FINDING · EVALUATION

HTTP GET fuzzing via subtle token modifications bypassed large fractions of filters: removing the `\r\n` before the Host header bypassed 36–38 of 44 Host-header filters; embedding the censored URL in the middle of a long hostname string bypassed 33–35 filters; placing the URL in an after-Host field with a non-empty Host bypassed 29–36 filters. Blacklist coverage was also weak: no filter blocked all 100 of the Alexa top adult sites, and some blocked as few as 31.

From 2017-jermyn-autosondaAutosonda: Discovering Rules and Triggers of Censorship Devices · §4.1 / Appendix A · 2017 · Free and Open Communications on the Internet

Implications

Tags

censors
generic
techniques
dpikeyword-filtering
defenses
mimicryrandomization

Extracted by claude-sonnet-4-6 — review before relying.