<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>DNS Security on Nalar</title>
    <link>https://nalar.dev/tags/dns-security/</link>
    <description>Recent content in DNS Security on Nalar</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 14 Sep 2026 00:00:00 +0700</lastBuildDate>
    <atom:link href="https://nalar.dev/tags/dns-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Dangling DNS Records Can Outlive the Services They Point To</title>
      <link>https://nalar.dev/dangling-dns-records-can-outlive-the-services-they-point-to/</link>
      <pubDate>Mon, 14 Sep 2026 00:00:00 +0700</pubDate>
      <guid>https://nalar.dev/dangling-dns-records-can-outlive-the-services-they-point-to/</guid>
      <description>&lt;p&gt;A hostname can remain part of an organisation&amp;rsquo;s public identity long after the application behind it has disappeared. The DNS record still resolves, certificates may have existed for years, links remain in old messages, and browser cookies may still be scoped broadly enough to include the name. Yet the external service named by that record may have been deleted and returned to a provider&amp;rsquo;s pool of available resources.&lt;/p&gt;&#xA;&lt;p&gt;That mismatch creates the conditions for subdomain takeover. The core problem is not DNS compromise. The authoritative zone can be operating exactly as configured. The failure sits between two control planes: DNS still delegates traffic toward an external platform, while the platform no longer associates the referenced resource with the domain owner.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DNS Rebinding Turns Browser Reachability Into a Security Boundary</title>
      <link>https://nalar.dev/dns-rebinding-turns-browser-reachability-into-a-security-boundary/</link>
      <pubDate>Sun, 13 Sep 2026 00:00:00 +0700</pubDate>
      <guid>https://nalar.dev/dns-rebinding-turns-browser-reachability-into-a-security-boundary/</guid>
      <description>&lt;p&gt;A service bound to a private address often feels insulated from the public web. An administrative panel on a home router, a development daemon on a laptop, or an internal HTTP endpoint may have no public route at all. Yet a browser on the same network can often reach it, and that browser also processes content from arbitrary public sites.&lt;/p&gt;&#xA;&lt;p&gt;DNS rebinding exploits the seam between those facts. A hostile site can use a domain it controls, arrange for that name to resolve to different addresses over time, and attempt to make browser requests under one web origin reach a service that was never intended to receive traffic from public content.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
