FINDING · DETECTION

The Russian censor at the tested Moscow vantage point (ASN 50867, China Unicom-equivalent private ISP) inspects only the first HTTP packet of the first TCP segment in a TCP stream and never blocks a second HTTP request, whether coalesced in the same TCP packet or sent in a subsequent one. All 2,015 web-server-accepted test vectors evaded Russian censorship, including standard-compliant whitespace-injection vectors (e.g., 'Content-Length\x20: <len>\x20').

From 2024-niere-http-smugglingTurning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling · §5.2 (Russia paragraph) · 2024 · FOCI 2024 (Free and Open Communications on the Internet)

Implications

Tags

censors
ru
techniques
dpikeyword-filteringpacket-injection

Extracted by claude-sonnet-4-6 — review before relying.