Web Hack List

Top 10 winner

JavaScript Port Scanning

Hacking Intranet Websites from the Outside

Grossman and Niedzialkowski's Black Hat USA 2006 deck 'Hacking Intranet Websites from the Outside'. A Java applet leaks the NAT'ed internal IP, <SCRIPT SRC> to an internal host reveals a listener by the JS parse error, and cycling platform-unique image URLs with onerror fingerprints it blindly. POST-to-GET then rewrites router passwords, opens the DMZ and drives HP printers.

Record

Document
Hacking Intranet Websites from the Outside
Researcher
Jeremiah Grossman and T.C. Niedzialkowski
Published by
WhiteHat Security, inc.
Date
Format
Slides
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Jeremiah Grossman and T.C. Niedzialkowski, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .