FINDING · DEFENSE

Two TCP-layer SNI-spoofing techniques briefly circumvented Iran's DPI for approximately four days: (1) sending a fake ClientHello with a TTL too low to reach the server but high enough to pass the censor, and (2) sending a fake ClientHello at a future TCP sequence number that the server would ignore but the stateless DPI would accept. Both were defeated once Iran placed Cloudflare IPs behind a stateful NAT that validated checksums and sequence numbers. Iran's SNI whitelist permitted only specific domains, hcaptcha.com among them.

From 2026-tuleo1-internet-analysis-shutdownInternet analysis in the shutdown in iran · Issue body (SNI spoofing methods paragraph) · 2026 · net4people/bbs

Implications

Tags

censors
ir
techniques
dpisni-blockingmiddlebox-interference
defenses
geneva

Extracted by claude-sonnet-4-6 — review before relying.