FINDING · DETECTION

Of the 55 filters that inspected the HTTP Host header, 26 keyed only on the first Host header in a multi-Host request, 27 keyed only on the last, and only 2 examined both. Placing a benign Host header in the position the filter reads and the blocked URL in the other position bypassed the filter, and this divergence in behavior tracks RFC 7230's requirement to reject multi-Host requests with a 400 error — which none of the tested filters implemented.

From 2017-jermyn-autosondaAutosonda: Discovering Rules and Triggers of Censorship Devices · §4.1 Mechanism · 2017 · Free and Open Communications on the Internet

Implications

Tags

censors
generic
techniques
dpikeyword-filteringmiddlebox-interference
defenses
mimicry

Extracted by claude-sonnet-4-6 — review before relying.