New Techniques for Split-Second DNS Rebinding
HTML-код
- Опубликовано: 2 апр 2024
- ...In this talk, I will present two new techniques that can be used to achieve reliable, split-second DNS rebinding in Chrome, Edge, and Safari on hosts with IPv6 access, along with a method to bypass Chrome's restrictions on requests to the local network. I will also walk through a real-world attack against a web application resulting in AWS credentials to demonstrate how achievable rebinding attacks can be....
By: Daniel Thatcher
Full Abstract and Presentation Materials:
www.blackhat.c...