5 ms·
I suppose you could spoof having full Internet access by hosting nsci.txt or connecttest.txt locally and editing your hosts file to direct www.msftncsi.com or w
by divbzero 4y ago
I suppose you could spoof having full Internet access by hosting nsci.txt or connecttest.txt locally and editing your hosts file to direct www.msftncsi.com or www.msftconnecttest.com to 127.0.0.1? Conversely, if those Microsoft websites ever failed, countless Windows machines would determine that they have limited or no Internet access.
- number6 4y agoBest hosting company: localhost
- deleted 4y ago[deleted]
- vgb2k18 4y agoIn the linked comment section, Raymond Chen replied somewhat abrasively to a comment similar to this (the comment was "wouldn't this be easy to spoof?"). A bit harsh I thought!
- pkulak 4y agoHe just had to say that this is for convenience, not security.
- c0nsumer 4y agoYep, exactly. Because another part of this is NCSI is used for captive portal detection, so Windows can/will notify the user that they need to do something more to keep using the network. Android and Chrome do the same sort of thing to detect internet access; this is how Android pops the notification to sign in to the network. Then, at least on Windows, the results of NCSI flow down into WinHTTP and a ton of other things so apps can know the status of the network. It's also possible, via Group Policy, to configure a different URL for NCSI. This is useful in enterprises which may not have the NCSI URL available to unauthenticated things (eg: the OS) but still has internet access via proxies. It's also possible to disable NCSI, captive portal detection, etc, which is useful on some closed network boxes (eg: some enterprises) but this will cause problems if the machines are ever used on public/walled garden/captive portal networks. The biggest problem I've seen with this comes about where captive portal detection is disabled, a user ends up on a captive portal, tries to hit a website to satisfy the portal, but due to most sites that normal users will try being https these days can't get their session redirected in order to display the portal, so they think "the internet is broken". The NCSI/captive portal detection makes a point of using HTTP so captive portal redirection can work properly.
- deleted 4y ago[deleted]
- bboygravity 4y agoDoesn't windows ignore localhost for Microsoft adresses? I vaguely recall reading an article on that.
- lukeboi 4y agoyep! or do this at the dns level
- tveyben 4y agoNot if they parse the payload of the response Yes if they only use the http status (I Think they rely on the payload…)