Q

How to prevent anti-DNS pinning attacks

Application security measures can prevent anti-DNS pinning, aka DNS rebinding. Expert Chris Wysopal explains how to protect end users from this attack.

How do you prevent anti-DNS pinning in a Web application?

Anti-DNS pinning, also known as DNS rebinding, is more of an attack against the end user. To say "my Web application is vulnerable to anti-DNS pinning" would not make sense. The attack takes advantage of deficiencies in the Web browser and fools it into executing JavaScript code that makes hidden Web requests without the user's knowledge.

One defense from the Web application side is to verify that the HTTP host header is correct; however, there are attacks to circumvent this as well, depending on which Web browser the victim is using. Users will likely always be vulnerable to anti-DNS pinning until the browsers (and other client-side components such as Flash) fix the issue.

Software testing resources:
CSRF attack vector with Ajax serialization

How to integrate security into the SDLC (Featured Topic)

How to counter cross-site scripting (XSS) attacks (Featured Topic)

If I'm the owner of a Web application, say Gmail, the best way to protect my users from the effects of anti-DNS pinning attacks is to eliminate cross-site request forgery (CSRF or XSRF) vulnerabilities in my application. While this doesn't prevent anti-DNS pinning itself, it prevents an anti-DNS pinning attack from being able to target users of my particular Web application.

-- Chris Eng, director of security services at Veracode, contributed to this response.

This was first published in December 2007

Dig deeper on Building security into the SDLC (Software development life cycle)

Pro+

Features

Enjoy the benefits of Pro+ membership, learn more and join.

Have a question for an expert?

Please add a title for your question

Get answers from a TechTarget expert on whatever's puzzling you.

You will be able to add details on the next page.

0 comments

Oldest 

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to:

-ADS BY GOOGLE

SearchSOA

TheServerSide

SearchCloudApplications

SearchAWS

SearchBusinessAnalytics

SearchFinancialApplications

SearchHealthIT

Close