Results 1 -
3 of
3
Protecting browsers from DNS rebinding attacks
- In Proceedings of of the 14th ACM Conference on Computer and Communications Security (CCS
, 2007
"... DNS rebinding attacks subvert the same-origin policy of browsers, converting them into open network proxies. Using DNS rebinding, an attacker can circumvent organizational and personal firewalls, send spam email, and defraud pay-per-click advertisers. We evaluate the cost effectiveness of mounting D ..."
Abstract
-
Cited by 32 (8 self)
- Add to MetaCart
DNS rebinding attacks subvert the same-origin policy of browsers, converting them into open network proxies. Using DNS rebinding, an attacker can circumvent organizational and personal firewalls, send spam email, and defraud pay-per-click advertisers. We evaluate the cost effectiveness of mounting DNS rebinding attacks, finding that an attacker requires less than $100 to hijack 100,000 IP addresses. We analyze defenses to DNS rebinding attacks, including improvements to the classic “DNS pinning, ” and recommend changes to browser plug-ins, firewalls, and Web servers. Our defenses have been adopted by plug-in vendors and by a number of open-source firewall implementations.
Cross-Site Request Forgeries: Exploitation and Prevention
"... has fixed the vulnerability described below. Also clarified that our server-side CSRF protection recommendations do not prevent the active network attacks described in [17]. The newest version of this paper can be found at ..."
Abstract
-
Cited by 9 (0 self)
- Add to MetaCart
has fixed the vulnerability described below. Also clarified that our server-side CSRF protection recommendations do not prevent the active network attacks described in [17]. The newest version of this paper can be found at
NO WARRANTY
, 2011
"... The ideas and findings in this report should not be construed as an official DoD position. It is published in the interest of scientific and technical information exchange. ..."
Abstract
- Add to MetaCart
The ideas and findings in this report should not be construed as an official DoD position. It is published in the interest of scientific and technical information exchange.

