nccgroup / nccgroup/singularity

Required Server For 3 Second DNS Rebinding

Open
#69 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
JavaScript
Stars
1.3k
Forks
161
PR merge metrics
No merged PRs in 30d

Description

I would like to understand the exact requirements and conditions for the MA (Multiple Answers) DNS rebinding strategy to successfully complete a rebinding attack within approximately 3 seconds.

Specifically, what assumptions need to hold (browser caching, TTL behavior, resolver behavior, number of queries, etc.) for the MA strategy to reliably achieve a rebinding window of around 3 seconds?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the MA (Multiple Answers) DNS rebinding strategy and its attack flow. Document the assumptions about browser caching, TTL behavior, resolver behavior, and query count that would be required for an approximately three-second rebinding window, and state whether those conditions make the timing reliable.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
networking, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.