Giter VIP home page Giter VIP logo

pyrebind's Introduction

pyrebind

pyrebind is a very simple DNS server written in Python for testing software against DNS rebinding vulnerabilities. The server responds to queries by randomly selecting one of the IP addresses specified in the requested domain name and returning it as the answer with the lowest possible TTL=1.

https://en.wikipedia.org/wiki/DNS_rebinding

For example, to switch between 127.0.0.1 and 10.10.10.10 you would need to encode them like this:

127-0-0-1.10-10-10-10.any.domain

Here is how it looks in action:

$ host 127-0-0-1.10-10-10-10.any.domain
127-0-0-1.10-10-10-10.any.domain has address 127.0.0.1
$ host 127-0-0-1.10-10-10-10.any.domain
127-0-0-1.10-10-10-10.any.domain has address 127.0.0.1
$ host 127-0-0-1.10-10-10-10.any.domain
127-0-0-1.10-10-10-10.any.domain has address 127.0.0.1
$ host 127-0-0-1.10-10-10-10.any.domain
127-0-0-1.10-10-10-10.any.domain has address 10.10.10.10
$ host 127-0-0-1.10-10-10-10.any.domain
127-0-0-1.10-10-10-10.any.domain has address 10.10.10.10
$ host 127-0-0-1.10-10-10-10.any.domain
127-0-0-1.10-10-10-10.any.domain has address 127.0.0.1
$ host 127-0-0-1.10-10-10-10.any.domain
127-0-0-1.10-10-10-10.any.domain has address 127.0.0.1
$ host 127-0-0-1.10-10-10-10.any.domain
127-0-0-1.10-10-10-10.any.domain has address 10.10.10.10
$ host 127-0-0-1.10-10-10-10.any.domain
127-0-0-1.10-10-10-10.any.domain has address 10.10.10.10

Constraints

This implementation aims to be as simple as possible and therefore it supports only standard IN A queries - other are simply ignored. Also keep in mind it requires high privileges to bind port 53/udp and lacks proper error handling. With that said, it is highly recommended to not use it for anything important.

pyrebind's People

Contributors

elceef avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.