Web Hack List

Top 10 winner

TLS-poison

TLS-poison abuses TLS session persistence combined with DNS rebinding so that an https URL fed to a victim client (curl, or a browser image tag) is redirected mid-session to an internal service. This delivers attacker-chosen payload bytes to services like memcached or SMTP, giving generic SSRF and cross-protocol injection and image-tag CSRF without relying on a parser bug.

Record

Researcher
jmdx
Published by
GitHub
Format
Repository
Topic
Crypto

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of jmdx, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .