Web Hack List

Collected research

Socket Capable Browser Plugins Result In Transparent Proxy Abuse

The Security Practice: Socket Capable Browser Plugins Result In Transparent Proxy Abuse

Announcement of a paper behind CERT VU#435052. Where a transparent proxy routes by destination host header rather than IP, a socket-capable plug-in such as Flash can open a raw connection and forge that header, reaching any host the proxy can reach. The result is a partial same-origin policy bypass affecting enterprise, hotel and ISP networks.

Record

Document
The Security Practice: Socket Capable Browser Plugins Result In Transparent Proxy Abuse
Published by
thesecuritypractice.com
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of thesecuritypractice.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .