Dns Rebinding

DNS rebinding attack to bypass browser same-origin policy and reach IMDS/localhost/internal services: TTL=0 rebind mechanics, rbndr.us/singularity tooling, browser DNS cache pinning, chaining into AWS/GCP/Azure IMDS credential pivot. Use when SSRF is blocked but a victim browser can be induced to make requests, or when a localhost service is exposed. Triggers on: 'dns rebinding', 'rebind', 'DNS TTL 0', 'singularity', 'rbndr', 'localhost bypass via browser', 'imds via browser', 'SSRF via DNS'.

purpleailab d36b13f 8.2 KB Updated

File contents

purpleailab/decepticon/tree/main/packages/decepticon/decepticon/skills/standard/exploit/web/dns-rebinding commit d36b13f363

Frequently asked questions

npx skillmds@latest add purpleailab/dns-rebinding