Skip to content
← LibraryTechnique entry
DNS-REBINDINGLateral Movement

DNS Rebinding

Attacker-controlled DNS responds with short-TTL A records that flip from attacker IP to internal RFC1918 IPs — victim browser then talks to internal services via the attacker page.

§ Where this technique fits

DNS-REBINDING is catalogued under the Lateral Movement tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 4 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Default Credentials
    W-AUTH-DEFAULT · Credential Access
    seen 1×