FINDING · DETECTION

Iran's HTTP censorship allows the TCP three-way handshake to complete normally before acting on the HTTP GET request: the censor responds with a '403 Forbidden' and simultaneously sends 5 spoofed RST packets to the destination server (3 with in-sequence numbers, 2 with seemingly random offsets). No modifications to TCP/IP or HTTP headers were observed at either endpoint, ruling out a transparent proxy and pointing to inline DPI.

From 2013-aryan-internetInternet Censorship in Iran: A First Look · §4.2, Figure 3 · 2013 · Free and Open Communications on the Internet

Implications

Tags

censors
ir
techniques
dpirst-injectionkeyword-filtering

Extracted by claude-sonnet-4-6 — review before relying.