Web Hack List

Collected research

Account Takeover due to DNS Rebinding

Examines a login-token handoff that continues to trust a custom domain after its DNS destination changes. The owner verifies the domain, obtains TLS credentials and repoints its records; a subsequent authentication flow sends a redeemable token to the owner’s server. The case includes a DNS-switching helper for testing the lifetime of domain trust.

Record

Researcher
Yashar Shahinzadeh
Published by
Voorivex
Date
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Yashar Shahinzadeh, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .