Firefox 3.5 and IE8 Abused to Spy Inside Intranets

Two security researchers have devised proof-of-concept "ping sweeping" attacks, which leverage on the new Cross-Origin Resource Sharing implementation in Firefox 3.5, as well as the one already existing in Internet Explorer 8. A design weakness can allow attackers to remotely map Web servers ... [ read more >> ]

Remote intranet Web server mapping via XMLHttpRequest

Image comment: Remote intranet Web server mapping via XMLHttpRequest
Image credits: Herebe

Remote intranet Web server mapping via XMLHttpRequest