{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/dns-security/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["initial-access","dns-security","network-monitoring","threat-detection"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eDNS rebinding is an attack technique used to circumvent browser-based security controls, such as the Same-Origin Policy, by manipulating the DNS resolution process. An attacker-controlled, publicly registered domain is initially configured to resolve to an attacker-owned public IP address to establish trust or deliver malicious payloads. Subsequently, the DNS record is updated to resolve to an internal, private, loopback, or link-local address (RFC1918, etc.). When a victim's client - typically a browser - attempts to connect, the resolution shifts to the internal address, effectively allowing the attacker's code to interact with internal resources, probe services, or perform unauthorized actions as if it were operating from within the trusted network. This behavior is highly effective for pivoting through browsers or applications to reach services that assume they are only accessible to local users. Defenders must monitor for rapid shifts between public and private IP responses to prevent unauthorized internal service exploitation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker registers a public domain name and sets up an authoritative DNS server.\u003c/li\u003e\n\u003cli\u003eAttacker configures the domain to resolve to an attacker-controlled public IP address.\u003c/li\u003e\n\u003cli\u003eVictim's browser or application is lured to the attacker-controlled domain, typically via phishing or drive-by compromise.\u003c/li\u003e\n\u003cli\u003eThe victim's client performs a DNS query for the attacker's domain and receives the public IP address.\u003c/li\u003e\n\u003cli\u003eThe attacker updates the DNS record on the authoritative server to point to an internal or loopback address (e.g., 127.0.0.1 or 192.168.x.x).\u003c/li\u003e\n\u003cli\u003eThe victim's client performs a subsequent DNS query or the original resolution's TTL expires, forcing a re-query.\u003c/li\u003e\n\u003cli\u003eThe client receives the internal IP address and attempts to connect, bypassing browser security policies.\u003c/li\u003e\n\u003cli\u003eThe internal service receives the request, potentially leaking sensitive data or allowing state modification due to the implied trust of a local origin.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eDNS rebinding allows attackers to perform unauthorized actions against internal services, bypass firewall perimeters, and exfiltrate data from protected internal network segments. By successfully rebinding a domain, an attacker can turn a victim's web browser into a proxy for internal scanning, service exploitation, or sensitive data retrieval. This impact is significant in environments relying on IP-based trust or lacking robust authentication for internal web-based services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy DNS telemetry monitoring to detect rapid public-to-private IP resolution transitions as defined in the detection criteria.\u003c/li\u003e\n\u003cli\u003eEstablish a baseline for split-horizon DNS, VPN, and service discovery traffic to tune out legitimate internal infrastructure naming conventions.\u003c/li\u003e\n\u003cli\u003eEnsure that internal web-based services validate the 'Host' header to reject requests that do not match the expected internal hostname.\u003c/li\u003e\n\u003cli\u003eImplement outbound DNS filtering to prevent clients from resolving arbitrary external domains if direct egress is not required for business operations.\u003c/li\u003e\n\u003cli\u003eValidate that DNS sensor placement is positioned to see endpoint-to-resolver traffic rather than upstream recursive resolver activity to ensure client-specific attribution.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T00:44:21Z","date_published":"2026-08-26T00:44:21Z","id":"https://feed.craftedsignal.io/briefs/2026-08-dns-rebinding-detection/","summary":"Attackers leverage DNS rebinding to bypass security boundaries by causing a public domain to resolve to internal, loopback, or private IP addresses, enabling unauthorized access to protected internal services.","title":"Detection of DNS Rebinding via Public-to-Private Resolution Patterns","url":"https://feed.craftedsignal.io/briefs/2026-08-dns-rebinding-detection/"}],"language":"en","title":"CraftedSignal Threat Feed - Dns-Security","version":"https://jsonfeed.org/version/1.1"}