where the internet is censored by the government, or ISPs. This is achieved by tunneling a user’s internet connection through a SSH tunnel. When this happens a users ISP is not aware of what site’s the user is browsing, or what files the user is downloading.

2. HTTP Injector is also used for secure, and private browsing. The traffic between your device and the SSH server is encrypted, so you can browse over an encrypted connection as you could with a VPN.

3. In countries where the cost of internet is extremely high users use the App to exit their ISPs LAN and gain access to the internet, this is achieved usually by faking the HTTP header host address to a host address that would be normally free to access on that particular network.

This tutorial will be mainly focused on point 3, but the same principes may be applied for other uses.

What are free hosts, and how to find free hosts?

Most ISP’s allow users to browse certain websites for free, like captive portal pages, the ISP’s home page etc… These are what we call free hosts.

If you have been on a certain network for a long time, by now you should already know what sites are free to browse. You could try your networks homepage, or other sites that you think might be free to browse. When in doubt you can always call up your networks customer support and kindly ask them what sites are free to browse.

You could use packet capture Apps for Android like tPacketCapure, or similar Apps, to capture network packets. tPacketCapture records all network activity (captures packets) and saves the data into PCAP files. PCAP Reader for Android, can be used to read the output generated by tPacketCapture. I have personally used tPacketCapture, and have found free hosts unknown to most people. Example if one of your ISPs free sites is freesite.com. You simply start tPacketCapture, you go into your browser and enter freesite.com, you browse maybe two pages on freesite.com, then you stop tPacketCapture. You then use PCAP reader to read the output, first you find out exactly how your device communicates with freesite.com (IP addresses, Ports in use, Protocols in use), second you will find out what the dependencies of freesite.com are. Dependencies of freesite.com might be for example imageserver.com. Great! You just discovered a new free site imageserver.com. You see most websites have dependencies, in other words they draw certain resources from other websites. By using packet capture software, you can find out, which other sites they are reliant on and in turn, discover more free hosts. Trust me I have captured and analyzing thousands upon thousands of packets I have found free hosts unknown to most.

What are HTTP headers?

HTTP stands for “Hypertext Transfer Protocol”. The entire World Wide Web uses this protocol. It was established in the early 1990’s. Almost everything you see in your browser is transmitted to your computer over HTTP. For example, when you visit You do not have permission to view the full content of this post. Log in or register now. on your browser, your browser would have sent an HTTP Requests very similar to the one below. I have boxed the HTTP Request in the blue box. The yellow highlighted lines are HTTP Headers, each line is a different HTTP Header.

own%20hi%20packet%201-180x300.jpg


Esishop’s web server would then respond with an HTTP Response, very similar to the one below. Again, I have boxed the HTTP Response in blue. The yellow highlighted lines are HTTP Headers, each line is a different HTTP Header.

own%20hi%20packet%202-180x300.jpg


HTTP headers are the core part of these HTTP requests and responses, and they carry information about the client browser, the requested page, the server and more.

Now that we have a clear picture for everything. Let’s make our first HTTP Injector config. Before we can proceed first we need to get ourselves an SSH Account, and a proxy server. Let’s do that now.

Creating An SSH Account

1. An SSH account is an absolute must for creating your own HTTP Injector configs. We begin by searching the term “free ssh”, we can see from the search results that there are thousands upon thousands of “free ssh” providers to choose from. Now, I am not going to recommend any free SSH providers, as each scenario is different. Some SSH servers work on some networks, some SSH servers don’t. It is up to you to find an SSH server that works on your particular network/case.

own%20hi%201-180x300.jpg


2. Oh, look the first result that came up is FastSSH. FastSSH is a pretty popular SSH account provider that I sometimes use. Let’s create an account on there now. By visiting FastSSH you can see there are many regions, and countries to choose from. Performance wise it is best choosing a country that is closest to you. Again I won’t recommend a particular SSH Server, try out for yourself and use whatever works best for you, in you particular scenario. Ok, so after you have created yourself an SSH account, you should get your account details as seen bellow. Grab a pen, and paper and write down your account details, or copy/paste them somewhere for future reference. Here I have created a random SSH account on FastSSH’s CA-2 server.

own%20hi%202-180x300.jpg


4. Great! So now we have an SSH account for ourselves. Next, we need to find a proxy server.

Finding A Proxy Server

Most free SSH account providers also have proxy servers, try looking around their site for pages named “squid”, or “proxy”. Like with FastSSH they have a tab on their website called “Squid”, there you can find a list of free proxy servers that you can use alongside their SSH servers.

own%20hi%20proxy%201-180x300.jpg


2. Let’s click open the tab and see what they have to offer. As seen bellow, they have numerous proxy servers to use alongside their SSH servers. In our case since we opened an SSH account on FastSSH’s CA-2 SSH Server, we have to use the proxy servers I highlighted in yellow.

own%20hi%20proxy%202-180x300.jpg


3. If you free SSH account provider does not have any proxy servers, simply search the term “free proxy list”. As seen bellow there are thousand of sites offering free proxy servers. I sometimes use HideMyAss to get my proxy servers.



4. Bellow is a screenshot from HideMyAss. So which to use? FastSSH’s proxy servers, or proxy servers from HideMyAss? Again I won’t recommend any particular proxy server, as each case is different. Always use whatever works best for you, and for your particular network. For todays demo I have decided to use the proxy server 118.151.209.114, port 80, India. I have decided to use this particular HideMyAss proxy server since it seems fast according to HideMyAss.

own%20hi%203-180x300.jpg


5. Great! Now we have everything we need to start making our own HTTP Injector configs.

Clearing Settings/Data

1. We want to begin from scratch, so first let’s clear out our recent settings/data. We proceed by pressing the three point menu button on the upper right hand corner of the screen.

own%20hi%204-180x300.jpg


2. On the menu that appears we press “Clear Settings/Data”.

own%20hi%205-180x300.jpg


3. A confirmation dialogue appears prompting us if we are sure we want to reset all our data. Yes, we are sure, so we proceed by pressing “YES”.

own%20hi%206-180x300.jpg


4. Great all our recent settings/data should now be cleared, and we should be as clean as slate.

Creating Our First HTTP Injector Config

1. Ok, by now we should have created our own SSH account, we should have found a proxy server, and we should have cleared our recent HTTP Injector settings/data. Now time to create our first HTTP Injector config. Are you tired? Yes, me too…. But heck let’s keep proceeding like no bodies business. So, let’s proceed by pressing gear icon, as seen below.

own%20hi%207-180x300.jpg


2. This brings us to HTTP Injector’s settings page. From here we proceed by pressing “Secure Shell (SSH)”.

own%20hi%208-180x300.jpg


3. This bring us to the SSH settings page, where we fill in our SSH Host, our SSH Host Port, our SSH account username, and our SSH account password. The SSH Host port is usually port 22, check with your free SSH account provider for the correct port numbers. After we have filled in all our SSH account particulars, we proceed by pressing the back button, as seen below.

own%20hi%2017-180x300.jpg


4. Now back on our home screen let’s insert our proxy server’s address, and port. We do so by pressing the pencil icon on the bottom right hand corner of the screen.

own%20hi%2019-180x300.jpg


5. With our proxy server’s IP address, and port number filled in we press “SAVE” to proceed.

own%20hi%2020-180x300.jpg


6. Now that our proxy server details are filled in, we now need to format our HTTP Request (payload). We proceed by pressing the three line menu on the top left hand corner.

own%20hi%2021-180x300.jpg


7. On the menu that appears we press “Payload Generator”.

own%20hi%2022-180x300.jpg


8. This brings us to the payload generator. I normally generate my payloads as seen bellow, but use whatever works best for you, and your particular network. In the “URL/Host” field you have to put the URL of whatever the free host is on your particular network (Example: 0.freebasics.com, wikipedia.org, internet.org, m.facebook.com etc… ). I wrote more about finding free hosts in the beginning of this article. After that is sorted out, we proceed by pressing “Generate Payload”.

own%20hi%2023-180x300.jpg


List of Free Host For Payload:
s31-01-01.opera-mini.net
mobilis.dz
e7.whatapp.net
feedup.turkcell.com.tr
correo.tigo.com.co
mmc.xl.net.com
tigomusic.com
naver.jp
mms.gprs.safaricom.com
line.never.jp
indosat.com
You do not have permission to view the full content of this post. Log in or register now.
You do not have permission to view the full content of this post. Log in or register now.
web123.xl.co.id
fastssh.com
vodafone.eg
opx.opera.com
line.never.me
three.co.id
221.132.192.27.com
blackberry.net
b-whatsapp.com
inwi.com
tools.ip2location.com
gratis.claro-bemobi.com
mmc.xl.net.id
axis.com
uk1.servjet.co
gstaticadssl.l.google.com
naver.com
You do not have permission to view the full content of this post. Log in or register now.
server4.operamini.com
vodafon.com
d.line-scdn.net
libre.ph
line.co.id
tn.tn.vuclip.com
fb.com
starzplay.com
indosatooredoo.com
tkckish.com
m.me
sg3.com
You do not have permission to view the full content of this post. Log in or register now.
axisnet.muslimku.com
dtac.com
kakao.com
www8.subdomain.com
sg.tcpvpn.com
pangalan.com
0.freebasics.com
app.axisworld.co.id
point.excite.id
bin.nokia.whatsap.net
axisnet.bikep.com
dtac.co.th
claro.con.do
comcel.com
twitter.net
djaweb.dz
ito.gov.ir
ipophil.gov.ph
claro.com
YøùTùbé.co.id
You do not have permission to view the full content of this post. Log in or register now.
gc3.jualssh.com
You do not have permission to view the full content of this post. Log in or register now.
You do not have permission to view the full content of this post. Log in or register now.
unlimited.smartfren.co
wap.movistar.com.ni
ideasclaro.com.do
You do not have permission to view the full content of this post. Log in or register now.
axisworld.co
watsapp.com
whatsaap.com
redirection.gpeasynet.com
blackberrymessenger.com
indomaret.co.id
You do not have permission to view the full content of this post. Log in or register now.
unlimited.com
axishitz.unlimited.co
You do not have permission to view the full content of this post. Log in or register now.
turkcell.com
vodafone.com.eg
mytelkomsel.com
xl.com
path.com
axis.me
hotlink.fb.me
You do not have permission to view the full content of this post. Log in or register now.
xldrupal.xituz.com
You do not have permission to view the full content of this post. Log in or register now.
You do not have permission to view the full content of this post. Log in or register now.
bbm.me
uno.ma
t.me
mobilezone.iam.ma
You do not have permission to view the full content of this post. Log in or register now.
You do not have permission to view the full content of this post. Log in or register now.
You do not have permission to view the full content of this post. Log in or register now.
truemove-h.com
m.opera.com.zzz66.vba.nz
bbm.com
You do not have permission to view the full content of this post. Log in or register now.
m.feelsafedigital.com
sd.zain.com
You do not have permission to view the full content of this post. Log in or register now.
wap.xl.co.id.ipq.co
