Web Hack List

Collected research

DNS Rebinding Headless Browsers

Analytics backends that fetch back submitted Referer URLs do so with headless Chrome running on AWS. An image served with a Content-Length larger than the file stops the load event firing so the browser stays for minutes, long enough to DNS-rebind the attacker domain onto 169.254.169.254, read the instance metadata endpoint and exfiltrate temporary IAM credentials.

Record

Researcher
Alexandre Kaskasoli
Published by
MWR Labs
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Alexandre Kaskasoli, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .