Glossary
DNS rebinding
DNS rebinding is a cyberattack that manipulates DNS responses to bypass browser security controls and gain access to devices or services within a private network. By changing the IP address associated with a domain after a user's browser has already trusted it, attackers can trick browsers into communicating with internal systems that would normally be inaccessible from the internet.
This technique can be used to access internal applications, interact with network-connected devices, and expose sensitive information without the victim’s knowledge.
{{anchor:How DNS rebinding works}}
How DNS rebinding works
A DNS rebinding attack typically begins when a user visits a malicious website controlled by an attacker.
The attacker then:
- Delivers malicious JavaScript through a trusted domain
- Manipulates DNS responses associated with that domain
- Rebinds the domain to a private or internal IP address
- Tricks the browser into treating internal resources as part of the trusted site
- Interacts with devices, applications, or services inside the victim’s network
By exploiting the way browsers handle DNS resolution and trust relationships, attackers can bypass security boundaries designed to isolate internal systems from external access.
{{anchor:Why it matters}}
Why DNS rebinding matters
DNS rebinding can expose organizations to a range of security risks, including:
- Unauthorized access to internal systems
- Exposure of sensitive business data
- Compromise of cloud or administrative resources
- Manipulation of network-connected devices
- Service disruption and operational risk
- Financial, legal, and reputational damage
Organizations with connected devices, cloud services, administrative interfaces, or internal web applications may be particularly vulnerable if proper safeguards are not in place.
{{anchor:Reducing risk}}
Reducing DNS rebinding risk
Organizations can help mitigate DNS rebinding attacks by:
- Implementing protective DNS services
- Restricting untrusted JavaScript execution
- Using DNS pinning where appropriate
- Securing internal applications with strong authentication
- Encrypting services with HTTPS
- Segmenting internal networks and sensitive systems
- Monitoring DNS activity for suspicious behavior
- Conducting regular security assessments
A layered security strategy helps reduce opportunities for attackers to exploit browser and DNS trust relationships.
{{anchor:How DigiCert helps}}
How DigiCert can help
DigiCert UltraDDR helps organizations defend against DNS-based threats through advanced protective DNS capabilities. By leveraging continuously updated threat intelligence and real-time analysis of malicious infrastructure, UltraDDR can identify and block access to suspicious domains before attackers can establish communications or deliver malicious content.
UltraDDR provides visibility into DNS activity across users, devices, and networks, helping security teams detect unusual behavior and reduce exposure to malicious domains that may be used in DNS rebinding campaigns. By disrupting malicious DNS activity early, organizations can strengthen cyber resilience and reduce the risk of compromise.