New Techniques for Split-Second DNS Rebinding

...In this talk, I will present two new techniques that can be used to achieve reliable, split-second DNS rebinding in Chrome, Edge, and Safari on hosts with IPv6 access, along with a method to bypass Chrome’s restrictions on requests to the local network. I will also walk through a real-world attack against a web application resulting in AWS credentials to demonstrate how achievable rebinding attacks can be.... By: Daniel Thatcher Full Abstract and Presentation Materials: #new-techniques-for-split-second-dns-rebinding-35619
Back to Top