You do not have permission to view the full content of this post. Log in or register now.
animeflv.net
tsel.co.id
vivo.com
langitmusik.com
tn.tn
airtel.com
internet.tn
4gclaro.com
You do not have permission to view the full content of this post. Log in or register now.
internet.org
moov.com
elevenia.co.id
go.talkntext.ph
fb.co
phcorner.net
livechat.com
You do not have permission to view the full content of this post. Log in or register now.
tsel.me
djezzy.com
static.smartnet.ph
speed.com
You do not have permission to view the full content of this post. Log in or register now.
sg2.ipspeed.co
You do not have permission to view the full content of this post. Log in or register now.
You do not have permission to view the full content of this post. Log in or register now.
lycamobile.tn
powerfulbet.com
king.iwilldoforking.com
fate.netgame.com
http.You do not have permission to view the full content of this post. Log in or register now.
u.com.my
sg-month.vpntcp.com
imanila.ph
axis.kzl.sosmed.net
sgdo3.setan.cf
jollyworkshosting.com
german-proxy.de
xlaxiata.com
api.line.com
sudani.sd
mtn.ci
axisworld.net
vivo.ddivulga.com
tokobagus.com
orange.ci
vivo.com.ar
xplore.co.id
talkntext.facebook.cn
opx.opera.com.
web.com.ph
dot.ph
shopee.co.id
rewardzonemobile.com
whatsapps.net
app.axisworld.com
shopee.net
sggs11-group.mytunneling.com
djezzy.dz
You do not have permission to view the full content of this post. Log in or register now.
facebook.ooredoo.dz
pippo.it
andifekra.tn
m.im3ooredoo.com
gianpermana.zpn.im
comcel.ec
123.indosatoredo.com
cnt.net
mobilis.com
blackberry.com.dnsdb.com
babblebug.com
sg-top1.bestvpnssh.com
pun.smkn5bjm.sch.id
You do not have permission to view the full content of this post. Log in or register now.
crew.info
developer.facebook.de
unli.smart4g.com
gamex.ph
tntph.com
axis.kzl.net
You do not have permission to view the full content of this post. Log in or register now.
You do not have permission to view the full content of this post. Log in or register now.
se.smart.com
etisalat.com
psiphonhealthyliving.com
You do not have permission to view the full content of this post. Log in or register now.
api2.smartner.ph
telcel.com
truemove.com
You do not have permission to view the full content of this post. Log in or register now.
123.indosatooredo.com
weixin.qq.com
xsgdo1.mxtn.me
stc.com
You do not have permission to view the full content of this post. Log in or register now.
hooq.com
ns3010330.ip-5-135-184.ph
facebook.co.id
ns3010330.ip-5-135-184.eu
sgp01.globalssh.xyz
xhhbz52553.lithium.com
xl.co.net
m.ekhanei.com
w1716.smartadserver.com
wikipedia.org
proxy2017.com
appsclub.grameenphone.com
teletalk.com.bd
whatsapps.com
etisalat.eg
upfile.mobi
ltnsd.spaces.live.com
icflix.com
asia.com
You do not have permission to view the full content of this post. Log in or register now.
mobil.net
ifood.delivery
telkomsel.co.id
mms.digicelgroup.com
bug.com
You do not have permission to view the full content of this post. Log in or register now.
axis.kzl.com
beeg.com
iklanstore.co.id
wana.ma
inwi.ma
ρá†ch.com
patc.com
wechat.com

