FINDING · DETECTION

Injectors sending multiple RSTs with increasing sequence numbers to overcome the RST_SEQ_DATA race condition produce a detection signature (RST_SEQ_CHANGE) that cannot arise from a standards-compliant TCP endpoint: the second RST must have a sequence number exceeding both the preceding RST and any ACK yet observed from the receiver. This creates an inherent design tension — a robust injector that uses sequence-incremented multi-packet RSTs to ensure delivery is precisely the kind most detectable by passive monitoring.

From 2009-weaver-detectingDetecting Forged TCP Reset Packets · §5 · 2009 · Network and Distributed System Security

Implications

Tags

censors
cngeneric
techniques
rst-injectionpacket-injection

Extracted by claude-sonnet-4-6 — review before relying.