MCP DNS Rebinding Attack — Hostname Time-Based IP Switching - ATR-2026-01307 (efff64e0-d223-5e5b-a1d2-5979b5bc3d48)
Detects DNS rebinding attack payloads targeting MCP servers. DNS rebinding exploits the browser/client same-origin policy by initially resolving a hostname to an attacker-controlled IP (bypassing the agent's origin checks), then rebinding the DNS to a local/internal IP (e.g., 192.168.x.x or 127.0.0.1) after the connection is established. This lets an attacker read or manipulate a locally running MCP server through a victim browser/agent that loaded attacker-controlled content. The canonical payload format uses rebind.network, rbndr.us, nip.io, or 1time/forever TTL suffixes. MCPSecBench probe: