logo

Captive Portal Detection, (Tue, Jul 21st)

ID: cd920733-686d-508c-b632-12ab6ed19ef5

STIX ID: report--cd920733-686d-508c-b632-12ab6ed19ef5

Feed Name: SANS ISC Diary

Date Published: 2026-07-21

Date Updated: 2026-07-21

...
...

This note describes how operating systems and browsers detect captive portals by requesting specific HTTP probe URLs (e.g., Windows: http://www.msftconnecttest.com/connecttest.txt; Apple: http://captive.apple.com/hotspot-detect.html; Android: http://connectivitycheck.android.com/generate_204; Chrome: http://www.gstatic.com/generate_204; Firefox: http://detectportal.firefox.com/canonical.html) and explains that these requests are normal network behavior used to detect and redirect to splash/login pages rather than indicators of an attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.