Analysis of SOCKS5 Handshake Initialization & DPI Behavior

Plain-text SOCKS5 traffic is typically intercepted and filtered by deep packet inspection (DPI) systems like the GFW. Recently, however, I noticed a strange phenomenon: certain unencrypted packets containing sensitive domain keywords (such as google.com) were able to pass through without being blocked.

After capturing and inspecting the network traffic, I found that this behavior is directly tied to how the SOCKS5 connection is initialized.


1. SOCKS5 Handshake Protocol

When establishing a SOCKS5 connection, the client first sends a Method Selection Request detailing the authentication methods it supports.

A typical request frame looks like this:

05 02 00 02

The byte breakdown is as follows:

  • 05: Protocol version (SOCKS5).
  • 02: NMETHODS — the number of authentication methods supported (in this case, 2).
  • 00 02: METHODS — the supported method identifiers:
    • 0x00: No authentication
    • 0x02: Username/Password

Standard SOCKS5 Authentication Method Identifiers

Method Code Description
0x00 No authentication required
0x01 GSSAPI
0x02 Username/Password
0x03 – 0x7F Methods assigned by IANA
0x80 – 0xFE Reserved for private use
0xFF No acceptable methods

2. The Anomaly

The anomaly occurs when the client advertises support for GSSAPI (0x01) during the initial negotiation.

Even if the server ultimately selects 0x00 (No Auth) or 0x02 (Username/Password) and GSSAPI is never actually used for the connection, the presence of 0x01 in the client’s initial request causes the GFW to bypass DPI scanning on subsequent payload traffic.

Specifically, when the handshake payload contains:

05 03 00 01 02

(SOCKS5, 3 methods supported: No Auth, GSSAPI, Username/Password)

The GFW appears to ignore the connection from that point forward.


3. Conclusion

This behavior is quite bizarre, though it holds true in recent tests. However, relying on protocol quirks in plain-text SOCKS5 is inherently fragile and unreliable for long-term use. For consistent security and uninhibited traffic flow, encapsulating connection data using encrypted solutions like stunnel or TLS wrappers remains the recommended approach.

Leave a Reply

Your email address will not be published. Required fields are marked *


This site uses Akismet to reduce spam. Learn how your comment data is processed.