New Techniques for Split-Second DNS Rebinding

Описание к видео New Techniques for Split-Second DNS Rebinding

...In this talk, I will present two new techniques that can be used to achieve reliable, split-second DNS rebinding in Chrome, Edge, and Safari on hosts with IPv6 access, along with a method to bypass Chrome's restrictions on requests to the local network. I will also walk through a real-world attack against a web application resulting in AWS credentials to demonstrate how achievable rebinding attacks can be....

By: Daniel Thatcher

Full Abstract and Presentation Materials:
https://www.blackhat.com/eu-23/briefi...

Комментарии

Информация по комментариям в разработке