FINDING · EVALUATION

GFW DNS AAAA responses for censored domains return 622 IPv6 addresses: 30 from Facebook's 2a03:2880::/32 network (all sharing interface identifier face:b00c:0:25de), and 592 malformed Teredo addresses in the 2001::/32 range that directly hex-encode entries from the IPv4 pool in the lower 32 bits rather than following RFC 4380 Teredo structure. The Teredo addresses' server IPv4 (0.0.0.0) and port (0) fields are nonsensical.

From 2025-sheffey-extendedExtended Abstract: I’ll Shake Your Hand: What Happens After DNS Poisoning · §2.1, Appendix A · 2025 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
dns-poisoning

Extracted by claude-sonnet-4-6 — review before relying.