Collected research
Stuffing Javascript into DNS names
SkullSecurity » Blog Archive » Stuffing Javascript into DNS names
DNS responses are almost never filtered, so the dnsxss tool answers CNAME, MX, TXT and NS lookups with JavaScript. Three sites taken from a single Google query all rendered the injected script, and the post argues the same back channel should reach SQL injection and, more widely, reverse-DNS records displayed in firewalls, proxies and logs.
Record
- Document
- SkullSecurity » Blog Archive » Stuffing Javascript into DNS names
- Researcher
- Ron Bowes
- Published by
- skullsecurity.org
- Topic
- Server
In the archive
Related sources
- miXSS Whitepaper
Tags
This page is the archive's own catalogue record. The research is the work of Ron Bowes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .