FINDING · DETECTION

The Great Firewall of China deploys at least four distinct, simultaneously-operating RST injectors with separate fingerprints (IPID 64, IPID -26, SEQ 1460, RAE). The RAE injector—which sets RST+ACK+ECN-nonce-sum flags—is the most common, with 4,162 distinct source IPs observed at UCB alone. Of 298 ICSI hosts disrupted by Chinese injectors, 102 showed fingerprints of two or more injectors acting independently on the same connection.

From 2009-weaver-detectingDetecting Forged TCP Reset Packets · §7.1.6 · 2009 · Network and Distributed System Security

Implications

Tags

censors
cn
techniques
rst-injectionpacket-injection

Extracted by claude-sonnet-4-6 — review before relying.