Counterpoint: Many efficient tunneling techniques are known and most
tunneling applications used by the clients have been found via Google.

What detains me from hacking a simple tunneling just now myself?

Is http://www.something.invalid/?PHPSESSIONID=$somehexgarbage a simple
website access or a constant data transfer?

Good point. If you don't know, you cannot prevent tunneling.

At first there was the word. And the word was Content-type: text/plain