FINDING · DEFENSE
Two TCP-layer SNI-spoofing techniques briefly circumvented Iran's DPI for approximately four days: (1) sending a fake ClientHello with a TTL too low to reach the server but high enough to pass the censor, and (2) sending a fake ClientHello at a future TCP sequence number that the server would ignore but the stateless DPI would accept. Both were defeated once Iran placed Cloudflare IPs behind a stateful NAT that validated checksums and sequence numbers. Iran's SNI whitelist permitted only specific domains, hcaptcha.com among them.
From 2026-tuleo1-internet-analysis-shutdown — Internet analysis in the shutdown in iran · Issue body (SNI spoofing methods paragraph) · 2026 · net4people/bbs
Implications
- TTL-limited and out-of-order fake-record attacks on stateless DPI are viable only until the censor deploys stateful reassembly; treat them as a temporary emergency measure rather than a durable transport design.
- Publish such techniques only when active deployment is already widespread — the 4-day window before countermeasure suggests that mass adoption itself triggers rapid patching.
Tags
Extracted by claude-sonnet-4-6 — review before relying.