4 ms·
Dnspooq Vulnerabilities in Dnsmasq
- captn3m0 6y ago>The rules ofthe game here are that we can trick the victim in to accessing an attacker-controlled website, causing hisdevice to execute malicious JavaScript code. >To make the browser generate many DNS queries, we used AJAX requests (viaXMLHttpRequest). So they used JS code execution on the browser to achieve JS code execution? There are ways of triggering dozens of sustained DNS requests without JS in your browser, but this is just lazy alarmist research. To the researchers: Please explain your cute logo and name at the bottom of your website, not at the very top.