Domain name

When the SSRF target is supplied as a hostname rather than a literal IP, a second layer appears between the string and the socket: name resolution. A validator inspects the hostname as text, but the HTTP client hands that name to a resolver and connects to whatever address comes back, possibly at a different moment and possibly after Unicode processing has rewritten it. The two pages here exploit that layer.

  • DNS rebinding attacks the timing of resolution. A name the attacker controls answers with a public address when the validator resolves it, then with 127.0.0.1 or a metadata IP when the client connects, so one hostname passes the check and hits an internal service.
  • Internationalized domain attacks the text of the hostname. Unicode labels, punycode, and normalization let a name read as an allowed host to one comparison and resolve as an attacker host to another.

Both widen the same gap the whole Authority subtree targets, between the host a filter sees and the host the request reaches, but they do it at the naming layer rather than through raw IP encodings.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more