Web Hack List

Top 10 winner

RFC1918 Caching Security Issues

Because everyone reuses the same RFC1918 ranges, a hostile VPN peer or cafe MITM can route a victim to its own 10.x/192.168.x hosts and leave cached JavaScript behind. When the tunnel drops, the cache is served again from the victim's real intranet address, giving a persistent backdoor without breaking the same-origin policy. Defences: TLS, internal FQDNs, static routes.

Record

Researcher
Robert Hansen
Published by
sectheory.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Robert Hansen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .