Professional Webmasters Community
Would you like to react to this message? Create an account in a few clicks or log in to continue.

Exploiting DNSbased Trust Relationships On The Web

Go down

Exploiting DNSbased Trust Relationships On The Web Empty Exploiting DNSbased Trust Relationships On The Web

Post  andry Mon Dec 20, 2010 3:58 am

As Software-as-a-Service becomes an increasingly popular business model, network administrators and application maintainers are left trying to integrate thirdparty sites with their own. A common convention for doing so is to configure DNS servers, creating A or CNAME records pointing to the thirdparty site's server. While this may ease the integration process, many of the clientside web technologies we use make trust decisions based on these DNS records, and records pointed at poorly configured systems can be used to leak data and compromise even the strongest of web applications.These vulnerabilities are remarkably common, and many have not been formally addressed. This paper will include demonstrations of attacks on highprofile websites, as well as a discussion on mitigation methods.

Download [urlhttp://skeptikal.org/repository/one_in_every_family.pdf]PDF[/url]

Check also: Cross-subdomain Cookie Attacks
andry
andry
Moderator
Moderator

Posts : 467
Join date : 2010-05-07

Back to top Go down

Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum