Collected research
SMB Decloaking
SMB Decloaking ha.ckers.org web application security lab
An iframe pointing at a file:// UNC path makes Internet Explorer open an SMB connection to the attacker's host, which a packet capture reads for the real username, IP address, computer name and service pack. It needs no user interaction; the author estimates about half of networks allow outbound SMB.
Record
- Document
- SMB Decloaking ha.ckers.org web application security lab
- Published by
- ha.ckers.org
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of ha.ckers.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .