Web Hack List

Collected research

Stuffing Javascript into DNS names

SkullSecurity » Blog Archive » Stuffing Javascript into DNS names

DNS responses are almost never filtered, so the dnsxss tool answers CNAME, MX, TXT and NS lookups with JavaScript. Three sites taken from a single Google query all rendered the injected script, and the post argues the same back channel should reach SQL injection and, more widely, reverse-DNS records displayed in firewalls, proxies and logs.

Record

Document
SkullSecurity » Blog Archive » Stuffing Javascript into DNS names
Researcher
Ron Bowes
Published by
skullsecurity.org
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Ron Bowes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .