FINDING · DETECTION

TTL manipulation experiments demonstrated that the GFW injects forged DNS responses at the router level, not at the DNS server: responses to censored domain queries exhibited inconsistent IP ident fields and wildly varying TTL values — consistent with a stateless in-path router — while control (non-censored) responses to the same server showed monotonically increasing ident and stable TTL. The injection was observed exclusively on port 53; identical queries sent to port 80 received no injected responses.

From 2007-lowe-greatThe Great DNS Wall of China · §6.4, Table 3 · 2007 · New York University

Implications

Tags

censors
cn
techniques
dns-poisoningpacket-injectionmiddlebox-interferenceport-blocking

Extracted by claude-sonnet-4-6 — review before relying.