WebApp Sec mailing list archives

Re: extra dot on domain name gives different site


From: Javier Fernandez-Sanguino <jfernandez () germinus com>
Date: Fri, 07 Mar 2008 18:49:38 +0100

Robin Wood dijo:
I didn't realise that an extra dot on the end was a valid domainname
until this. It is definitely an extra check I'll be making on my
audits from now on.

Actually, the real domainname ends with a 'dot' (which is DNS' root, equivalent to a filename's, in UNIX, first '/'). The fact is, most DNS-based applications will assume that 'xxxx.yy' is equivalent to 'xxxx.yy.' (i.e. yy is a valid subdomain of the DNS root zone)

You seem to have found a misconfiguration issue in that webserver. Probably, if you craft an HTTP request with an invalid Host: header you will get a similar result.

Regards

Javier


-------------------------------------------------------------------------
Sponsored by: Watchfire Methodologies & Tools for Web Application Security Assessment With the rapid rise in the number and types of security threats, web application security assessments should be considered a crucial phase in the development of any web application. What methodology should be followed? What tools can accelerate the assessment process? Download this Whitepaper today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=70170000000940F
-------------------------------------------------------------------------


Current thread: