Collected research
XMLHTTPReqest "Ping" Sweeping in Firefox 3.5+
XMLHTTPReqest “Ping” Sweeping in Firefox 3.5+ ha.ckers.org web application security lab
Firefox 3.5's CORS cross-domain XMLHttpRequest hides whether a target page exists, but the attacker can still issue the initial request. Live hosts answer immediately while absent ones hang for 20-75 seconds, and that timing gap enumerates internal address space behind the victim's firewall. Basic and digest auth popups are suppressed, which suits intranet sweeping.
Record
- Document
- XMLHTTPReqest “Ping” Sweeping in Firefox 3.5+ ha.ckers.org web application security lab
- Published by
- ha.ckers.org
- Topic
- Browser
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of ha.ckers.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .