DEF CON 27 - State of DNS Rebinding Attack & Prevention Techniques and the Singularity of Origin @HackersOnBoard
DEF CON 27 - State of DNS Rebinding Attack & Prevention Techniques and the Singularity of Origin  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 4 days ago
Do you want to know how you can exploit DNS rebinding 10x faster, bypass prevention mechanisms, interactively browse the victim's internal network, and automate the whole process during your next red team exercise?

This talk will teach you how and give you an easy-to-use tool to do it.

First, we will cover in detail the subtleties that make DNS rebinding attacks more effective in practice, including techniques and operational conditions that make it faster and more reliable. We'll also explain how to bypass commonly recommended security controls, dispelling attack and defense misconceptions that have been disseminated in blogs and social media posts.

This talk will include a number of demos using Singularity, our open source DNS rebinding attack framework that includes all the parts you need to get started pwning today, including:

Remote code execution and exfiltration payloads for common dev tools and software
Practical scanning and automation techniques to maximize the chance of controlling targeted services
We'll also show an interesting post-exploitation technique that allows you to browse a victim browser network environment via the attacker's browser without the use of HTTP proxies.

You'll leave this talk with the knowledge and tools to immediately start finding and exploiting DNS rebinding bugs.

Talk by Gerald Doussot
DEF CON 27 - State of DNS Rebinding Attack & Prevention Techniques and the Singularity of OriginDEF CON 27 - droogie - Go NULL Yourself or How I Learned to Start Worrying While Getting FinedDEF CON 27 - XiaoHuiHui - All the 4G Modules Could Be HackedDEF CON 27 - Leon Jacobs - Meticulously Modern Mobile ManipulationsDEF CON 27 - Backdooring Hardware Devices By Injecting Malicious Payloads On MicrocontrollersDEF CON 27 - Patrick Wardle - Harnessing Weapons of Mac DestructionDEF CON 27 - How You Can Buy ATandT T-Mobile and Sprint Real-Time Location Data on the Black MarketDEF CON 27 - Pedro Cabrera Camara - SDR Against Smart TVs URL and Channel Injection AttacksBlack Hat USA 2018 - Pestilential Protocol How Unsecure HL7 Messages Threaten Patient LivesEdge Side Include Injection Abusing Caching Servers into SSRF and Transparent Session HijackingEfail Breaking S MIME and OpenPGP Email Encryption using Exfiltration ChannelsBlack Hat USA 2018 - Exploitation of a Modern Smartphone Baseband
HackersOnBoard |

DEF CON 27 - State of DNS Rebinding Attack & Prevention Techniques and the Singularity of Origin

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER