The Art of DNS Rebinding

No ratings

Presented at InfoSecurityEurope 2019 by

So much of the information security world is reactionary… it took years for credential relaying to see any sort of solution and it still isn’t completely fixed. There are web servers and services that allow plain text HTTP communication and the state of email encryption is just laughable. Forget, “If it ain’t broke, don’t fix it”, vendors prefer, “If it is broke, ignore it.” DNS rebinding is not something that we can continue to ignore, it needs to be addressed today, which is why this session will introduce my latest tool, Dolos.Learning Outcomes:Use DNS rebinding to circumvent the browser same-origin policy to bypass perimeter firewallsMitigate DNS rebinding at the application level (e.g. via HTTP request validation)Mitigate DNS rebinding at the network level (e.g. through DNS response filtering)Install and configure the Dolos framework on their own systemDevelop and execute attacks through the Dolos framework