Exploiting Persistent XSS And Unsanitized Injection Vectors For DIRECTIVEFOUR Protocol...

Discussion in 'News Aggregator' started by Packet Storm, 27 May 2022.

  1. Packet Storm

    Packet Storm Guest

    In this whitepaper, the author demonstrates abusing persistent cross site scripting and polyglot payloads can allow for robust protocol creation similar to COOLHANDLUKE and allows an attacker to exfiltrate, encapsulate, and tunnel their malicious traffic between IPv4 and IPv6 networks without a router. The author calls the technique and protocol "DIRECTIVEFOUR". This issue affects Cisco SMB and Sx Series switches.

    Continue reading...
     

Share This Page

Loading...