3 ms·
Wouldn't it be better to put "confetti" -- the API key as part of the domain name? That way, the key would be leaked without any required clicks due to the DNS
by jesprenj 2y ago
Wouldn't it be better to put "confetti" -- the API key as part of the domain name? That way, the key would be leaked without any required clicks due to the DNS prefetching by the browser.
- reassess_blind 2y agoHow would you own the server if you don't know what the domain is going to be? Perhaps I don't understand. Edit: Ah, wildcard subdomain? Does that get prefetched in Slack? Pretty terrible if so.
- MobiusHorizons 2y agoI think if you make the key a subdomain and you run the dns server for that domain it should be possible to make it work ie: secret.attacker-domain.com will end up asking the dns for attacker-domain.com about secret.attacker-domain.com, and that dns server can log the secret and return an ip
- jerjerjer 2y agoWildcard dns would work: *.example.com. 14400 IN A 1.2.3.4 after that just collect webserver logs.
- reassess_blind 2y agoYeah, assuming Slack does prefetch these links that makes the attack significantly easier and faster to carry out.
- jesprenj 2y agoI actually meant DNS prefetching, not HTTP prefetching. I don't think browsers will prefetch (make HTTP GET requests before they are clicked) links by default (maybe slack does to get metadata), but they quite often prefetch the DNS host records as soon as an "a href" appears. In case of DNS prefetching, a wildcard record wouldn't be needed, you just need to control the nameservers of the domain and enable query logging. But I'm not sure how do browsers decide what links to DNS prefetch, maybe it's not even possible for links generated with JS or something like that ... I'm just guessing.
- gcollard- 2y agoSubdomains.