Web Hack List

Collected research

Penetrating Intranets through Adobe Flex Applications

BlazeDS proxy services let a Flex client have the server fetch remote URLs on its behalf, sidestepping crossdomain.xml. Sample configurations ship with a wildcard soap property, so the proxy will reach any host it can see from the server. The released tool Blazentoo drives such a destination to browse intranet sites behind the firewall.

Record

Researcher
Marcin Wielgoszewski
Published by
gdssecurity.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Marcin Wielgoszewski, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .