Collected research
Cross Environment Hopping
An XSS flaw in one localhost web server reaches every other service on the machine, because same-origin policy does not separate ports on localhost for IE's ActiveX XMLHTTP objects. Firefox extends it further through Java sockets in JavaScript: enumerate SMB shares, or drive a locally installed proxy (AVAST's) and its HTTP CONNECT support to tunnel into the intranet and talk SMTP.
Record
- Researcher
- Yair Amit
- Published by
- IBM Application Security Insider
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Yair Amit, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .