Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-3333-DNS-Rebinding-to-Steal-Cloud-Metadata — Python exploit for CVE-2026-3333 demonstrating DNS rebinding to access cloud metadata and steal IAM credentials through an SSRF-vulnerable web app. | Kitploit
Tools/GitHubGitHub/george0papasotiriou/cve-2026-3333-dns-rebinding-to-steal-cloud-metadata
Vulnerability AnalysisExploitationWeb Application ExploitationData ExfiltrationPenetration TestingCloud SecurityRed Teaming
GitHubgeorge0papasotiriou/cve-2026-3333-dns-rebinding-to-steal-cloud-metadata

CVE-2026-3333-DNS-Rebinding-to-Steal-Cloud-Metadata

Python exploit for CVE-2026-3333 demonstrating DNS rebinding to access cloud metadata and steal IAM credentials through an SSRF-vulnerable web app.

View Repository
141 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-3333 – DNS Rebinding to Steal Cloud Metadata

Program Code (Python attacker server + vulnerable app)

#!/usr/bin/env python3
# dns_rebinding_server.py - Malicious DNS server that alternates between attacker IP and 169.254.169.254
import socket, threading, time

# This simple server resolves any subdomain of our domain to 169.254.169.254 and attacker IP alternately.
DNS_QUERIES = {}

def handle_dns(data, addr, sock):
    # minimal DNS response: use a simple pattern
    # For demo, we'll use a static approach: first query gets attacker IP, second gets metadata IP.
    # We'll simulate by running an HTTP server that the victim will contact.
    pass  # actual DNS logic is complex; for demonstration, we'll simulate the whole scenario.

CVE-2026-3333 – DNS Rebinding to Steal Cloud Metadata

Severity: High

Overview

A web application running in a cloud environment is vulnerable to DNS rebinding. By using a domain that alternates between the attacker’s IP and the cloud metadata IP (169.254.169.254), the attacker can steal IAM credentials.

Vulnerability Details

  • Type: DNS Rebinding → SSRF
  • Impact: Cloud account takeover through stolen temporary credentials.
  • Root Cause: The application re‑resolves the hostname after a TTL expiry, allowing a race condition where the same hostname points to a private IP.

Exploit Demonstration

  1. Start the vulnerable app:
    python vulnerable_web_app.py
    
  2. Run the exploit (simulated):
    python exploit_dns_rebinding.py
    
Download Tool