FINDING · DETECTION

Censoring middleboxes respond to non-compliant TCP sequences because they must handle asymmetric routing and cannot rely on observing both sides of a connection. The hSYN; PSH+ACKi sequence elicited responses from 69.6% of 184 tested censoring middleboxes with a maximum amplification of 7,455×, while a lone PSH+ACK with no prior handshake elicited responses from 33.2% of middleboxes.

From 2021-bock-weaponizingWeaponizing Middleboxes for TCP Reflected Amplification · §2, §3.3 · 2021 · USENIX Security Symposium

Implications

Tags

censors
generic
techniques
middlebox-interferencedpipacket-injection

Extracted by claude-sonnet-4-6 — review before relying.