Collected research
Circumventing DNS Pinning for XSS
Circumventing DNS Pinning for XSS ha.ckers.org web application security lab
Write-up of Martin Johns' finding that a browser drops its pinned DNS entry when the origin server stops answering. Change the record, then firewall or shut the host, and the browser re-resolves, letting script read and write internal RFC1918 hosts across the same-origin boundary. It is limited to IP-addressable hosts, not virtual hosts.
Record
- Document
- Circumventing DNS Pinning for XSS ha.ckers.org web application security lab
- Published by
- ha.ckers.org
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of ha.ckers.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .