FINDING · DEFENSE

The GFW's keyword-blocking mechanism relies entirely on endpoints honoring injected TCP RST packets; because the IDS operates out-of-band and cannot remove packets already queued in the router's transmission path, configuring both endpoints to silently discard incoming RSTs (e.g., via `iptables -A INPUT -p tcp --tcp-flags RST RST -j DROP`) allows blocked content to transfer unimpeded. In a controlled experiment, 28 injected RSTs were ignored and the complete blocked web page was successfully retrieved.

From 2006-clayton-ignoringIgnoring the Great Firewall of China · §5 · 2006 · Privacy Enhancing Technologies

Implications

Tags

censors
cn
techniques
rst-injectionkeyword-filteringdpi

Extracted by claude-sonnet-4-6 — review before relying.