It's common sense that DNS query packet can be used to establish convert channels. But in my experiment of DNS query reflection, where I send out DNS queries with spoofed source IP and MAC address to primary DNS server, the victim machines don't receive any response from the DNS server.
Could it be that my spoofed packets are recognized and discarded by the hotspot? But I'm really confused how such recognition would be possible, given the forged MAC.
My experiment environment is a hotspot system over DD-WRT router.