logo

What is the TCP Split-Handshake Attack and Does It Affect Me?

ID: c54ebb35-33c9-5392-b18a-f35a16b1f898

STIX ID: report--c54ebb35-33c9-5392-b18a-f35a16b1f898

Feed Name: WatchGuard Secplicity Blog

Threat Score
30/100

Date Published: 2011-04-15

Date Updated: 2026-05-01

Author: The Editor

...
...

This report explains the TCP split-handshake attack: a legitimate but unusual TCP handshake variant that a malicious server can use to reverse connection direction and potentially evade gateway security controls (IPS/AV/content filters). It provides technical background, recommends testing with the fakestack.rb tool, and reports that WatchGuard XTM appliances are not vulnerable because they reject split-handshake connections and enable TCP SYN checking by default.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.