FINDING · DETECTION

Starting October 1, 2023, the GFW began injecting HTTP 301 and 302 responses to connections destined for 1.1.1.1:80, redirecting clients to China's National Anti-Fraud Center (182.43.124.6, AS58519 China Telecom Cloud). Over 6,169 HTTP requests from a Tencent Cloud Beijing vantage point (AS45090), the GFW injected 301 responses at a 9.06% rate and 302 responses at a 28.5% rate.

From 2023-gfw-blocking-1111The blocking of 1.1.1.1 in China, starting from 2023-10-01 · Major observations / Analysis on the injection to 1.1.1.1:80 · 2023 · gfw.report

Implications

Tags

censors
cn
techniques
packet-injectionip-blocking

Extracted by claude-sonnet-4-6 — review before relying.