China national company registry JavaScript-challenge observations, 14 August 2026
收藏资源简介:
HTTP status codes returned by China's national company registry and two government control hosts, measured from two unrelated networks inside mainland China on 14 August 2026. Method: each host root was requested three times per vantage point. The two vantage points share no infrastructure — a China Unicom Shandong consumer broadband line and a Shanghai cloud host — and the exit address of each was verified before the run. Control hosts were requested from the same machine in the same session, which is what distinguishes a server-side refusal from a broken proxy, a routing fault or an IP-range block. Result: the registry front page returned 521 on all six attempts. Both control hosts returned 200 on all six. A registry sub-host returned precondition and method refusals. The 521 responses carried a JavaScript-challenge signature: a client that executes the returned script obtains a cookie and is admitted on a later request, and a client that does not execute it stays on 521. A browser therefore reaches the site and a plain HTTP client does not. Limits, stated so they travel with the data: this is one date and two vantage points, both inside mainland China, so it says nothing about access from outside China and nothing about this host today. The challenge is identified from the shape of the response and from secondary technical sources, not from any vendor documentation. No attempt was made to pass the challenge and no circumvention method is published here or anywhere else by us. Fields: observation_date, host, label, role (target or control), vantage, vantage_detail, round1_status, round2_status, round3_status, challenge_signature, notes. Write-up, including the two wrong conclusions we reached before this one: https://currawongweb.com/verify/gsxt-javascript-challenge/




