China's national company registry serves browsers and refuses scripts: paired-control observations from two mainland networks
收藏资源简介:
Whether China's national company registry (www.gsxt.gov.cn) answers automated clients, measured on 2026-08-14 from two mainland-China vantage points that share no infrastructure — a China Unicom Shandong consumer broadband line whose exit address was confirmed before the run, and a Shanghai cloud host — three rounds each, with control hosts requested from the same machines in the same sessions. The registry front page returned 521 on all six target requests (two vantage points × three rounds). In the same sessions, two government control hosts — www.gov.cn and www.samr.gov.cn — returned 200 on all twelve of their requests. A registry sub-host, bt.gsxt.gov.cn, returned 412/405/412 from the Shandong vantage: precondition and method refusals rather than a challenge. The 521 is not silence. Its body is obfuscated JavaScript that computes a clearance cookie, and the response carries a JS-challenge header and a challenge cookie; a client that executes the script is admitted on a subsequent request, and a client that does not stays on 521 indefinitely. The same URL returns 200 in a browser. The accurate statement is therefore not that the registry is down, but that it serves browsers and refuses scripts. Boundaries that travel with the figures: this is a single-day observation, not continuous monitoring, and it covers front-page reachability rather than the registry's search function. Both vantage points are inside mainland China, so the result says nothing about foreign-IP blocking — if anything it rules that explanation out for these observations. The sub-host was tested from one vantage point only and was not retested from Shanghai. The dataset records observed HTTP behaviour and does not identify the vendor, infer intent, or establish who the challenge is aimed at. Method, per-host rounds and full write-up: https://currawongweb.com/verify/gsxt-javascript-challenge/



