FINDING · DETECTION

The GFW only inspects two locations within an HTTP request for censored keywords: the path component of the request line and the Host header, in UTF-8 and GB 18030 encodings (with %-decoding applied). Cookie headers, custom headers (e.g., X-Tension), and POST body fields are not monitored. Even in monitored positions, only approximately 75% of requests containing censored keywords actually trigger a TCP RST disconnection.

From 2021-rambert-chineseChinese Wall or Swiss Cheese? Keyword filtering in the Great Firewall of China · §4.4 · 2021 · WWW

Implications

Tags

censors
cn
techniques
keyword-filteringdpirst-injection

Extracted by claude-sonnet-4-6 — review before relying.