09. DNS Rebinding: The Boundary Between Origin and Endpoint
DNS Rebinding is an attack in which an attacker changes DNS answers for a hostname they control so that a browser first receives code from an external server and later connects through the same hostname to an internal-network or loopback service. The key is not hacking DNS itself, but exploiting the gap between a web origin's identity and its actual network endpoint.