Security decisions based on DNS lookup results

Security decisions based on DNS lookup results

Description

Using forward or reverse DNS results directly to establish trust, grant access or authenticate a caller can be bypassed through DNS spoofing, cache poisoning or rebinding.

Potential impact

  • An attacker may manipulate DNS responses to appear to be a trusted host.
  • Access may be granted based only on a reverse DNS name.

Remediation

  • Base authentication and access decisions on evidence independent of DNS, such as TLS client authentication, signed tokens and server-side authorization.
  • If network location checks are necessary, compare resolved IP addresses with approved CIDR ranges and recheck after redirects.

Examples

Access based only on DNS

python
addr = socket.gethostbyname(host)
if addr == TRUSTED_IP:
    grant_access()

Additional network check

python
addr = ipaddress.ip_address(socket.gethostbyname(host))
return addr in TRUSTED_NET

Explanation:

  • Vulnerable code: Directly relies on a DNS lookup result to grant access, making the decision vulnerable to manipulated DNS results.
  • Network location check: Compares the resolved IP address with an approved CIDR range as an additional check. This code alone must not establish the caller's identity or grant access. Authenticate and authorize independently of DNS.

References