This document contains details on a proof-of-concept white paper on how to circumvent Cisco access-lists which rely on only permitting “established” TCP sessions by establishing communications between a client and server (included) which never uses the SYN bit. Works on any firewall that accepts all packets without the syn bit.
You can download it from the following link: https://packetstormsecurity.com/files/download/21983/cisco-ack-proof-concept.tgz
Source: https://packetstormsecurity.com/files/21983/cisco-ack-proof-concept.tgz.html