Hacker News new | ask | show | jobs
How I gained access to TMobile’s national network for free (medium.com)
62 points by cujanovic 3564 days ago
6 comments

Wasn't this posted a few days ago?
Back in the 2000's (age of J2ME featurephones and when 3G networks were only starting to flourish) there was this Spanish carrier that had a separate APN for sending MMS (with a proxy that only allowed access to the actual MMS server, that billed by sent message) and another one for ordinary data (which was, of course, expensive at the time).

After some fiddling, I found out that the filtering proxy was banning access to anything other than http://mms.provider.es*. Note how there was not a trailing slash. You could access any domain like http://mms.provider.eswhatever.freedns.org and it would happily proxy you to the outside internet. As the billing was done on the MMS server and not in the proxy, you could pretty much open any HTTP connection to any proxy that had a domain like that pointed to it.

Some deep browsing (too much free time) led to Filipino forums sharing hacked versions of Opera Mini and other popular apps that let you change the Opera proxy endpoint to other custom domain that then was pointed to Opera's own servers - probably because of similar separate tricks.

Oh, old times...

This strikes me as burying the lede -- if TMobile is traffic shaping based on what looks like the speedtest folder, are they also QoS-prioritizing that traffic to get better speedtest results?
That is a great point, but kind of outside the scope of his article. I think using the /speedtest/ folder as a test across the same resource would provide some clues.

s3/asset.jpg s3/speedtest/asset.jpg

Of course, they might whitelist using speedtest but give priority based on originating domain (which would obviously make a billion times more sense).

Maybe. Louis Rossmann demonstrates a definite difference between speedtest and youtube[1]. The comments suggest it might be "binge-on" throttling, not favoring speedtest per say.

[1] https://youtu.be/2ImKF0fly8s

It is a well known fact that many ISP's cache well known speed test sites.

I truly believe that the speed test sites caught on to this and changed from sending a static file to a randomly named file.

Now they probably just prioritize the speed test sites.

Props for disclosing this. I would have probably went for a life-time of free, unlimited and prioritized mobile internet access.
I remember being able to SSH to any host using a PAYG sim on three that had run out of credit a few years ago.

These sorts of slips seem quite common

Do you want to get into a a great university?

Because making things like his post is how you great university.

This isn't a large technological feat, but the curiosity and writing ability on display would certainly have me ticking the [yes] box were I in admissions. (Though I am not.)