FINDING · DETECTION

Russia's censor (at the Moscow/ASN-50867 vantage point) inspects only the first HTTP packet of the first TCP segment per TCP stream and never analyzes subsequent HTTP requests—whether in the same TCP packet or a later one. This caused all 2,015 accepted test vectors to successfully evade censorship, and the bypass is achievable with standard-compliant HTTP (e.g., whitespace or case variations in header names, which HTTP/1.1 explicitly permits).

From 2024-m-ller-turningTurning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling · §5.2 / §5.3 · 2024 · Free and Open Communications on the Internet

Implications

Tags

censors
ru
techniques
dpikeyword-filtering
defenses
geneva

Extracted by claude-sonnet-4-6 — review before relying.