Top 10 winner
TLS-poison
TLS-poison abuses TLS session persistence combined with DNS rebinding so that an https URL fed to a victim client (curl, or a browser image tag) is redirected mid-session to an internal service. This delivers attacker-chosen payload bytes to services like memcached or SMTP, giving generic SSRF and cross-protocol injection and image-tag CSRF without relying on a parser bug.
Record
- Researcher
- jmdx
- Published by
- GitHub
- Format
- Repository
- Topic
- Crypto
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of jmdx, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .