Top 10 winner
DNS Rebinding (3-part series)
A worked scenario for combining persistent cookies with DNS rebinding: the attacker's site plants a cookie carrying an XSS payload, forces a browser restart to release the DNS pin, then rebinds to an intranet address. The intranet server ignores the wrong Host header, reflects the cookie and runs the payload. Mitigations: TLS, host-header checks, clearing cookies on exit.
In the archive
Related sources
- DNS Rebinding for Scraping and Spamming
- Session Fixation Via DNS Rebinding
- Author’s follow-up explanation
Tags
This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.