Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support for cnames #45

Open
0ca opened this issue Jan 11, 2019 · 1 comment
Open

Support for cnames #45

0ca opened this issue Jan 11, 2019 · 1 comment
Assignees
Labels
enhancement New feature or request
Milestone

Comments

@0ca
Copy link

0ca commented Jan 11, 2019

Hello,

I was wondering if it would be possible to add support to rebind a domain to a cname. That would allow an attacker to access some internal hosts without knowing the internal IP address, p.e. wiki.companydomain.com.

This technique is described in this paper:
https://crypto.stanford.edu/dns/dns-rebinding.pdf

Spidering the Intranet. 
The attacker need not specify 
the target machine by IP address. Instead, the attacker
can guess the internal host name of the target, for example
hr.corp.company.com, and rebind attacker.com to a CNAME
record pointing to that host name. The client’s own recursive DNS resolver will complete the resolution and return
the IP address of the target. Intranet host names are often
guessable and occasionally disclosed publicly [30, 9]. This
technique obviates the need for the attacker to scan IP addresses to find an interesting target but does not work with
the multiple A record technique described in Section 3.1.
@serain serain self-assigned this Jan 14, 2019
@serain serain added this to the 0.2.0-alpha milestone Jan 14, 2019
@serain
Copy link
Collaborator

serain commented Jan 14, 2019

Definitely. I'll look into this.

@serain serain added the enhancement New feature or request label Jan 14, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants