3 ms·
Perhaps the biggest revelation from this is that Firefox doesn't implement rebinding protection, and that CGNAT DNS responses aren't dropped by most resolvers.
by dvzk 4y ago
Perhaps the biggest revelation from this is that Firefox doesn't implement rebinding protection, and that CGNAT DNS responses aren't dropped by most resolvers. Host validation is preferable anyway [1] but the second problem still has bad implications.
1. https://github.com/nccgroup/singularity/wiki/Preventing-DNS-Rebinding-Attacks https://github.com/nccgroup/singularity/wiki/Preventing-DNS-...