What is the TCP Split-Handshake Attack and Does It Affect Me?
ID: c54ebb35-33c9-5392-b18a-f35a16b1f898
STIX ID: report--c54ebb35-33c9-5392-b18a-f35a16b1f898
Feed Name: WatchGuard Secplicity Blog
Threat Score
This report explains the TCP split-handshake attack: a legitimate but unusual TCP handshake variant that a malicious server can use to reverse connection direction and potentially evade gateway security controls (IPS/AV/content filters). It provides technical background, recommends testing with the fakestack.rb tool, and reports that WatchGuard XTM appliances are not vulnerable because they reject split-handshake connections and enable TCP SYN checking by default.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
