Collected research
UPnP Hacking via Flash
Hacking The Interwebs
pdp and Adrian Pastor drop the XSS requirement from UPnP router attacks. Flash's URLRequest can set POST content type application/xml and add a SOAPAction header, so a plain malicious SWF sends a UPnP SOAP control message straight to the LAN router, adding port forwards or changing the primary DNS server. No same-origin bypass needed, and most consumer routers of the day ship UPnP on.
Record
- Document
- Hacking The Interwebs
- Researcher
- Adrian Pastor and pdp
- Published by
- gnucitizen.org
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Adrian Pastor and pdp, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .