Researchers documented DNS-response poisoning linked to China’s Great Firewall that affects domains whose authoritative DNS traffic traverses Chinese infrastructure, not only .cn domains. DNS queries containing selected keywords, including webproxy.id, may receive rotating forged A records—even for nonexistent names—in place of expected NXDOMAIN or REFUSED responses, consistent with censorship infrastructure injecting or altering DNS replies.
The forged records can create subdomain-takeover-like exposure, including through Fastly domain claiming, and may route users to vulnerable cPanel deployments where attackers can trigger XSS. Organizations operating authoritative nameservers in China are most exposed; moving authoritative DNS outside China and setting Secure and HttpOnly cookie attributes can reduce some session-security impact, though phishing and website-defacement risks remain.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Assetnote demonstrated that poisoned subdomains resolving to Fastly could be abused if an attacker claims an unclaimed target wildcard domain and configures an attacker-controlled origin. Independent researcher Eric Head also provided a technique that searches poisoned subdomains for vulnerable cPanel hosts to produce an XSS condition.
Assetnote reported that DNS queries for domains whose authoritative DNS traffic traverses Chinese infrastructure could receive forged A records when query names contain trigger keywords such as "webproxy.id." The researchers assessed the behavior as network-path manipulation associated with Great Firewall censorship mechanisms, potentially affecting zones across multiple TLDs.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.