question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

DNS Rebinding protection

See original GitHub issue

Hi, I’m an independent security researcher and author of host-validation, an NPM module for protecting Express.js servers from DNS rebinding attacks via host header validation. I’ve done a fair amount of research on the subject and I think DNS rebinding protection through header validation would be a perfect addition to helmet. I’m happy to spearhead this effort if there is interest. I’m willing to write a PR with updates to the lib, tests, and documentation, pending discussion. This is an amazing project and I’d like to contribute a small bit to make it even better.

Issue Analytics

  • State:closed
  • Created 5 years ago
  • Reactions:1
  • Comments:6 (4 by maintainers)

github_iconTop GitHub Comments

1reaction
EvanHahncommented, Oct 22, 2018

Sounds good! I’ll make pull requests for these changes and @-mention you on both.

0reactions
EvanHahncommented, Oct 25, 2018

Closing this issue now that I’ve addressed the action items. Thanks for bringing this to my attention!

Read more comments on GitHub >

github_iconTop Results From Across the Web

DNS rebinding - Wikipedia
DNS rebinding is a method of manipulating resolution of domain names that is commonly used as a form of computer attack. In this...
Read more >
What is DNS Rebinding Protection? - NextDNS Help Center
DNS rebinding is a method of manipulating resolution of domain names that is commonly used as a form of computer attack.
Read more >
DNS Rebinding Attack: How Malicious Websites ... - Unit 42
DNS rebinding allows attackers to take advantage of web-based consoles to exploit internal networks by abusing the domain name system.
Read more >
DNS Rebinding Protections | pfSense Documentation
pfSense® software includes built in methods of protection against DNS rebinding attacks. DNS rebinding attack protection is active by default.
Read more >
[Technical] The pros and cons of DNS Rebinding protection
Rebind Protection in DNS Resolvers / Routers filter out (all or some of) the local IP addresses in responses from DNS requests to...
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found