daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (4845B)


      1 ---
      2 title: "DNS Rebinding"
      3 topic: "DNS Rebinding"
      4 topicSlug: "dns-rebinding"
      5 sourcePath: "DNS Rebinding/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/DNS%20Rebinding/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # DNS Rebinding
     12 
     13 > DNS rebinding changes the IP address of an attacker controlled machine name to the IP address of a target application, bypassing the [same-origin policy](https://developer.mozilla.org/en-US/docs/Web/Security/Same-origin_policy) and thus allowing the browser to make arbitrary requests to the target application and read their responses.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Methodology](#methodology)
     19 * [Protection Bypasses](#protection-bypasses)
     20     * [0.0.0.0](#0000)
     21     * [CNAME](#cname)
     22     * [localhost](#localhost)
     23 * [References](#references)
     24 
     25 ## Tools
     26 
     27 * [nccgroup/singularity](https://github.com/nccgroup/singularity) - A DNS rebinding attack framework.
     28 * [rebind.it](http://rebind.it/) - Singularity of Origin Web Client.
     29 * [taviso/rbndr](https://github.com/taviso/rbndr) - Simple DNS Rebinding Service
     30 * [taviso/rebinder](https://lock.cmpxchg8b.com/rebinder.html) - rbndr Tool Helper
     31 
     32 ## Methodology
     33 
     34 **Setup Phase**:
     35 
     36 * Register a malicious domain (e.g., `malicious.com`).
     37 * Configure a custom DNS server capable of resolving `malicious.com` to different IP addresses.
     38 
     39 **Initial Victim Interaction**:
     40 
     41 * Create a webpage on `malicious.com` containing malicious JavaScript or another exploit mechanism.
     42 * Entice the victim to visit the malicious webpage (e.g., via phishing, social engineering, or advertisements).
     43 
     44 **Initial DNS Resolution**:
     45 
     46 * When the victim's browser accesses `malicious.com`, it queries the attacker's DNS server for the IP address.
     47 * The DNS server resolves `malicious.com` to an initial, legitimate-looking IP address (e.g., 203.0.113.1).
     48 
     49 **Rebinding to Internal IP**:
     50 
     51 * After the browser's initial request, the attacker's DNS server updates the resolution for `malicious.com` to a private or internal IP address (e.g., 192.168.1.1, corresponding to the victim’s router or other internal devices).
     52 
     53 This is often achieved by setting a very short TTL (time-to-live) for the initial DNS response, forcing the browser to re-resolve the domain.
     54 
     55 **Same-Origin Exploitation:**
     56 
     57 The browser treats subsequent responses as coming from the same origin (`malicious.com`).
     58 
     59 Malicious JavaScript running in the victim's browser can now make requests to internal IP addresses or local services (e.g., 192.168.1.1 or 127.0.0.1), bypassing same-origin policy restrictions.
     60 
     61 **Example:**
     62 
     63 1. Register a domain.
     64 2. [Setup Singularity of Origin](https://github.com/nccgroup/singularity/wiki/Setup-and-Installation).
     65 3. Edit the [autoattack HTML page](https://github.com/nccgroup/singularity/blob/master/html/autoattack.html) for your needs.
     66 4. Browse to `http://rebinder.your.domain:8080/autoattack.html`.
     67 5. Wait for the attack to finish (it can take few seconds/minutes).
     68 
     69 ## Protection Bypasses
     70 
     71 > Most DNS protections are implemented in the form of blocking DNS responses containing unwanted IP addresses at the perimeter, when DNS responses enter the internal network. The most common form of protection is to block private IP addresses as defined in RFC 1918 (i.e. 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16). Some tools allow to additionally block localhost (127.0.0.0/8), local (internal) networks, or 0.0.0.0/0 network ranges.
     72 
     73 In the case where DNS protection are enabled (generally disabled by default), NCC Group has documented multiple [DNS protection bypasses](https://github.com/nccgroup/singularity/wiki/Protection-Bypasses) that can be used.
     74 
     75 ### 0.0.0.0
     76 
     77 We can use the IP address 0.0.0.0 to access the localhost (127.0.0.1) to bypass filters blocking DNS responses containing 127.0.0.1 or 127.0.0.0/8.
     78 
     79 ### CNAME
     80 
     81 We can use DNS CNAME records to bypass a DNS protection solution that blocks all internal IP addresses.
     82 Since our response will only return a CNAME of an internal server,
     83 the rule filtering internal IP addresses will not be applied.
     84 Then, the local, internal DNS server will resolve the CNAME.
     85 
     86 ```bash
     87 $ dig cname.example.com +noall +answer
     88 ; <<>> DiG 9.11.3-1ubuntu1.15-Ubuntu <<>> example.com +noall +answer
     89 ;; global options: +cmd
     90 cname.example.com.            381     IN      CNAME   target.local.
     91 ```
     92 
     93 ### localhost
     94 
     95 We can use "localhost" as a DNS CNAME record to bypass filters blocking DNS responses containing 127.0.0.1.
     96 
     97 ```bash
     98 $ dig www.example.com +noall +answer
     99 ; <<>> DiG 9.11.3-1ubuntu1.15-Ubuntu <<>> example.com +noall +answer
    100 ;; global options: +cmd
    101 localhost.example.com.            381     IN      CNAME   localhost.
    102 ```
    103 
    104 ## References
    105 
    106 * [How Do DNS Rebinding Attacks Work? - NCC Group - April 9, 2019](https://github.com/nccgroup/singularity/wiki/How-Do-DNS-Rebinding-Attacks-Work%3F)