TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Crossing the Mixed Content Boundary: Abusing Stun/Turn as Communication Channel

1 点作者 gyf30410 个月前

1 comment

ggm10 个月前
Stun can also leak local IP info. A couple of years back I managed to satisfy myself and a co-researcher you could use a reference to a stun/turn instance to reveal local IP bindings behind the NAT. It's in the enumerated service capability list (I don't know the proper name for this but it was something the web clients of the day proferred when taken to the URL in the right way)