Web Hack List

Other nomination

Effects of DNS Rebinding On IE's Trust Zones

An email from natron chaining DNS rebinding into NTLM theft. Windows XP's NBNS transaction IDs start at 0x8000 and step by one to four, so a Java applet can spam predictable spoofed responses; Active Directory DNS also accepts unauthenticated update records. Either route places an attacker host in IE's Intranet or Trusted zone, where NTLM-over-HTTP authenticates automatically.

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.