CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Captive Portal Detection

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2928

As cited

Copy frozen at (site build).

threat intel

Captive Portal Detection

This article explains how modern operating systems and browsers detect captive portals on public WiFi networks by attempting to access specific HTTP URLs and checking for redirect responses. Different platforms use different detection URLs: Windows checks msftconnecttest.com, Apple uses captive.apple.com, Android and Chrome use generate_204 endpoints, and Firefox uses detectportal.firefox.com. Understanding these detection mechanisms can help network administrators and security analysts recognize benign traffic patterns and assist users who encounter connectivity issues.

Why it matters: Network defenders and SOC analysts should recognize these captive portal detection requests as normal background traffic to avoid false alerts, and IT support staff can use this knowledge to help users manually trigger portal login pages when automatic detection fails.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Captive Portal Detection

This article explains how modern operating systems and browsers detect captive portals on public WiFi networks by attempting to access specific HTTP URLs and checking for redirect responses. Different platforms use different detection URLs: Windows checks msftconnecttest.com, Apple uses captive.apple.com, Android and Chrome use generate_204 endpoints, and Firefox uses detectportal.firefox.com. Understanding these detection mechanisms can help network administrators and security analysts recognize benign traffic patterns and assist users who encounter connectivity issues.

Why it matters: Network defenders and SOC analysts should recognize these captive portal detection requests as normal background traffic to avoid false alerts, and IT support staff can use this knowledge to help users manually trigger portal login pages when automatic detection fails.

VendorsMicrosoftAppleGoogleWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary