Ask the Expert

How to prevent anti-DNS pinning attacks

How do you prevent anti-DNS pinning in a Web application?

    Requires Free Membership to View

Anti-DNS pinning, also known as DNS rebinding, is more of an attack against the end user. To say "my Web application is vulnerable to anti-DNS pinning" would not make sense. The attack takes advantage of deficiencies in the Web browser and fools it into executing JavaScript code that makes hidden Web requests without the user's knowledge.

One defense from the Web application side is to verify that the HTTP host header is correct; however, there are attacks to circumvent this as well, depending on which Web browser the victim is using. Users will likely always be vulnerable to anti-DNS pinning until the browsers (and other client-side components such as Flash) fix the issue.

Software testing resources:
CSRF attack vector with Ajax serialization

How to integrate security into the SDLC (Featured Topic)

How to counter cross-site scripting (XSS) attacks (Featured Topic)

If I'm the owner of a Web application, say Gmail, the best way to protect my users from the effects of anti-DNS pinning attacks is to eliminate cross-site request forgery (CSRF or XSRF) vulnerabilities in my application. While this doesn't prevent anti-DNS pinning itself, it prevents an anti-DNS pinning attack from being able to target users of my particular Web application.

-- Chris Eng, director of security services at Veracode, contributed to this response.

This was first published in December 2007

There are Comments. Add yours.

 
TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: