FINDING · DETECTION

All tested censors (China, Iran, Kazakhstan) can be triggered statelessly—without completing a TCP 3-way handshake—using a SYN with decremented sequence number followed by a PSH+ACK containing the forbidden payload. This stateless triggering enables fully off-path, source-spoofed attacks: an adversary with packet-spoofing capability can residually censor a victim pair they have no on-path access to.

From 2021-bock-yourYour Censor is My Censor: Weaponizing Censorship Infrastructure for Availability Attacks · §IV, §V.A · 2021 · Workshop on Offensive Technologies

Implications

Tags

censors
cnirkz
techniques
rst-injectionip-blockingmiddlebox-interference

Extracted by claude-sonnet-4-6 — review before relying.