Web Hack List

Collected research

DNS Rebinding on Java Applets

Java 6 exposed the Packages object to every browser, not just those with LiveConnect, so a JavaScript-instantiated applet runs in the JavaScriptProtectionDomain tied to the calling page's host. Rebinding that host to another IP extends Kanatoko Anvil's Firefox-only 2007 DNS rebinding attack to all browsers, letting the applet open sockets to the victim's site and steal cookies.

Record

Researcher
Stefano Di Paola
Published by
blog.mindedsecurity.com
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Stefano Di Paola, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .