Detailedlikelihood: Highseverity: Very HighDraft

CAPEC-275DNS Rebinding

Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
Very High

Description

An adversary serves content whose IP address is resolved by a DNS server that the adversary controls. After initial contact by a web browser (or similar client), the adversary changes the IP address to which its name resolves, to an address within the target organization that is not publicly accessible. This allows the web browser to examine this internal address on behalf of the adversary.

Related weaknesses· 1

CWE-350

Related attack patterns· 1

CAPEC-194 (ChildOf)

Exploits1

TypeTargetConfidenceTier
WeaknessReliance on Reverse DNS Resolution for a Security-Critical Actioncwe-350100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
DNS Cache Poisoning
CAPEC
DNS Blocking
CAPEC
DNS Spoofing
CAPEC
DNS Zone Transfers
CAPEC
DNS Domain Seizure
CAPEC
Using Alternative IP Address Encodings
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.