4 ms·
> The simple fix is to replace it with '.dell.com', but they didn't do that. That would be, if it were not for... $ dig localhost.dell.com ; <<>> DiG 9.9.5-3
by mwh12 11y ago
> The simple fix is to replace it with '.dell.com', but they didn't do that.
That would be, if it were not for...
$ dig localhost.dell.com
; <<>> DiG 9.9.5-3ubuntu0.5-Ubuntu <<>> localhost.dell.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 56836
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4000
;; QUESTION SECTION:
;localhost.dell.com. IN A
;; ANSWER SECTION:
localhost.dell.com. 462 IN A 127.0.0.1
- baby 11y agoany explanation on that?
- mwh12 11y agoEssentially, there's a public DNS A record that maps a Dell subdomain to your local machine's IP, namely localhost.dell.com to 127.0.0.1 An attacker who can either abuse an already running local webserver (like Apache configured to listen to *:80) or start up a locally running webserver (using something like python's SimpleHTTPServer) can serve their content under a Dell subdomain. This requires some sort of local filesystem privileges or potentially RCE, but if the original commenter is correct, this can be pivoted to SYSTEM RCE.