FINDING · DETECTION

Injector 3 mirrors the probe packet's IP TTL in its injected reply rather than using a fixed TTL. This defeats TTL-limited localization probes: the injected reply only reaches the prober when the probe's initial TTL equals 2n−1 (where n is the hop distance to the injector); at lower TTLs the mirrored TTL is too small for the reply to return. All three injectors appear co-located (inter-probe delays within 0.2 ms of each other), confirmed from 7 vantage points across 5 continents, and the behavior is consistent across 62% of all 36K tested Chinese IP prefixes.

From 2020-anonymous-triplet-censorsTriplet Censors: Demystifying Great Firewall's DNS Censorship Behavior · §4.3 · 2020 · FOCI

Implications

Tags

censors
cn
techniques
dns-poisoningpacket-injection

Extracted by claude-sonnet-4-6 — review before relying.