random dross

Web security and beyond...

Browse by Tags

Tagged Content List
  • Blog Post: Current Thoughts on DNS Rebinding

    RSnake and Dan Kaminsky have been talking about session fixation via DNS Rebinding . As you may recall, an attacker can't abuse your Foo.com cookies in a rebinding attack, though they can walk your browser around Foo.com content and control the session. The gist of what these guys are talking about is...
  • Blog Post: Pinning / Rebinding / Quick-Swap DNS Links

    A group at Stanford has been researching these issues and recently published Protecting Browsers from DNS Rebinding Attacks . Also, Dan Kaminski has published his slides from Blackhat 2007, Black Ops 2007: Design Reviewing The Web .
  • Blog Post: Notes on DNS Pinning

    Christian Matthies has an excellent writeup on DNS Pinning (with diagrams!) If you're tuned into web app security you've probably noticed a lot of discussion around Anti DNS Pinning a.k.a. DNS Rebinding a.k.a. Quick-Swap DNS lately. You're likely to see a lot more such discussion after this year's Blackhat...
Page 1 of 1 (3 items)