Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Go on....


DNS rebinding attacks is probably one of them.


Browsers will need to update their same-origin policy so that a change in IP address will block same requesting a different site under a different name.


DNS rebinding attacks also work in non-browser environments like SSRF attacks.


This would mean that long-lived single page web apps would need to be hard-refreshed every once in a while when, through no fault of the app developer, all the IP addresses that their domain name resolves to have rotated.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: