3 ms·
? I browse from work. And I'm fairly sure my Sys Admin won't want random websites knowing my internal IP address. Network shares etc. would likely be somewher
by tezza 10y ago
? I browse from work.
And I'm fairly sure my Sys Admin won't want random websites knowing my internal IP address.
Network shares etc. would likely be somewhere on the same range and they could launch subsequent attacks to try to sniff confidential documents and resources.
- pyvpx 10y agoyour network shares have public, routable IP addresses? that, in my opinion, would be a far bigger issue than 'leaking' a hosts IP address.
- tezza 10y agoi'm more talking about being able to craft subsequent XSS requests. My browser will unwittingly be doing the attacking My ip address is 192.168.99.105 Script tries XSS attacks on: http://192.168.99.1/ciscowebinterface/known_dodgy_admin?user=root&pass=NEVERCHANGED1 http://192.168.99.1/juniper/also_leaky_admin?user=root&pass=NEVERCHANGED2 http://192.168.99.2/... enumerated
- diafygi 10y agoNo, any website can detect your local IP address, then use ajax to scan a targeted IP subnet range fairly quickly (and completely hidden from the user) to find any shitty CORS-enabled web interface your company has (think some "modern" internal accounting webapp that enables CORS for its "API"). Prior to WebRTC you'd have to scan much larger IP ranges to try and find internal network webapps that are CORS enabled.
- api 10y agoAgain: that is a problem. If that is possible your internal network is insecure. The castle and moat model is obsolete anyway. Most attacks today come through "pulled" vectors that bypass the firewall. If you rely on a physical network perimeter for security your security is an illusion.