[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] Checking existence of firewalled URLs via javascript's script.onload
From:       Jeremy Stanley <fungi () yuggoth ! org>
Date:       2023-04-20 11:51:37
Message-ID: 20230420115135.fmeae6hawx7mqqoh () yuggoth ! org
[Download RAW message or body]


On 2023-04-20 10:58:42 +0300 (+0300), Georgi Guninski wrote:
[...]
> I can't imagine how can you check for open port/URL without
> javascript, can you give reference or explanation? You can make
> request, but without javascript you can't read the result.

If the attacker controls the destination, they can simply record
whether the connection is successfully established at the remote
end. While this may not tell them much about what specific hosts the
victim has access to reach, it can easily leak general egress
filtering information.
--=20
Jeremy Stanley

["signature.asc" (application/pgp-signature)]

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic