FINDING · DETECTION
All five Republic of Cyprus ISPs (Callsat AS24672, Cablenet AS35432, Cyta AS6866, MTN AS15805, and Primetel) used DNS hijacking as their sole blocking mechanism, creating local zone entries that override legitimate DNS replies and redirect users to ISP-controlled block pages or error pages.
From 2017-ververis-internet — Internet Censorship Capabilities in Cyprus: An Investigation of Online Gambling Blocklisting · §6 · 2017 · E-Democracy
Implications
- DNS-based blocking is ISP-specific and entirely bypassed by configuring any third-party resolver; circumvention tools should default to encrypted DNS (DoH/DoT) or embed a trusted resolver to avoid relying on the user's ISP resolver.
- Since block pages are served via HTTP redirect after DNS hijack, HTTPS-only services already defeat the notification mechanism; proxies should default to HTTPS to prevent blockpage injection.
Tags
Extracted by claude-sonnet-4-6 — review before relying.