Other nomination
UPnP Hacking via Flash
pdp and Adrian Pastor drop the XSS requirement from UPnP router attacks. Flash's URLRequest can set POST content type application/xml and add a SOAPAction header, so a plain malicious SWF sends a UPnP SOAP control message straight to the LAN router, adding port forwards or changing the primary DNS server. No same-origin bypass needed, and most consumer routers of the day ship UPnP on.
Record
- Researcher
- Adrian Pastor and pdp
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Adrian Pastor and pdp, first published at the original source. Preserved copies are kept so the citation survives its host.