CAPEC 275 DNS Rebinding

Draft Detailed High Risk
Severity Very High

Description

An adversary serves content whose IP address is resolved by a DNS server that the adversary controls. After initial contact by a web browser (or similar client), the adversary changes the IP address to which its name resolves, to an address within the target organization that is not publicly accessible. This allows the web browser to examine this internal address on behalf of the adversary.

Attack Execution Flow

5

Mitigations

3

Consequences

Relationships

Resources Required

1