FINDING · DETECTION

Default Tor connections to a private bridge inside China were detected by the Great Firewall via active probing: an initial connection succeeded, followed by a probe from a Chinese IP address approximately 15 minutes later that performed a TLS handshake and then blacklisted the (IP, port) combination. Subsequent connection attempts resulted in a successful SYN followed by spoofed TCP RSTs terminating both the client and bridge connections.

From 2013-dyer-protocolProtocol Misidentification Made Easy with Format-Transforming Encryption · §6 · 2013 · Computer and Communications Security

Implications

Tags

censors
cn
techniques
active-probingrst-injection
defenses
torbridges

Extracted by claude-sonnet-4-6 — review before relying.