• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Identify Encrypted BitTorrent packets using Wireshark

Sayth

Gawd
Joined
Oct 7, 2001
Messages
618
Can someone tell me what I'm looking for to identify that my BitTorrent traffic is indeed encrypted? I don't even know if this is easily identifiable but it's worth a shot.
 
do you just want to know that its happening or exactly what it is. If you just want to know its being used then you can look at it based on the port number. If you dont know that its probably the port handling the most traffic
 
most torrent clients will pick random ports within a set range. The easiest way would be to see which IPs (seeds) you are connected to, and setup a filter based on those.

The problem is, if you dont know what unencrypted BT torrents look like, it'll be really tough to compare. Plus the nature of BT as a medium to gather data presents a problem in that you are connected to several seeds and the data is combined at the client. An encrypted packet will have black squares blocking out the data.
 
Last edited:
Well this is a copy of a few bytes at the end of one of the packets identified as a bittorrent packet coming to me.

You're right and I understand that identifying encrypted data over plain text when you're downloading anything non-text based can be difficult. I'm thinking maybe I should re-run my test while downloading a doc or txt file...?

Code:
3d50   03 59 7b 70 ef ec ca 90 6f 2f 6e 1d d5 97 52 0d  .Y{p....o/n...R.
3d60   e9 ed c3 bd 33 2a 41 bd 61 b8 28 c0 51 b9 fc 4b  ....3*A.a.(.Q..K
3d70   c1 28 e5 f6 80 8c 10 33 18 b8 58 7a 9a 98 21 c6  .(.....3..Xz..!.
3d80   ef e8 39 ba b5 a2 a8 21 32 cc 28 93 26 2a 9c 76  ..9....!2.(.&*.v
3d90   ba c5 a2 dd 77 e5 0e 53 d4 c1 e0 58 69 77 32 75  ....w..S...Xiw2u
3da0   71 03 3e af 23 2f af c5 8a c1 39 f2 e6 a5 0c c1  q.>.#/....9.....
3db0   2a 52 e9 48 5f c8 6e b3 b5 2e 88 40 ee ad 59 65  *R.H_.n....@..Ye
3dc0   69 74 09 3b 5e ef 66 f5 7a a7 73 39 a3 c7 34 5a  it.;^.f.z.s9..4Z
3dd0   cd 73 85 70 d2 87 10 65 7c c3 a9 e1 b9 09 d2 60  .s.p...e|......`
3de0   98 4a 93 48 9d 8b 93 b9 12 d4 4e 53 8c a3 98 f1  .J.H......NS....
3df0   8a 0f d0 24 0d e3 81 28 e4 f5 cb 56 7c a8 71 8d  ...$...(...V|.q.
3e00   87 07 4b 0d d9 5d 41 6e 60 64 5b 62 88 cd 2b 0a  ..K..]An`d[b..+.
3e10   a9 70 46 cb e4 e8 14 f9 73 57 1d 67 ea 8d 20 83  .pF.....sW.g.. .
3e20   43 19 d5 94 55 26 1c 8d f9 1d 4c b6 e7 b8 30 d5  C...U&....L...0.
3e30   f9 b4 97 75 78 1e 48 f8 a4 7f ab 6b 30 2f 7b 42  ...ux.H....k0/{B
3e40   dc 58 71 7b ba 40 ab d6 31 63 0b 9d 61 16 46 d0  .Xq{.@..1c..a.F.
3e50   f1 9b 75 4c 69 1a 78 28 83 30 21 56 1a 44 c6 87  ..uLi.x(.0!V.D..
3e60   07 28 c2 82 4c 88 e8 c2 41 57 e2 14 19 9c 58 92  .(..L...AW....X.
3e70   18 d0 19 6a 4c a6 40 00 05 c0 42 59 0a 07 dc 68  ...jL.@...BY...h
3e80   fc d0 a1 ea f4 ce 34 8d 53 ca d7 d2 69 26 ba 28  ......4.S...i&.(
3e90   35 e6 1a cb 1d ba d2 35 05 56 08 6a bc 89 67 3f  5......5.V.j..g?
3ea0   31 f4 4d 6a 90 eb a9 1b a0 6b d4 d3 8e 9b 8b 66  1.Mj.....k.....f
3eb0   71 c2 87 a4 15 63 b0 4e d5 4e db 50 d4 9b b3 f9  q....c.N.N.P....
3ec0   5e aa 2e 2c 24 79 61 6c 51 17 e2 54 5b d5 03 a9  ^..,$yalQ..T[...
3ed0   28 27 8c ca c3 08 60 36 a4 4f 53 91 22 6f 24 53  ('....`6.OS."o$S
3ee0   85 f4 e4 4e 8e 62 b3 20 34 80 48 4f 8c 84 63 4c  ...N.b. 4.HO..cL
3ef0   ce e5 96 32 10 f5 f4 05 44 5c d3 71 2f 6a 40 72  ...2....D\.q/j@r
3f00   cd 5c 53 b0 e1 2d 36 a9 e2 56 55 59 d8 df 0a d1  .\S..-6..VUY....
3f10   71 ad be 81 1a 34 e7 7c 08 2e af 7c c1 61 87 3e  q....4.|...|.a.>
3f20   20 4f 13 32 69 b1 de e9 7a fd d6 b0 27 bd a1 5a   O.2i...z...'..Z
3f30   2c b1 69 3e a0 41 bc c1 a5 a1 aa 56 81 93 25 42  ,.i>.A.....V..%B
3f40   b5 a3 65 d4 50 65 a4 40 d1 04 e2 52 66 14 14 9c  ..e.Pe.@...Rf...
3f50   ef c2 38 98 0a bb 30 8a 2a 73 0a 8d 07 63 a8 43  ..8...0.*s...c.C
3f60   96 de 89 69 b4 bb d6 a0 22 23 69 09 73 c9 00 ad  ...i...."#i.s...
3f70   57 d2 48 ee 89 04 97 c1 10 b1 18 7b b1 c7 e9 ba  W.H........{....
3f80   b3 7b af 7a c0 3c ae 94 75 fa 67 b0 d3 64 9b 64  .{.z.<..u.g..d.d
3f90   8f 6b fd 03 32 d5 fb 8c 62 81 b6 86 22 90 1c 7d  .k..2...b..."..}
3fa0   ac 5b 6e 7f 87 8c 0c 88 24 03 79 aa 4f 55 6b 94  .[n.....$.y.OUk.
3fb0   2c f6 2e 6a a4 63 39 97 d3 66 50 91 a1 ee 09 6a  ,..j.c9..fP....j
3fc0   86 42 56 21 3e 54 0b 86 24 27 a1 cc 57 b3 3b 00  .BV!>T..$'..W.;.
3fd0   06 15 a1 0e 23 db 50 87 aa 75 1c 3a cb 15 57 5a  ....#.P..u.:..WZ
3fe0   b5 51 9f 6a e7 34 a5 5d d2 56 c8 6d 8a 56 65 7b  .Q.j.4.].V.m.Ve{
3ff0   29 bc 89 7a 8f 42 28 a1 d5 1d 32 c7 b2 b9 99 9a  )..z.B(...2.....
4000   f1 5f f5 dc 08 d4 be 18 b3 1a 04 68 ed           ._.........h.
 
Why not run a single torrent unencrypted, say an Linux ISO, and then enable an encrypted torrent? That way you have a baseline to work from.
 
Funny you say that.

Right now I am trying to run small txt files first encrypted then not encrypted hoping that maybe I can search a word form the file within the packets but will also compare to try to see a difference in the packet bytes as well.

I'll keep you posted in case anyone is interested...
 
So I downloaded a very small .txt text file.

Using uTorrent with Encryption off, Wireshark was able to decode the BitTorrent traffic no problem. Also, a simple string search for any part of the text file showed many packets with the data in plain-text. Also only 30% of the traffic was UDP.

With encryption on, Wireshark did not decode any traffic as BitTorrent. 60% was UDP. There really was very little to indicate any BitTorrent traffic. A string search for the text file contents produced nothing, as expected.

Pretty simple to deduct that the traffic was indeed encrypted and I could not tell at all whether or not there was any BitTorrent traffic in the encrypted capture.

Really was interesting though because how do you look for something that you expect not to find?

Thanks for the advice though.

As a side note, my buddy's home-brew BitTorrent program forgeTorrentSpectrum (Retarded name I know) showed evidence of TLSV1 packets saying "Server Hello, Change Cipher Spec, Encrypted Handshake Message"

So if I tested more mainstream BitTorrent clients I wonder if I would have found that same "cipher" info. Who knows? I'm done!
 
Good to know. It is practical little exercises like this that help broaden one's knowledge.
 
Good to know, and I like the outcome. I wonder if outbound traffic would work the same way, for seeding files.

However it seems a little moot. If you're downloading and or seeding anything, then you should have to 'hide' it from anyone. And if you do need to hide it, then you probably shouldnt be dl/ ul it to begin with.
 
I do agree J-Will, but don't forget about the traffic shaping that goes on with some ISPs. Depending on the ISP, you may be able to get your full internet speed out of BitTorrent downloads of legitimate Linux ISOs by encrypting traffic.

Now it's thought for us Cannucks that Rogers Internet still throttles encrypted traffic as well, but the speed definitely increases with encryption forced.

Not everything is done for an illegitimate reason bud don't worry ;)
 
Back
Top