Top 10 winner
JavaScript Port Scanning
Hacking Intranet Websites from the Outside
Grossman and Niedzialkowski's Black Hat USA 2006 deck 'Hacking Intranet Websites from the Outside'. A Java applet leaks the NAT'ed internal IP, <SCRIPT SRC> to an internal host reveals a listener by the JS parse error, and cycling platform-unique image URLs with onerror fingerprints it blindly. POST-to-GET then rewrites router passwords, opens the DMZ and drives HP printers.
Record
- Document
- Hacking Intranet Websites from the Outside
- Researcher
- Jeremiah Grossman and T.C. Niedzialkowski
- Published by
- WhiteHat Security, inc.
- Date
- Format
- Slides
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Jeremiah Grossman and T.C. Niedzialkowski, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .