Web Hack List

Collected research

Circumventing DNS Pinning for XSS

Circumventing DNS Pinning for XSS ha.ckers.org web application security lab

Write-up of Martin Johns' finding that a browser drops its pinned DNS entry when the origin server stops answering. Change the record, then firewall or shut the host, and the browser re-resolves, letting script read and write internal RFC1918 hosts across the same-origin boundary. It is limited to IP-addressable hosts, not virtual hosts.

Record

Document
Circumventing DNS Pinning for XSS ha.ckers.org web application security lab
Published by
ha.ckers.org
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of ha.ckers.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .