100.64.0.0/10 = 100.64.0.0 - 100.127.255.255
Thanks to Lawrence Systems who covered his own network setup!
100.64.0.0/10 = 100.64.0.0 - 100.127.255.255
Thanks to Lawrence Systems who covered his own network setup!
[SimpleShell]
~
$ curl -sL 'https://github.com/stoops/SimpleShell/commits/main/' | tr '=:,<>[]{}"\' '\n' | grep -Ei '/commit/' | head -n 1 | awk -F'/' '{ print $NF }'
$ spctl -a -v bin/SimpleShell.app
bin/SimpleShell.app: accepted
source=Notarized Developer ID
I was searching for a good quality but simple free open terminal for MacOS and I couldn’t really find what I was looking for interface wise (I used to use iTerm for a long time but it started getting more and more bloated and laggy on me – using up a lot of system power on battery and I don’t want all that AI stuff baked in).
I started a project earlier this year but got stuck on it because I was trying to implement a basic ANSI parser which was a mistake on my part. I didn’t realize how incredibly complicated that finite state machine would be, esp with bash and ansi apps sending complicated instructions into the machine! I then asked Google AI for help and it pointed me to a GitHub page that hosted a libvterm (from vim) that was compatible with Objective-C.
I’ve been working on this app non-stop for the last 9 days now and I only have the basics covered, I didn’t realize how much code it took just to make a basic text processing input/output app but I think this is one of my more complicated code bases (possibly TurnTable is the other app of mine that might be more complicated but that one is in Swift).
I still have a lot more work on my todo list for and I will continue development on it now that I got ANSI parsing to work, the rest is just mainly ViewController and functionality features. I targeted it for the bash shell so I don’t know if it works with other shells but this is just my first release post about it.
Layout List
Feature List
Todo List
Limitation List
Warning List
~
Source Code: https://github.com/stoops/SimpleShell
~
Layer 2 – Ethernet Frames – Leet ARP Spoofing
ebtables -t nat -I PREROUTING -i wifi+ -p ARP --arp-opcode Reply --arp-ip-src 192.168.1.1 -s ! 00:12:34:56:78:00 -j DROPebtables -t nat -A PREROUTING -i wifi+ -p ARP --arp-opcode Reply --arp-ip-dst 192.168.1.1 -s ! 00:12:34:56:78:00 -j DROP
~
Layer 3 – Second Favorites – Lazy DHCP Snooping
ebtables -t nat -I PREROUTING -i eth0.1 -p IPv4 --ip-proto udp --ip-sport 67 -j ACCEPTebtables -t nat -A PREROUTING -i wifi+ -p IPv4 --ip-proto udp --ip-sport 67 -j DROP
~
[kmod-nft-bridge]
table bridge ethernet { chain PREROUTING { type filter hook prerouting priority filter; policy accept; iifname "wifi*" arp operation reply arp saddr ether != 00:11:22:33:44:00 arp saddr ip 192.168.1.1 counter drop iifname "wifi*" ip protocol udp udp sport 67 counter drop }}
~
OpenWRT Config
wireless.default_radio0.isolate='1'wireless.default_radio0.bridge_isolate='1'
~
Untested Commands
bridge link set dev wlan0 hairpin off isolated onebtables -A FORWARD -i wlan0 -o wlan0 -j DROP
~
Note: Most of these commands won’t work on UAP-U7-PRO APs I believe due to hardware based frame/packet routing/forwarding – I have since enabled arp-proxy and dhcp-snooping in the UI network controller application, however, I don’t see them working either, possibly because I am running a third-party gateway device. I have finally enabled client-isolation, which as tested, solves the ARP and DHCP attacks completely and forces client-to-client communication through the router instead for even further filtering!
~
I have first since used a couple web based AI systems for different specific tech things and they are pretty useful if you do the extra work to verify and modify what they are telling you. I’ve found that Google Gemini AI is really good a general tech questions and configuration items (with looking it over and understanding it and modifying it of course for your specific needs) and Claude Sonnet AI is really amazing at verifying that your code is correct and other more in-depth programming related tasks (for example, memory allocation and pointer handling and file descriptor tracking).
I’ve been using these systems lightly whenever I get stuck and they are able to find the exact code snippets I was looking for to complete the rest of my projects!
Note: It’s a shame that AI resources are being used on social or political issues rather than solving technology and scientific issues to help progress humanity. I’m still amazed that I was able to feed a 1000 lines of C code to Claude as a test and it was able to determine the components purposes and the network proxy applications of it all…
Google AI seems a little more friendly and personable whereas Claude is more on task and professional ha 🙂
~
I wanted to eventually experiment with using the AES hardware instruction but for the ARM architecture because there are ways to turn block ciphers into stream ciphers for future usage. There appears to be a C header include file that exists on both Mac and Ubuntu (arm_neon.h) and you can compile this small C program file with standard gcc options (no special arguments needed). The hardware instruction method names appear very cryptic, however, they do seem to work when I tested the hex output against other sites!
K: [00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ]R: [00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 62 63 63 63 62 63 63 63 62 63 63 63 62 63 63 63 aa fb fb fb aa fb fb fb aa fb fb fb aa fb fb fb 6f 6c 6c cf 0d 0f 0f ac 6f 6c 6c cf 0d 0f 0f ac 7d 8d 8d 6a d7 76 76 91 7d 8d 8d 6a d7 76 76 91 53 54 ed c1 5e 5b e2 6d 31 37 8e a2 3c 38 81 0e 96 8a 81 c1 41 fc f7 50 3c 71 7a 3a eb 07 0c ab 9e aa 8f 28 c0 f1 6d 45 f1 c6 e3 e7 cd fe 62 e9 2b 31 2b df 6a cd dc 8f 56 bc a6 b5 bd bb aa 1e 64 06 fd 52 a4 f7 90 17 55 31 73 f0 98 cf 11 19 6d bb a9 0b 07 76 75 84 51 ca d3 31 ec 71 79 2f e7 b0 e8 9c 43 47 78 8b 16 76 0b 7b 8e b9 1a 62 74 ed 0b a1 73 9b 7e 25 22 51 ad 14 ce 20 d4 3b 10 f8 0a 17 53 bf 72 9c 45 c9 79 e7 cb 70 63 85 ]I: [00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ]O: [dc 95 c0 78 a2 40 89 89 ad 48 a2 14 92 84 20 87 ]I: [dc 95 c0 78 a2 40 89 89 ad 48 a2 14 92 84 20 87 ]O: [00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ]
~
Source Code: github.com/stoops/aes/blob/main/aes.c
~
Thanks to Google’s AI code snippets, I was able to finally implement multiple threads all reading from a singular tun interface as well as each thread performing larger batch reads/writes in one singular syscall (up to 65536 bytes per call)! Here are the parameters (IFF_MULTI_QUEUE | IFF_VNET_HDR) and calls you need to set to get it:
~
Source Code: github.com/stoops/vpn/blob/main/gtun.c
EC ElGamalpoint=f(x, y)G - point (public)k - integer (private)Q=kG - point (public)r - integer [random integer] (private)s - integer [secret integer] (private)M=sG - point [secret point] (private)C=rG - point [reference point] (public)E=rQ+M - point [encrypted point] (public)(C, E) - message [(rG, rkG+M)] (public)D=k*C - point [decryption point] (private)M=E−D - point [((rkG+M)-krG)] (private)note: must generate a unique r/M value/coordinate each time for a given keynote: encryption only works in one direction from public key to private key
~
EC DH- each side generates a secret integer (r) and multiplies with point G (rG)- each side sends their point multiplication result (rG) to the other- each side multiplies their secret integer (r) with the exchanged point r(xG)- each side can encrypt their results before sending with EC ElGamal
~
You can see point S has the same X, Y coordinates in the client as in the server and only points C and E were published!
~
Source Code: github.com/stoops/vpn/blob/main/lib/key.c
Key Generator: github.com/stoops/eckx/blob/main/ecdh.c
~
So a little while back I upgraded all my lan components to 2.5gbps and I recently upgraded my wan to 1.5gbps and I wanted to tune up both the VPN solution I had previously made as well as the long since passed Proxy solution. The proxy solution, which is essentially a “Monkey-in-the-Middle” proxy on behalf of all network clients (no TUN interface read/writes are required) but the down side is managing thousands of client based UDP/TCP socket connections and firewall states and file descriptors and memory allocs. On a side note though, as a long time select caller, I finally learnt how to use poll as a better replacement.
With the VPN solution, I like and prefer the clean routing setup, however, I was only able to achieve ~900mbps whereas with the Proxy solution, it’s all pure sockets only where I am able to get ~1300mbps!
I wanted to retest what the performance would be of the MITM Proxy network solution over WiFi 6GHz@2400mbps and I was able to hit pretty fast VPN-style speeds over the network! I will have to retest to see how the VPN solution performs, however, I am trying to explore how multiple bulk IP packets can be read/written to/from the TUN interface in one singular syscall or being able to process larger size packet data before they get broken up by the interface MTU in the Linux Kernel… IFF_VNET_HDR / IFF_MULTI_QUEUE
Over 1.21 Jiggawatts! I mean Gigabits!!
~
~
Warning: Long Screenshot
Connection Management
🙂
MTUN: github.com/stoops/vpn
MITM: github.com/stoops/mitm
~
The kick.com live stream video experience on the web is not the best overall, it seems to constantly lose track of a previously buffered section of the live stream and then sends you to the live portion but mine also gets stuck on reconnecting again and remains frozen until a manual refresh! I tried to write a series of hacky javascript modifications to help solve the following issues:
// ==UserScript==
// @name klol
// @namespace http://tampermonkey.net/
// @version 2026-08-19
// @description try to take over the world!
// @author You
// @match https://kick.com/*
// @icon https://www.google.com/s2/favicons?sz=64&domain=kick.com
// @grant GM_addStyle
// @noframes
// ==/UserScript==
(function() {
'use strict';
GM_addStyle('#channel-chatroom { display: none !important; }');
var join = "?s=";
var murl = location.href;
var wait = 5;
var redo = 0;
function mmov(time) {
const targets = document.querySelectorAll('video');
targets.forEach(target => {
['mousedown', 'mouseup', 'click'].forEach(eventType => {
target.dispatchEvent(new MouseEvent(eventType, {
bubbles: true,
cancelable: true
}));
});
});
setTimeout(() => {
const target = document.querySelector('span[data-orientation="horizontal"]');
const event = new PointerEvent('pointerdown', {
bubbles: true,
cancelable: true,
composed: true,
pointerId: 1,
pointerType: 'mouse',
isPrimary: true,
clientX: 151,
clientY: 521,
button: 0,
buttons: 1,
pressure: 0.5
});
target.dispatchEvent(event);
setTimeout(() => {
document.querySelector("video").currentTime = time;
const target = document.querySelector('span[data-orientation="horizontal"]');
target.dispatchEvent(new PointerEvent('pointerup', {
bubbles: true,
cancelable: true,
composed: true,
pointerId: 1,
pointerType: 'mouse',
isPrimary: true,
clientX: 151,
clientY: 521,
button: 0,
buttons: 0
}));
}, 357);
}, 135);
}
function msec(inpt) {
var info = inpt.split(":");
if (info.length == 3) {
return ((parseInt(info[0]) * 3600) + (parseInt(info[1]) * 60) + parseInt(info[2]));
}
return 0;
}
function mbuf(objc, urls, time) {
if (urls == "") {
/*var left = new KeyboardEvent("keydown", { bubbles:true, cancelable:true, keyCode:37, which:37, key:"ArrowLeft", code:"ArrowLeft" });
objc.dispatchEvent(left);
objc.currentTime = time;*/
mmov(time);
} else {
location.href = (urls + join + time);
}
}
function rsec(time) {
const hour = Math.floor(time / 3600);
const mins = Math.floor((time % 3600) / 60);
const secs = Math.floor(time % 60);
const hhxx = String(hour).padStart(2, "0");
const mmxx = String(mins).padStart(2, "0");
const ssxx = String(secs).padStart(2, "0");
return (hhxx + ":" + mmxx + ":" + ssxx);
}
var r = -1;
var d = -2;
function mtxt() {
var q = document.querySelector("video");
var s = location.href.replace(/\?.*$/mig, "");
if (q) {
var t = parseInt(q.currentTime);
var u = (q.duration == Infinity) ? 0 : parseInt(q.duration);
var c = document.getElementById("channel-content");
if (c) {
var o = document.querySelector('[data-testid="follow-button"]');
if (o) {
o.parentNode.innerHTML = ("<span style='font-family:Monaco;'><span id='stop' style='display:none;'></span><span id='last' style='display:none;'>0</span> <a href='" + s + "'><b><---></b></a> <a href='javascript:void(0);' onclick='location.href = \"" + s + "?s=\" + document.getElementById(\"secs\").innerText.replace(/[^0-9]/ig, \"\");'><span id='secs'>[X]</span></a> <a href='javascript:void(0);' onclick='var o = document.getElementById(\"stop\"); var v = document.querySelector(\"video\"); if (o.innerText == \"\") { o.innerText = \"stop\"; v.pause(); } else { v.play(); o.innerText = \"\"; }'><span id='time'>" + rsec(t) + "</span></a> </span>");
}
var w = document.getElementById("time");
if (w) {
if (murl.includes(join)) {
//var q = document.querySelector("video");
var p = (parseFloat(murl.replace(/^.*=/mig, "")) - 5.0);
console.log(" TIME " + q.readyState + " p:" + p);
mbuf(q, "", p);
murl = "";
}
var stop = document.getElementById("stop");
if ((q.readyState != 4) && (stop.innerText == "")) {
console.log(" LOAD " + q.readyState + " r:" + r);
if (wait > 0) {
wait -= 1;
} else {
if (r > 15) {
location.href = (s + join + r);
} else {
location.href = s;
}
stop.innerText = "x";
}
}
var last = document.getElementById("last");
var h = parseInt(last.innerText);
var y = document.getElementById("secs");
var e = parseInt(r + ((u - r) * 0.75));
if (u != 0) {
if ((r > 0) && ((t < 15) || (e < t))) {
console.log(" KICK " + q.readyState + " w:" + w.innerText + " t:" + t + " u:" + u + " h:" + h + " e:" + e + " r:" + r);
mbuf(q, s, r);
redo = 5;
} else {
y.style.color = "#31e531";
y.innerText = (" [" + t + "] ");
r = t; d = -9;
last.innerText = t;
document.getElementById("time").innerHTML = ("-" + rsec(u - t));
}
} else {
y.style.color = "#e95555";
y.innerText = (" [" + t + "] ");
r = -9; d = t;
last.innerText = "0";
document.getElementById("time").innerHTML = ("+" + rsec(t));
}
}
}
}
}
function maud() {
var vobj = document.getElementById("vido");
var volu = document.querySelector("video");
if (volu) {
if (!vobj) {
var main = document.querySelector("main").parentNode;
document.body.innerHTML = "<div id='vido'></div>";
document.body.appendChild(main);
const bloc = document.querySelector('a[href="/category/just-chatting"]')?.closest('div.flex');
if (bloc) { bloc.style.display = 'none'; }
setInterval(mtxt, 1.91 * 1000);
} else {
volu.volume = 1;
}
}
}
setInterval(maud, 1.91 * 1000);
})();
When reading packets or network data from a tunnel interface, the order in which they are read does matter as they can impact connectionless protocols and also cause stateful protocols to spend time re-ordering data! There were three techniques that I tried implementing to solve this issue:
One other observation I noticed is speed tests may seem lower which I believe is because of all the extra inner header data being prepended to the buffers in addition to the outer IPv4 + TCP headers:
Added note: Making a VPN-style MITM Proxy service which handles thousands of network states and file descriptors is all about connection management and thread management!
Final note: Building these solutions on top of TCP allows for larger payloads, ordered delivery, auto keepalives, and connection management – full size MTU!
~
MTUN: github.com/stoops/vpn
MITM: github.com/stoops/mitm
~
It is inspired by icanhazip.com but it returns a little more information as well!
curl icanhazdns.com
~
Please help me start a petition to Apple to bring back smaller sized phones with a pro screen and a flat metal ribbon which wraps the curved glass front and back like a beautiful diamond ring design should be! The iPhone 4S was soo close, all it needed was a full AOD screen with curved corners and edges…
screen -dm -S up bash -c "do-release-upgrade -d -m server ; sleep 99999"
Bonus Command:
screen -p 0 -S test -X stuff 'echo "test" \n'
~
So after spending a few years working first on a encrypted proxy solution and then moving to a encrypted tunnel solution, I’ve carried forward this highly modified version of the (ARCF) RC4 stream cipher, trying to tune it up and make improvements to it over time. This latest version includes the following features over the original version.
ARCF [DROP-INIT-XCTR-XKEY-XCBC-KSMG-HASH] MODS
[Code Snippet]
~
[Example Zero-Out/One-Bit Changes Inputs/Outputs]
~
Source Code: github.com/stoops/vpn/blob/main/lib/enc.c
~