TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Attacking private networks with DNS rebinding

16 点作者 braxxox将近 7 年前

2 条评论

isostatic将近 7 年前
One practical thing that could help (beyond the usual patching and setting passwords) would be to seperate your networks -- client devices on one subnet, IOT on another, servers&#x2F;nas etc on another. Ensure that private IPs are disjointed (say 10.65.34.128&#x2F;28, 172.29.34.0&#x2F;27, 192.168.14.208&#x2F;29 etc). That adds layers of obscurity.<p>Enable multicast between them, pretty tricky for a XSS to know which networks your IOT devices are on.<p>Other things you can do (like only allowing control of IOT devices from a separate admin network for instance) is a matter of security vs convenience.
pnunesc将近 7 年前
Good read!