FINDING · EVALUATION
tracebox identified a transparent HTTP proxy or IDS within a National Research Network (SUNET) that intercepted port-80 SYN probes but not port-21 SYN probes, producing shorter observed path lengths to port 80. It also found proxy misconfigurations causing forwarding loops for non-HTTP traffic, where ICMP replies alternated between two routers indefinitely.
From 2013-detal-revealing — Revealing Middlebox Interference with Tracebox · §4.2 · 2013 · Internet Measurement Conference
Implications
- Assume transparent port-80 proxies are present even in academic or research networks; circumvention transports must not assume TCP connections on well-known ports reach their intended destination without interception or protocol inspection.
- Test circumvention handshakes across both standard (80, 443) and non-standard ports to detect port-selective proxy interception that may silently terminate or reroute connections.
Tags
Extracted by claude-sonnet-4-6 — review before relying.