2 ms·
That's the essence of a DNS rebinding attack, which can be used to bypass server-side request forgery vulnerability mitigations.
by throwawaymath 7y ago
That's the essence of a DNS rebinding attack, which can be used to bypass server-side request forgery vulnerability mitigations.
- znep 7y agoI might be wrong, it was a long time ago, but IIRC a different DNS rebinding attack was actually part of the reason this behavior was introduced to the URL class, to help protect against such attacks in Java Applets.