Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

tl;dr: but only if you're inside the lan or your target has enabled remote administration.


It looks like it could be done with a DNS rebinding attack (as you need to set a special HTTP header, so normal CSRF stuff doesn't work). This would mean the victim would simply need to visit an attacker controlled webpage


Sweet, even better. Is there any mitigation for that?


Sure! Install OpenWRT or some other alternative firmware.


just make user click your crafted link, "she put it in her mouth and you wont believe what happened next!"




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: