메뉴 건너뛰기




Volumn 3, Issue 1, 2009, Pages

Protecting browsers from DNS rebinding attacks

Author keywords

Click fraud; DNS; Firewall; Same origin policy; Spam

Indexed keywords

CLICK FRAUD; DNS; FIREWALL; SAME-ORIGIN POLICY; SPAM;

EID: 58849088038     PISSN: 15591131     EISSN: 1559114X     Source Type: Journal    
DOI: 10.1145/1462148.1462150     Document Type: Conference Paper
Times cited : (49)

References (58)
  • 1
    • 58849124033 scopus 로고    scopus 로고
    • Adobe. 2006. Adobe Flash Player 9 security, http://www.adobe. com/devnet/flashplayer/articles/fiash-player-9-security.pdf.
    • Adobe. 2006. Adobe Flash Player 9 security, http://www.adobe. com/devnet/flashplayer/articles/fiash-player-9-security.pdf.
  • 2
    • 58849167145 scopus 로고    scopus 로고
    • Adobe. 2008. Flash Player penetration. http://www.adobe.com/ products/player-census/flash-player/.
    • Adobe. 2008. Flash Player penetration. http://www.adobe.com/ products/player-census/flash-player/.
  • 3
    • 84916994727 scopus 로고    scopus 로고
    • Aleka. 2007. Top sites. http://www.alexa.com/site/ds/top-sites? ts-mode=global.
    • (2007) Top sites
    • Aleka1
  • 14
    • 58849108039 scopus 로고    scopus 로고
    • FIELDING, R., GETTYS, J., MOGUL, J., FRYSTYK, H., MASINTER, L., LEACH, P., AND BERNERS-LEE, T. 1999. Hypertext Transfer Protocol - HTTP/1.1. RFC 2616.
    • FIELDING, R., GETTYS, J., MOGUL, J., FRYSTYK, H., MASINTER, L., LEACH, P., AND BERNERS-LEE, T. 1999. Hypertext Transfer Protocol - HTTP/1.1. RFC 2616.
  • 15
    • 58849154877 scopus 로고    scopus 로고
    • Personal communication
    • FISHER, D. 2007. Personal communication.
    • (2007)
    • FISHER, D.1
  • 16
    • 58849117879 scopus 로고    scopus 로고
    • FISHER, D. ET AL. 2003. Problems with new DNS cache (pinning forever). https://bugzilla.mozilla.org/show-bug.cgi?id= 162871.
    • FISHER, D. ET AL. 2003. Problems with new DNS cache ("pinning" forever). https://bugzilla.mozilla.org/show-bug.cgi?id= 162871.
  • 17
    • 70349327284 scopus 로고    scopus 로고
    • On the insecurity of Microsoft's identity metasystem
    • Tech. Rep. HGI-TR-2008-003, Horst Görtz Institute for IT Security, Ruhr University Bochum. May
    • GAJEK, S., SCHWENK, J., AND XUAN, C. 2008. On the insecurity of Microsoft's identity metasystem. Tech. Rep. HGI-TR-2008-003, Horst Görtz Institute for IT Security, Ruhr University Bochum. May. http://demo.nds.rub.de/cardspace/.
    • (2008)
    • GAJEK, S.1    SCHWENK, J.2    XUAN, C.3
  • 18
    • 58849162573 scopus 로고    scopus 로고
    • Calif. man pleads guilty to felony hacking
    • GOODIN, D. 2005. Calif. man pleads guilty to felony hacking. Assoc. Press.
    • (2005) Assoc. Press
    • GOODIN, D.1
  • 19
    • 58849094347 scopus 로고    scopus 로고
    • GOTTSCHALL, S. ET AL. 2008. DD-WRT (version 24). http://www.dd-wrt.com/.
    • GOTTSCHALL, S. ET AL. 2008. DD-WRT (version 24). http://www.dd-wrt.com/.
  • 21
    • 34547256115 scopus 로고    scopus 로고
    • Hacking intranet Websites from the outside: JavaScript malware just got a lot more dangerous
    • Invited talk
    • GROSSMAN, J. AND NIEDZIALKOWSKI, T. 2006. Hacking intranet Websites from the outside: JavaScript malware just got a lot more dangerous. In Blackhat USA. Invited talk.
    • (2006) Blackhat USA
    • GROSSMAN, J.1    NIEDZIALKOWSKI, T.2
  • 22
    • 84868888621 scopus 로고    scopus 로고
    • dnswall FreeBSD port
    • HAUPT, E. 2008. dnswall FreeBSD port. http://www.freebsd.org/ cgi/cvsweb.cgi/ports/dns/dnswall/.
    • (2008)
    • HAUPT, E.1
  • 29
    • 84868870470 scopus 로고    scopus 로고
    • KELLEY, S. 2008. Dnsmasq version 2.41
    • KELLEY, S. 2008. Dnsmasq (version 2.41). http://www.thekelleys. org.uk/dnsmasq/doc.html.
  • 30
    • 84868885602 scopus 로고    scopus 로고
    • as an anti anti DNS-pinning measure
    • KLEIN, A. 2006. Host header cannot be trusted as an anti anti DNS-pinning measure. http://www.securityfocus.com/archive/1/445490.
    • (2006) Host header cannot be trusted
    • KLEIN, A.1
  • 32
    • 84868889564 scopus 로고    scopus 로고
    • MAONE, G. 2007a. DNS spoofing/pinning. http://sla.ckers.org/ forum/read.php?6,4511,14500.
    • (2007) DNS spoofing/pinning , pp. 4511-14500
    • MAONE, G.1
  • 37
    • 58849139477 scopus 로고    scopus 로고
    • Microsoft. 2004. Microsoft Web enterprise portal. http://www.microsoft.com/technet/itshowcase/content/MSWebTWP.mspx.
    • Microsoft. 2004. Microsoft Web enterprise portal. http://www.microsoft.com/technet/itshowcase/content/MSWebTWP.mspx.
  • 38
    • 58849106558 scopus 로고    scopus 로고
    • MICROSOFT 2008. Socket class (System.Net.Sockets). http://msdn.microsoft.com/en-us/library/system.net.sockets.soeket(VS.95).aspx.
    • MICROSOFT 2008. Socket class (System.Net.Sockets). http://msdn.microsoft.com/en-us/library/system.net.sockets.soeket(VS.95).aspx.
  • 39
    • 58849151172 scopus 로고    scopus 로고
    • MITRE. 2007a. CVE-2007-5273.
    • (2007) , vol.CVE-2007-5273
    • MITRE1
  • 40
    • 58849165139 scopus 로고    scopus 로고
    • MITRE. 2007b. CVE-2007-5274.
    • (2007) , vol.CVE-2007-5274
    • MITRE1
  • 41
    • 58849158182 scopus 로고    scopus 로고
    • MITRE. 2007c. CVE-2007-5275.
    • (2007) , vol.CVE-2007-5275
    • MITRE1
  • 42
    • 58849158609 scopus 로고    scopus 로고
    • MITRE. 2007d. CVE-2007-6244.
    • (2007) , vol.CVE-2007-6244
    • MITRE1
  • 43
    • 58849109703 scopus 로고    scopus 로고
    • MITRE. 2008. CVE-2008-1192.
    • (2008) , vol.CVE-2008-1192
    • MITRE1
  • 45
    • 58849155419 scopus 로고    scopus 로고
    • Personal communication
    • NUUJA, C. 2007. Personal communication.
    • (2007)
    • NUUJA, C.1
  • 49
    • 58849099840 scopus 로고    scopus 로고
    • Attacks against the Netscape browser
    • Invited talk
    • ROSKIND, J. 2001. Attacks against the Netscape browser. In RSA Conference. Invited talk.
    • (2001) RSA Conference
    • ROSKIND, J.1
  • 50
    • 84868886729 scopus 로고    scopus 로고
    • ROSS, D. 2007. Notes on DNS pinning. http://blogs.msdn.com/ dross/archive/2007/07/09/notes-o-ndns-pinning.aspx.
    • (2007) Notes on DNS pinning
    • ROSS, D.1
  • 51
    • 84868885879 scopus 로고    scopus 로고
    • Same origin
    • RUDKUMAN, J. 2001. JavaScript security: Same origin. http://www.mozilla.org/projects/security/components/same-origin.html.
    • (2001) JavaScript security
    • RUDKUMAN, J.1
  • 53
  • 54
    • 38549139786 scopus 로고    scopus 로고
    • Drive-By pharming
    • Tech. Rep. 641, Computer Science Department, Indiana University. December
    • STAMM, S., RAMZAN, Z., AND JAKOBSSON, M. 2006. Drive-By pharming. Tech. Rep. 641, Computer Science Department, Indiana University. December.
    • (2006)
    • STAMM, S.1    RAMZAN, Z.2    JAKOBSSON, M.3
  • 57
    • 58849165586 scopus 로고    scopus 로고
    • Home PCs rented out in sabotage-for-hire racket
    • WARNER, B. 2004. Home PCs rented out in sabotage-for-hire racket. Reuters.
    • (2004) Reuters
    • WARNER, B.1


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.