Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
ID: dbae72a9-877e-5429-92ae-c95b5edc5c52
STIX ID: report--dbae72a9-877e-5429-92ae-c95b5edc5c52
Feed Name: SANS ISC Diary
Threat Score
This note warns that attackers scanning for the cloud metadata service (169.254.169.254) via SSRF can evade IP-based blocklists by using specially crafted hostnames (e.g., 169.254.169.254.nip.io, 169-254-169-254.sslip.io, or dynamic domains from 1u.ms). It recommends checking DNS resolution logs for such hostnames because simple string or IP blocklists are insufficient to prevent these exploitation attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
