8 ms·
Sure, but all the adversary needs is for the user to visit a webpage that makes his/her browser contact the router (i.e. from within the LAN). If the adversary
by homeomorphic 13y ago
Sure, but all the adversary needs is for the user to visit a webpage that makes his/her browser contact the router (i.e. from within the LAN). If the adversary has to take into account defeating the user's password, this becomes an impractical attack. With the backdoor, however…
- deleted 13y ago[deleted]
- xyzzy123 13y agoMight be hard to set the user-agent for a JavaScript cross-origin request though...
- throwaway2048 13y agoflash allows you to generate UPNP requests, just generate one to forward the web server port to the internet, and you have an easy solution.