Monday, August 06, 2007
Tuesday, July 31, 2007
Bootstrapping to Anonymous P2P Networks
Even P2P overlays need some way to bootstrap in disconnected networks.
While DNS typically bootstraps with hardcoded IP addresses of the 13
root servers.
Ants p2p (version 2) kerjodando bootstraps using the itsdargens.com website.
Any user website can be set-up and used for this purpose.
Basically, all code is open source so that users can set-up own bootstrapping website.
The website replaces the current ANts p2p bootstrapping methods:
- irc (why use this method when a website is much more friendly)
- Gwebcache (this openly displays your ip address to strangers) and
- Random walk accross the ad-hoc network. This allows users who you are not connected to (and don't know) to find out who else is connected.
The itsdargens.com Ruby on Rails bootstrapping website will provides the following functions:
- Bootstrapping to a friend to friend group
- TCP NAT traversal
Posted by
Ezzye
at
8:12 AM
Labels: 443, Anonymous P2P, ANts, Ants p2p, bootstrap, friend-to-friend, kerjodando, web 2.0
Monday, July 30, 2007
STUNT P2P TCP NAT Traversal on a Ad-hoc Overlay Network

I've been thinking about this TCP NAT Traversal (TCP hole punching a method that allows everyone to connect quickly without port forwarding).
I think the following changes are needed to kerjodando to make it work.
- Trusted Peers list (and itsDargens User database table) need to include two extra hidden fields, User ID (prob already in itsDargens database) and "use STUNT" flag. For example, if 100 users on a LAN connect to one group they will all have different user IDs although they have the same ip+port. Then when a user wants to connect to another user (after trying direct connection) they connect to STUNT using their user ID and signal (using SIPS) to another users ID. STUNT then tell them what ip+port to use to connect to that user ID. Also STUNT would set the "use STUNT flag" to yes.
- ItsDargens user database to change to include "use STUNT" flag
- Trusted peer file needs to download and use the included user IDs and "use STUNT" flag as well as ip+port.
However, once they have connected to all their trusted peers they can disconnect form the STUNT server.
Also, probably there will be some users that you can't connect to even with STUNT, maybe these should be marked as such in "use STUNT" flag and counted as connected when deciding if should disconnect form STUNT server.
To me a STUNT server consists of the following processes:
- Maintaing TCP user connections with many users (User IDs)
- Recording user (user ID) ip+port for at least two test connections from the user
- Calculating predicted ip+port for a user (User ID)
- Reply to a request to connect to a User ID with predicted ip+port
- Telling other User to also make a request etc
- Recording "STUNT flag" in user database table so that it can be included in downloaded trusted peers
- Recording if STUNT does not work
More About STUNT:
Found STUNT ( Simple Traversal of UDP Through NATs and TCP too) library in java:
http://nutss.gforge.cis
What does the
stunt.jar library provide?It provides a way to establish unproxied TCP connections between two end-points, both of which can be behind a NAT. It returns a
SocketChannel that can be used for blocking or non-blocking IO as the application desires.How does one write a server-client or peer-to-peer applications with the library?
We have provided a simple server-client application consisting of an EchoServer ( http://nutss.gforge.cis
Does the library require some infrastructure?
Yes. The library requires a rendezvous server (much like a directory server) where applications with one URI can find the application with another URI and coordinate to establish a connection. The library also requires some STUNT servers that help applications find out their external IP address and port for establishing the real connection.
Does the rendezvous server proxy data?
No. The rendezvous server only helps set up the connection. After that, all data is exchanged directly between the end-points and does not go through the rendezvous server.
Who provides the rendezvous and STUNT service? Who can use them?
We at Cornell University are providing a rendezvous and STUNT service for developers and researchers to use. However, if you wish to deploy your own application that uses the library, we ask that you set up rendezvous and STUNT servers only for your own applications such that you do not overburden the Cornell service (which is for research and development purposes) and so that outages and changes in the Cornell service doesn't affect your application. The rendezvous server ( https://gforge.cis.cornell.edu
Is this library under active development? Will you implement feature X?
The library is a proof of concept that TCP NAT Traversal is possible and is intended to be a starting-poing for application developers who want to use it in a real-world deployable project. At the same time, it is a library that can be used more-or-less unmodified for research and quicky-development and prototyping of applications. Time permitting, I would like to implement various features that are requested; but I cannot promise that all features will be implemented in a timely fashion. I will do my best to make the library more suited to its primary goal -- show how the NAT TCP problem can be solved easily by applications.
I want to implement TCP NAT traversal in my application but don't want to use your library?
The TCP NAT traversal code is contained in the file STUNTCont.java ( https://gforge.cis.cornell.edu
Also see http://en.wikipedia.org/wiki
Aslo see:
see STUNT
http://nutss.gforge.cis
and
http://www1.ietf.org/mail
and
http://en.wikipedia.org/wiki
and
http://reports-archive.adm.cs
and
http://emu.freenetproject.org
Posted by
Ezzye
at
8:34 AM
Labels: 443, Ad-hoc, Anonymous P2P, ANts, Ants p2p, Dargens, ezzy elliott, F2F, friend-to-friend, java, Overlay Network, p2p, ruby on rails, STUNT, TCP, TCP NAT Traversal
Monday, July 16, 2007
Firewall Tunnelling and Quicker User Connection

Tne next project is ensure that users connect quickly and easily to kerjodando. It has two parts:
1. Ensure that users connect quickly and easily to trusted peers ONLY (except for users using Upnp to connect to other LAN users)
Currently "Ants" has several methods of connecting these need to be removed leaving only trusted peers and Upnp.
There might be more than this but here are the methods I know:
- irc - REMOVED
- gwebcache - REMOVED
- peers - previous connections - LEAVE
- random walk across the network from peer to peer recording peers with free slots - TO BE REMOVED
- manual connect in advance tab - LEAVE
- trusted peers - IMPROVE SO THAT IT KEEPS TRYING UNTIL CONNECTION MADE WITHOUT ANY BANDWIDTH TESTING
- Upnp - LEAVE
2. Using the itsDargens website as an intermediary develop a simple process to allow two peers with un-forwarded ports to connect.
I must admit that I don't fully understand the TCP/IP protocol but I would prefer if the solution involved a client connecting to website and then the website updating the trusted peers file to reflect the external port that was used. (This could be total rubbish on my part) The solution must be SIMPLE.
This is important as with fewer users in each group quick connection is very important and there is a high probability that both users may not have kerj ports forwarded.
Both jobs are urgent as the point of the application is to CONNECT and DOWNLOAD and currently about 50% of users can't connect!
The full list of things added and removed are:
Needed:
Own folder, separate from Ants - JAVA - OUTSTANDING
Client minimize to systems tray on opening - JAVA- OUTSTANDING
try to connect to trusted peers - JAVA- OUTSTANDING
itsdargens itermediate connection help where two users behind a firewall - RAILS - OUTSTANDING
ipfilter.dat - RAILS - OUTSTANDING
irc applet to website - RAILS- OUTSTANDING
email invite from google and IM on website - RAILS - OUTSTANDING
Not Needed:
Help page not needed as it is no help! - JAVA - DONE
Browser location setting no longer needed - JAVA - DONE
Monitor clip board for ed2k and ants links - JAVA - DONE
Random walk for new peers with free slots (must use trusted peers) - JAVA - OUTSTANDING
irc - JAVA - DONE
http tunnel - JAVA - DONE
ed2k hashes - JAVA - DONE
publish ip on gwebcache - JAVA - DONE
any restriction on peers connected to e.g. bandwidth - JAVA - OUTSTANDING
Posted by
Ezzye
at
10:39 AM
Labels: 443, anonymous, Anonymous P2P, ANts, Ants p2p, connecting, friend-to-friend, kerjodando, p2p, p2p development, social networking, Web proxy avoidance
Monday, July 02, 2007
You Can Use Any Port on ANts p2p version 2 (kerjodando)

The development team has just added a new option to use any port to connect to Ants p2p (kerjodando) YUM YUM!
See http://www.itsdargens.com/swarm/show_one/86d1cca8104f981648eb1b1d0f0f3a39
If you don't put a port then 443 is used.
443 is still the recommended port as it allows people behind firewalls to connect easily.
Please try it we need some feedback.
Posted by
Ezzye
at
12:38 PM
Labels: 443, anonymous, Anonymous P2P, ANts, Ants p2p, British Red Cross, Dargens, ezzy elliott, F2F, file sharing, friend-to-friend, p2p, p2p development, Port, small world, social networking, web 2.0
Friday, June 29, 2007
Port 443 in the Trusted Peer File

Currently kerjodando defaults to port 443 in the trusted peer file.
However, I have three computers on a LAN and so only one can use port 443.
So only one can be connected to from outside the LAN by using the trusted peer file.
This is now a very big issue.
I have received a lot of feedback from users (linux and Mac ) who can't use 443 so other users can't directly connect to them - they have to use an intermediary.
THIS HAS TO CHANGE.
So I propose that the developers add an input field on for port number on the swarm page e.g. http://www.itsdargens.com
Should put it below description but above start. Put the following highlighted text next to it.
Enter port for p2p client, if using a router this port must be forwarded (leave blank if not sure - default port is 443)
The default port should stay as 443. However if a user inputs a port number then this should be used instead of 443 in the trusted peers file that is downloaded every 5 minutes.
THIS TAKE PRIORITY OVER THE WEB GUI AS IT IS MY MISTAKE IN LOGIC THAT NEEDS TO BE FIXED.
NEED DO IT BEFORE CONTINUING TO WORK ON WEB GUI.
Posted by
Ezzye
at
9:05 AM
Labels: 443, Anonymous P2P, ANts, Ants p2p, ezzy elliott, friend-to-friend, kerjodando
Monday, June 25, 2007
Connecting to a P2P Network - ANts p2p and ANts p2p version 2 (kerjodando)
| Port Needed to Connect to Ants p2p and Ants p2p version 2 (kerjodando) | ||||
| Your Enviroment | Can You Connect? | |||
| Your Port | Port on Firewall Open? | Port forwarded? | YOU can connect TO OTHERS | OTHERS can connect TO YOU |
| 443 | Yes* | Yes | Yes | Yes |
| 443 | Yes* | No | Yes | Once you have connected to first user then others can connect to you. |
| Other Port | Yes | Yes | Yes | Once you have connected to first user then others can connect to you. |
| Other Port | Yes | No | Yes | Once you have connected to first user then others can connect to you. |
| Other Port | No | No | No | No |
| *This port is always open in firewalls; | ||||
Posted by
Ezzye
at
8:52 AM
Labels: 443, anonymous, Anonymous P2P, ANts, Ants p2p, connecting, ezzy elliott, F2F, kerjodando, p2p, p2p development, Port, web 2.0, Websense bypass

