Web Hack List

Collected research

Hacking Intranets Through Web Interfaces

Uses the web server, not the browser, as the way into an intranet: any feature that fetches a URL server-side (avatar-by-URL, RSS aggregation) will reach RFC1918 space. Default images such as Apache's /icons/ and WordPress smilies turn that fetch into a port sweep and an application fingerprint, and one GET carrying an RFI payload exploits what it finds.

Record

Researcher
Robert Hansen
Published by
sectheory.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Robert Hansen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .