FINDING · EVALUATION
Two of the 8 handshake-accepting injected IPv4 addresses host active services reachable both inside and outside China: 103.230.123.190 runs OpenSSH 8.2p1 on port 22, and 103.246.246.144 redirects 0.164% of all censored-domain requests to a website serving forbidden adult content.
From 2025-sheffey-extended — Extended Abstract: I’ll Shake Your Hand: What Happens After DNS Poisoning · §2.2.1 · 2025 · Free and Open Communications on the Internet
Implications
- Circumvention clients should never silently follow TCP connections to DNS-poisoned addresses; active confirmation of the intended server identity (e.g., pinned certificates) is required before transmitting any user data.
Tags
Extracted by claude-sonnet-4-6 — review before relying.