FINDING · EVALUATION

Pakistan Telecom Company Ltd. implemented DNS injection by returning 127.0.0.1 (localhost) for blocked domains, so TCP connections and HTTP requests appeared to succeed ("Content available" near 100%) while no legitimate content was served. Only 11.7% of DNS resolutions yielded a plausible IP address, yet the symptom is a silent local service response rather than an explicit blockpage, misleading users and confusing automated detection tools that rely on TCP reachability.

From 2015-aceto-monitoringMonitoring Internet Censorship with UBICA · §3.1 · 2015 · Traffic Monitoring and Analysis

Implications

Tags

censors
pk
techniques
dns-poisoning

Extracted by claude-sonnet-4-6 — review before relying.