Top 10 winner
RFC1918 Caching Security Issues
Because everyone reuses the same RFC1918 ranges, a hostile VPN peer or cafe MITM can route a victim to its own 10.x/192.168.x hosts and leave cached JavaScript behind. When the tunnel drops, the cache is served again from the victim's real intranet address, giving a persistent backdoor without breaking the same-origin policy. Defences: TLS, internal FQDNs, static routes.
Record
- Researcher
- Robert Hansen
- Published by
- sectheory.com
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Robert Hansen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .