TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Crossing the Mixed Content Boundary: Abusing Stun/Turn as Communication Channel

1 pointsby gyf30410 months ago

1 comment

ggm10 months ago
Stun can also leak local IP info. A couple of years back I managed to satisfy myself and a co-researcher you could use a reference to a stun/turn instance to reveal local IP bindings behind the NAT. It's in the enumerated service capability list (I don't know the proper name for this but it was something the web clients of the day proferred when taken to the URL in the right way)