Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, any website can detect your local IP address, then use ajax to scan a targeted IP subnet range fairly quickly (and completely hidden from the user) to find any shitty CORS-enabled web interface your company has (think some "modern" internal accounting webapp that enables CORS for its "API").

Prior to WebRTC you'd have to scan much larger IP ranges to try and find internal network webapps that are CORS enabled.



Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: