<?xml version="1.0"?>
<rss version="2.0">
<channel>

  
<title>Mark Goodwin&#039;s Blog - Does Firefox implement DNS Pinning?</title>
<link>http://directwebremoting.org/blog/mark/2007/07/19/does_firefox_implement_dns_pinning.html</link>
<description> I&#039;ve been playing around with DNS pinning over the past few weeks; mainly on how the presence of proxies affects the story, which Rsnake and Portswigger beat  me to (nice work guys), but also on various other bits.    Something that&#039;s caught my ...</description>
<language>en</language>
<managingEditor>Mark Goodwin</managingEditor>
<lastBuildDate>Thu, 26 Jul 2007 07:45:00 GMT</lastBuildDate>
  
  

  <generator>Pebble (http://pebble.sourceforge.net)</generator>
  <docs>http://backend.userland.com/rss</docs>
  
  
  <item>
    <title>Re: Does Firefox implement DNS Pinning?</title>
    <link>http://directwebremoting.org/blog/mark/2007/07/19/does_firefox_implement_dns_pinning.html#comment1186729184020</link>
    <description>
      Yes, I was aware of this.&amp;nbsp; I thought the firefox thing was noteworthy for two reasons:&lt;br /&gt;
&lt;ol&gt;
    &lt;li&gt;It seems to go against the widely understood behaviour of the browser&lt;/li&gt;
    &lt;li&gt;If you can carry out this type of attack without generating too much noise (e.g. connections from the browser to non-standard ports) the attack becomes harder to detect and therefore stop&lt;/li&gt;
&lt;/ol&gt;
The best I can come up with in terms of mitigation for this type of attack is to filter all traffic for responses that resolve unrecognised domains to internal addresses.
    </description>
    <author>Mark Goodwin</author>
    <comments>http://directwebremoting.org/blog/mark/2007/07/19/does_firefox_implement_dns_pinning.html#comments</comments>
    <guid isPermaLink="true">http://directwebremoting.org/blog/mark/2007/07/19/does_firefox_implement_dns_pinning.html#comment1186729184020</guid>
    <pubDate>Fri, 10 Aug 2007 06:59:44 GMT</pubDate>
  </item>
  
  <item>
    <title>Re: Does Firefox implement DNS Pinning?</title>
    <link>http://directwebremoting.org/blog/mark/2007/07/19/does_firefox_implement_dns_pinning.html#comment1185435900602</link>
    <description>
      You can use a closed port like 81 instead of firewalling.

Check this out
http://www.jumperz.net/index.php?i=2&amp;a=1&amp;b=7
    </description>
    <author>Kanatoko</author>
    <comments>http://directwebremoting.org/blog/mark/2007/07/19/does_firefox_implement_dns_pinning.html#comments</comments>
    <guid isPermaLink="true">http://directwebremoting.org/blog/mark/2007/07/19/does_firefox_implement_dns_pinning.html#comment1185435900602</guid>
    <pubDate>Thu, 26 Jul 2007 07:45:00 GMT</pubDate>
  </item>
  
  </channel>
</rss>
