Comment 164 for bug 113201

Revision history for this message
In , georgi (guninski) wrote :

(In reply to comment #88)
> Do you think that the
> DNS is changing between resolution points?
>

yes, malicious dns server on purpose gives different replies for the ip of
hostname with short dns TTL. so if a script is loading several times content
from mal.dns you may end up with content with hostname mal.dns coming from two
ip-s: 1.1.1.1 and 10.1.1.1 and both seem coming from the same hostname so they
can interact.