DNS Rebinding
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://tldfyi.com/iframe/glossary/dns-rebinding/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://tldfyi.com/glossary/dns-rebinding/
Add a dynamic SVG badge to your README or docs.
[](https://tldfyi.com/glossary/dns-rebinding/)
Use the native HTML custom element.
DNS rebinding is an attack that exploits the browser's same-origin policy by first resolving a domain to an attacker-controlled server, then rapidly rebinding the domain's [[dns|DNS]] record to an internal IP address (such as 192.168.1.1). This tricks the browser into treating the attacker's website as if it were the local network device, allowing malicious JavaScript to make requests to internal services that are normally inaccessible from the public internet. DNS rebinding can be used to attack routers, smart home devices, and internal corporate services. [[dnssec|DNSSEC]] does not prevent rebinding; mitigations include DNS-over-HTTPS with rebinding protection, short negative TTLs, and firewall rules.
Example
A malicious website changes its DNS record from a public IP to 192.168.1.1 mid-session, allowing the attacker's JavaScript to configure the victim's home router through the browser.