Glossary

DNS rebinding

Glossary for DNS Rebinding

DNS rebinding is a cyberattack that manipulates DNS responses to bypass browser security controls and gain access to devices or services within a private network. By changing the IP address associated with a domain after a user's browser has already trusted it, attackers can trick browsers into communicating with internal systems that would normally be inaccessible from the internet.

This technique can be used to access internal applications, interact with network-connected devices, and expose sensitive information without the victim’s knowledge.

{{anchor:How DNS rebinding works}}

How DNS rebinding works

A DNS rebinding attack typically begins when a user visits a malicious website controlled by an attacker.

The attacker then:

By exploiting the way browsers handle DNS resolution and trust relationships, attackers can bypass security boundaries designed to isolate internal systems from external access.

{{anchor:Why it matters}}

Why DNS rebinding matters

DNS rebinding can expose organizations to a range of security risks, including:

Organizations with connected devices, cloud services, administrative interfaces, or internal web applications may be particularly vulnerable if proper safeguards are not in place.

{{anchor:Reducing risk}}

Reducing DNS rebinding risk

Organizations can help mitigate DNS rebinding attacks by:

A layered security strategy helps reduce opportunities for attackers to exploit browser and DNS trust relationships.

{{anchor:How DigiCert helps}}

How DigiCert can help

DigiCert UltraDDR helps organizations defend against DNS-based threats through advanced protective DNS capabilities. By leveraging continuously updated threat intelligence and real-time analysis of malicious infrastructure, UltraDDR can identify and block access to suspicious domains before attackers can establish communications or deliver malicious content.

UltraDDR provides visibility into DNS activity across users, devices, and networks, helping security teams detect unusual behavior and reduce exposure to malicious domains that may be used in DNS rebinding campaigns. By disrupting malicious DNS activity early, organizations can strengthen cyber resilience and reduce the risk of compromise.