메뉴 건너뛰기




Volumn , Issue , 2007, Pages 421-431

Protecting browsers from DNS rebinding attacks

Author keywords

Click fraud; DNS; Firewall; Same origin policy; Spam

Indexed keywords

CLICK FRAUD; IP ADDRESSS; OPEN NETWORK; PLUG-INS; SAME-ORIGIN POLICY;

EID: 48349084659     PISSN: 15437221     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/1315245.1315298     Document Type: Conference Paper
Times cited : (50)

References (46)
  • 1
    • 49649108151 scopus 로고    scopus 로고
    • Adobe
    • Adobe. Flash Player Penetration. http://www.adobe.com/products/player- census/flashplayer/.
    • Flash Player Penetration
  • 2
    • 77952323881 scopus 로고    scopus 로고
    • Adobe, July
    • Adobe. Adobe flash player 9 security. http://www.adobe.com/devnet/ flashplayer/articles/flash-player-9-securit%ypdf, July 2006.
    • (2006) Adobe Flash Player 9 Security
  • 3
    • 77952368412 scopus 로고    scopus 로고
    • Alexa
    • Alexa. Top sites. http://www.alexa.com/site/ds/top-sites?ts-mode=global.
    • Top Sites
  • 5
    • 77952339019 scopus 로고    scopus 로고
    • A DNS filter and switch for packet-filtering gateways
    • W. Cheswick and S. Bellovin. A DNS filter and switch for packet-filtering gateways. In Proc. Usenix, 1996.
    • (1996) Proc. Usenix
    • Cheswick, W.1    Bellovin, S.2
  • 9
    • 58849163870 scopus 로고    scopus 로고
    • December
    • D. Edwards. Your MOMA knows best, December 2005. http://xooglers. blogspot.com/2005/12/your-moma-knows-best.html.
    • (2005) Your MOMA Knows Best
    • Edwards, D.1
  • 15
    • 77952402163 scopus 로고    scopus 로고
    • Google. dnswall
    • Google. dnswall. http://code.google.com/p/google-dnswall/.
  • 16
    • 77952338018 scopus 로고    scopus 로고
    • Google. Google Safe Browsing for Firefox
    • Google. Google Safe Browsing for Firefox, 2005. http://www.google.com/ tools/firefox/safebrowsing/.
    • (2005)
  • 18
    • 34547256115 scopus 로고    scopus 로고
    • Hacking intranet websites from the outside: Javascript malware just got a lot more dangerous
    • August, Invited talk
    • J. Grossman and T. Niedzialkowski. Hacking intranet websites from the outside: JavaScript malware just got a lot more dangerous. In Blackhat USA, August 2006. Invited talk.
    • (2006) Blackhat USA
    • Grossman, J.1    Niedzialkowski, T.2
  • 22
    • 77952394909 scopus 로고    scopus 로고
    • Protecting the intranet against "JavaScript malware" and related attacks
    • July
    • M. Johns and J. Winter. Protecting the Intranet against "JavaScript Malware" and related attacks. In Proc. DIMVA, July 2007.
    • (2007) Proc. DIMVA
    • Johns, M.1    Winter, J.2
  • 23
    • 77952370957 scopus 로고    scopus 로고
    • Dynamic pharming attacks and the locked same-origin policies for web browsers
    • October
    • C. K. Karlof, U. Shankar, D. Tygar, and D. Wagner. Dynamic pharming attacks and the locked same-origin policies for web browsers. In Proc. CCS, October 2007.
    • (2007) Proc. CCS
    • Karlof, C.K.1    Shankar, U.2    Tygar, D.3    Wagner, D.4
  • 24
    • 34547381072 scopus 로고    scopus 로고
    • Puppetnets: Misusing web browsers as a distributed attack infrastructure
    • V. T. Lam, S. Antonatos, P. Akritidis, and K. G. Anagnostakis. Puppetnets: Misusing web browsers as a distributed attack infrastructure. In Proc. CCS, 2006.
    • (2006) Proc. CCS
    • Lam, V.T.1    Antonatos, S.2    Akritidis, P.3    Anagnostakis, K.G.4
  • 26
    • 77952338518 scopus 로고    scopus 로고
    • NoScript
    • G. Maone. NoScript. http://noscript.net/.
    • Maone, G.1
  • 27
    • 77952382546 scopus 로고    scopus 로고
    • WSKE: Web Server Key Enabled Cookies
    • C. Masone, K. Baek, and S. Smith. WSKE: web server key enabled cookies. In Proc. USEC, 2007.
    • (2007) Proc. USEC
    • Masone, C.1    Baek, K.2    Smith, S.3
  • 30
    • 77952349148 scopus 로고    scopus 로고
    • Microsoft. Microsoft Web Enterprise Portal, January
    • Microsoft. Microsoft Web Enterprise Portal, January 2004. http://www.microsoft.com/technet/itshowcase/content/MSWebTWP.mspx.
    • (2004)
  • 31
    • 77952344120 scopus 로고    scopus 로고
    • Microsoft. Microsoft phishing filter: A new approach to building trust in e-commerce content
    • Microsoft. Microsoft phishing filter: A new approach to building trust in e-commerce content, 2005.
    • (2005)
  • 32
    • 0003324905 scopus 로고
    • Domain names-implementation and specification
    • November
    • P. Mockapetris. Domain Names-Implementation and Specification. IETF RFC 1035, November 1987.
    • (1987) IETF RFC 1035
    • Mockapetris, P.1
  • 34
    • 58849140341 scopus 로고    scopus 로고
    • August
    • G. Ollmann. The pharming guide. http://www.ngssoftware.com/papers/ ThePharmingGuidepdf, August 2005.
    • (2005) The Pharming Guide
    • Ollmann, G.1
  • 36
    • 58849099840 scopus 로고    scopus 로고
    • Attacks against the netscape browser
    • April, Invited talk
    • J. Roskind. Attacks against the Netscape browser. In RSA Conference, April 2001. Invited talk.
    • (2001) RSA Conference
    • Roskind, J.1
  • 37
    • 77952343585 scopus 로고    scopus 로고
    • D. Ross. Notes on DNS pinning. http://blogs.msdn.com/dross/archive/2007/ 07/09/notes-on-dns-pinning.asp%x, 2007.
    • (2007)
  • 39
    • 58849130889 scopus 로고    scopus 로고
    • Spamhaus
    • Spamhaus. The spamhaus block list, 2007. http://www.spamhaus.org/sbl/.
    • (2007) The Spamhaus Block List
  • 43
    • 77952361459 scopus 로고    scopus 로고
    • W3C. The XMLHttpRequest Object, February
    • W3C. The XMLHttpRequest Object, February 2007. http://www.w3.org/TR/ XMLHttpRequest/.
    • (2007)
  • 44
    • 58849165586 scopus 로고    scopus 로고
    • Home PCS rented out in sabotage-for-hire racket
    • July
    • B. Warner. Home PCs rented out in sabotage-for-hire racket. Reuters, July 2004.
    • (2004) Reuters
    • Warner, B.1
  • 46
    • 38349038696 scopus 로고    scopus 로고
    • Sender policy framework (SPF) for authorizing use of domains in E-Mail
    • April
    • M. Wong and W. Schlitt. Sender Policy Framework (SPF) for Authorizing Use of Domains in E-Mail. IETF RFC 4408, April 2006.
    • (2006) IETF RFC 4408
    • Wong, M.1    Schlitt, W.2


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.