logo

DNS rebinding attacks explained: The lookup is coming from inside the house!

ID: d5fafe0d-f31d-5dec-baa9-4784e21a7c66

STIX ID: report--d5fafe0d-f31d-5dec-baa9-4784e21a7c66

Feed Name: GitHub Security Lab

Threat Score
60/100

Date Published: 2025-06-03

Date Updated: 2026-04-27

Author: Jaroslav Lobacevski

...
...

This report explains DNS rebinding attacks and how they can bypass the browser same-origin policy to access local-network or localhost services, then details a Deluge WebUI vulnerability (fixed in v2.2.0) where an unauthenticated path traversal in the /js endpoint allowed arbitrary file reads (exposing configuration including salted SHA1 passwords and sessions); the report shows how DNS rebinding can be used to reach such local services and chain to installing malicious plugins, and concludes with practical mitigations (use HTTPS, strong authentication, Host header validation).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.