FINDING · DEFENSE

China's GFW keyword-based and Host-header HTTP censorship can be simultaneously defeated by a 'sandwich' strategy: a header with a name ≥64 bytes must appear before the Host header, the Host header value must start ≥1,281 bytes from the start of the headers, and the final header must be ≥129 bytes total — and the Host header must not be first or last. A 64+ byte header name alone is sufficient to defeat Host-header censorship because it prevents the GFW from reading further headers.

From 2022-harrity-getGET /out: Automated Discovery of Application-Layer Censorship Evasion Strategies · §5.2 · 2022 · USENIX Security Symposium

Implications

Tags

censors
cn
techniques
dpikeyword-filtering
defenses
geneva

Extracted by claude-sonnet-4-6 — review before relying.