FINDING · DETECTION

The StegoTorus-HTTP module returns '200 OK' for non-existent URIs, produces no response to HEAD, OPTIONS, DELETE, and TEST method requests, and omits xref tables from generated PDF files. Using httprecon with 9 request types, the StegoTorus server is distinguishable from any real HTTP server by an OB (resource-limited) censor that records port-80 destination IPs at line speed and fingerprints them offline.

From 2013-houmansadr-parrotThe Parrot is Dead: Observing Unobservable Network Communications · §VIII-B, §VIII-C, Table III · 2013 · Symposium on Security \& Privacy

Implications

Tags

censors
generic
techniques
dpiactive-probing
defenses
mimicrypluggable-transport

Extracted by claude-sonnet-4-6 — review before relying.