Hacker News new | ask | show | jobs
by yencabulator 1909 days ago
So now the attacker just needs `evil.example.com A 127.0.0.1` in DNS.

The protection has to sit in the HTTP client library after resolving the hostname to IP address, before connecting.