<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: [not] Protecting web sites and services from DNS rebinding attacks</title>
	<atom:link href="http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/</link>
	<description>what was</description>
	<pubDate>Wed, 17 Mar 2010 21:49:57 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: top10webhosting</title>
		<link>http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/#comment-30451</link>
		<dc:creator>top10webhosting</dc:creator>
		<pubDate>Mon, 03 Sep 2007 14:30:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/#comment-30451</guid>
		<description>Hmm.. I am getting the following error.  

Please wait for 15 seconds.
f1()
ERROR: Access is denied. 
ERROR: http://1188829961575.jumperz.net/exploits/dnsp3.jsp?address=127.0.0.1
ERROR: 50

What does it mean ?</description>
		<content:encoded><![CDATA[<p>Hmm.. I am getting the following error.  </p>
<p>Please wait for 15 seconds.<br />
f1()<br />
ERROR: Access is denied.<br />
ERROR: <a href="http://1188829961575.jumperz.net/exploits/dnsp3.jsp?address=127.0.0.1" rel="nofollow">http://1188829961575.jumperz.net/exploits/dnsp3.jsp?address=127.0.0.1</a><br />
ERROR: 50</p>
<p>What does it mean ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dmitry</title>
		<link>http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/#comment-30112</link>
		<dc:creator>Dmitry</dc:creator>
		<pubDate>Fri, 03 Aug 2007 19:04:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/#comment-30112</guid>
		<description>This component lets you protect Java web applications from
DNS rebinding: http://www.servletsuite.com/servlets/hostflt.htm</description>
		<content:encoded><![CDATA[<p>This component lets you protect Java web applications from<br />
DNS rebinding: <a href="http://www.servletsuite.com/servlets/hostflt.htm" rel="nofollow">http://www.servletsuite.com/servlets/hostflt.htm</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Weber</title>
		<link>http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/#comment-30109</link>
		<dc:creator>Dan Weber</dc:creator>
		<pubDate>Thu, 02 Aug 2007 18:40:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/#comment-30109</guid>
		<description>This works because jumperz.com's bind is sending back incorrect DNS responses, yes?</description>
		<content:encoded><![CDATA[<p>This works because jumperz.com&#8217;s bind is sending back incorrect DNS responses, yes?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christian Matthies</title>
		<link>http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/#comment-30108</link>
		<dc:creator>Christian Matthies</dc:creator>
		<pubDate>Thu, 02 Aug 2007 18:14:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/#comment-30108</guid>
		<description>Well, keep in mind that the host header can be spoofed with Anti Anti Anti DNS Pinning also. Check out http://christ1an.blogspot.com/2007/07/dns-pinning-explained.html, an article I wrote on this matter a few weeks ago.</description>
		<content:encoded><![CDATA[<p>Well, keep in mind that the host header can be spoofed with Anti Anti Anti DNS Pinning also. Check out <a href="http://christ1an.blogspot.com/2007/07/dns-pinning-explained.html" rel="nofollow">http://christ1an.blogspot.com/2007/07/dns-pinning-explained.html</a>, an article I wrote on this matter a few weeks ago.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: david</title>
		<link>http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/#comment-30103</link>
		<dc:creator>david</dc:creator>
		<pubDate>Thu, 02 Aug 2007 00:25:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/#comment-30103</guid>
		<description>stand: I think that the port-80 limit is just a feature of the jumperz.net demo, though you would probably have to stay on the same port as the original web page.  I'll have to look at the exploit in more detail.</description>
		<content:encoded><![CDATA[<p>stand: I think that the port-80 limit is just a feature of the jumperz.net demo, though you would probably have to stay on the same port as the original web page.  I&#8217;ll have to look at the exploit in more detail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: University Update - Firefox - Protecting web sites and services from DNS rebinding attacks</title>
		<link>http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/#comment-30102</link>
		<dc:creator>University Update - Firefox - Protecting web sites and services from DNS rebinding attacks</dc:creator>
		<pubDate>Thu, 02 Aug 2007 00:23:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/#comment-30102</guid>
		<description>[...]                Contact the Webmaster     Link to Article           firefox Protecting web sites and services from DNS rebinding attacks &#187;  Posted at [...]</description>
		<content:encoded><![CDATA[<p>[...]                Contact the Webmaster     Link to Article           firefox Protecting web sites and services from DNS rebinding attacks &#187;  Posted at [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stand</title>
		<link>http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/#comment-30101</link>
		<dc:creator>stand</dc:creator>
		<pubDate>Wed, 01 Aug 2007 23:14:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/#comment-30101</guid>
		<description>David, it's not immediately apparent to me whether this exploit will relay services that are not hosted on port 80. I don't see why is shouldn't, but the jumperz.net page you link to doesn't work with non-80 ports.</description>
		<content:encoded><![CDATA[<p>David, it&#8217;s not immediately apparent to me whether this exploit will relay services that are not hosted on port 80. I don&#8217;t see why is shouldn&#8217;t, but the jumperz.net page you link to doesn&#8217;t work with non-80 ports.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; Protecting web sites and services from DNS rebinding attacks</title>
		<link>http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/#comment-30100</link>
		<dc:creator>&#187; Protecting web sites and services from DNS rebinding attacks</dc:creator>
		<pubDate>Wed, 01 Aug 2007 21:51:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/#comment-30100</guid>
		<description>[...] Original post by david [...]</description>
		<content:encoded><![CDATA[<p>[...] Original post by david [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
