I’ve been toying around a little with DNS rebinding code lately, with some mixed results. Firstly, Java fixed their DNS rebinding issues (although it is my opinion they are still vulnerable, just in a different way - I talked with Dan Kamins... 続きを読む
2007/10/10 DNS Rebinding (Anti DNS Pinning) セキュリティホールmemoに、"Protecting Browsers from DNS Rebinding Attacks" という論文が紹介されていた。ブラウザ、Java、Flashが名前解決をごまかされないように、DNS Pinning(サーバにアクセス出来る限り、... 続きを読む