FINDING · DEPLOYMENT

Analysis of leaked stack frames confirmed the GFW's packet injector processes run on x86-64 Linux with ASLR and PIE enabled but without stack canaries, implying that buffer overflow vulnerabilities in the GFW may lack effective mitigation. Each injector process was inferred to use exactly four packet-handling threads, identified by up to four unique stack-address groups per return address (each group spanning within the 8 MB default Linux stack size).

From 2024-sakamoto-bleedingBleeding Wall: A Hematologic Examination on the Great Firewall · §4.4 Process Characteristics · 2024 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
dpi

Extracted by claude-sonnet-4-6 — review before relying.