Other payloads including freebasics, facebook, opera, internet.org, YøùTùbé and google.

0.0.freebasic.com
0.0.freebasics.com
0.facebook.com
0.frebasics.com
0.freebasic.com
0.freebasics.com
0.internet.org
0.operamini.freebasics.com
ads.freebasics.com
airtel.internet.org
b-api.facebook.com
b-graph.facebook.com
b-m.facebook.com
b-www.facebook.com
capk.internet.org
cellc.internet.org
edge-z-m-mini-shv-01-lax3.facebook.com
elite-operamini.internet.org
expresswifi.com
fr-m-wikipedia-org.0.freebasics.com
free.facebook.com
free.internet.org
freeb6.com
freebasic.com
freebasics.com
freebs.com
glol.internet.org
god.freebasic.com
h.internet.org
http-fr-m-wikihow-com.0.freebasics.com
http-ke-supersport-mobi.0.freebasics.com
http-m-spin-ph.0.freebasics.com
http-m-wattpad-com.0.freebasics.com
http-theabc-xyz.0.freebasics.com
http-www-e-tesda-gov-ph.0.freebasics.com
http-www-gov-ph.0.freebasics.com
https-en-m-wikipedia-org.0.freebasics.com
https-fr-m-wikipedia-org.0.freebasics.com
infi.internet.org
inquirer.net.0.freebasics.com
internet.org
lm.facebook.com
m.internet.org
mazter.internet.org
my.internet.org
nullmx.freebasic.com
nullmx.freebasics.com
o.freebasic.com
o.freebasics.com
o.internet.org
oonvare.internet.org
pappi.internet.org
pappitech.internet.org
server-3128.freebasics.com
server-80.freebasics.com
server-80.internet.org
server-8080.freebasics.com
simulator.c10r.freebasics.com
telstra.iph.internet.org
truemoveh.truecorp.co.th.0.freebasics.com
You do not have permission to view the full content of this post. Log in or register now.
You do not have permission to view the full content of this post. Log in or register now.
You do not have permission to view the full content of this post. Log in or register now.
You do not have permission to view the full content of this post. Log in or register now.
z-m-graph.facebook.com
z-m.c10r.facebook.com
z-m.facebook.com
z-upload.facebook.com
z.facebook.com
zero.facebook.com.internet.org
admin.google.com
android.clients.google.com
apps.google.com
books.google.com.ph
careers.google.com
client2.google.com
client3.google.com
client5.google.com
clients3.google.com
clients4.google.com
clients6.google.com
cloud.google.com
connectivitycheck.android.com
console.cloud.google.com
developer.android.com
developer.google.com
developers.google.com
dl.google.com
docs.google.com
doubleclick.net
drive.google.com
encrypted-tbn3.gstatic.com
g.co
goo.gl
google.co
google.com
ipv4.google.com
m.YøùTùbé.com
m.YøùTùbé.com.ph
maps.google.com
ogs.google.com
pixel.google.com
play.google.com
plus.google.com
redirector.googlevideo.com
s.YøùTùbé.com
safebrowsing-cache.google.com
safebrowsing.clients.google.com
sb-ssl.google.com
schema.org
spreadsheets.google.com
support.google.com
thinkwithgoogle.com
w.google.com
wap.google.com
You do not have permission to view the full content of this post. Log in or register now.
YøùTùbé.com
zero.freebasic.com
9. Great! We now have a fully functional HTTP Injector config. Well sort of Now we just have to test and debug our new creation.

Testing & Debugging

1. So we have our SSH Servers settings configured, Proxy server settings configured, and our HTTP request (payload) all set. Now time to debug and test our config. We proceed by pressing “TOOLS”.

own%20hi%20extra%20step%201-180x300.jpg


2. In the “TOOLS” page we proceed, by enabling “Debug Mode”. After Debug Mode has been enabled, we press “HOME”, to return back to our home screen.



3. Back at our Home screen we press “START”.



4. As usual we check the “I trust this application” check box, and we press “OK” to proceed.


5. Now let’s check out our logs. The logs can be accessed by pressing the “LOG” button, as seem bellow.



6. Because we have enabled “Debug Mode” in step 2, life becomes a whole lot easier for us when we are debugging our configs. As seen in the screenshot bellow we are getting a “302” error. What this basically means is that either our HTTP Request (payload), or proxy/ssh server combination is not suitable, or blocked. Most of the time it simply means our proxy/ssh server is blocked.

own%20hi%20extra%20step%207-180x300.jpg


The 302 error is the most common error you will encounter. If you encounter the 302 error I suggest you leave your payload as it is, but keep trying different proxy/ssh server combinations in different IP address ranges. Example if your proxy, and ssh server are in the IP address range of 65.**.**.**, next time try in the 26.**.**.** range. It would also be helpful if you note down IP address ranges that you have already tried, in order to save yourself the double work. In all keep trying different IP address ranges until you are successful.

Remember, nothing is impossible. Never give up.
Good Luck!
 
Last edited:
Ayan, nilapag na yung isang way para makahanap ng freesite.. sana marami makapagtest at makapagshare. Tulungan in short..
Thumbs up..
 
Status
Not open for further replies.

Similar threads

Back
Top