FINDING · DETECTION

A TTL-limited bare FIN packet (without ACK) is sufficient to induce GFW to tear down its connection state for a live TCP session (TCP6b), because GFW accepts FIN packets that violate RFC 793's requirement for the ACK flag. After induced state teardown, subsequent packets carrying banned keywords on the same connection produce no RST, confirming the monitor has lost track of the flow.

From 2013-khattak-towardsTowards Illuminating a Censorship Monitor's Model to Facilitate Evasion · §5, Table 1 (TCP6b) · 2013 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
dpirst-injectionmiddlebox-interference
defenses
geneva

Extracted by claude-sonnet-4-6 — review before relying.