Collected research
Hacking Intranets Through Web Interfaces
Uses the web server, not the browser, as the way into an intranet: any feature that fetches a URL server-side (avatar-by-URL, RSS aggregation) will reach RFC1918 space. Default images such as Apache's /icons/ and WordPress smilies turn that fetch into a port sweep and an application fingerprint, and one GET carrying an RFI payload exploits what it finds.
Record
- Researcher
- Robert Hansen
- Published by
- sectheory.com
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Robert Hansen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .