Comment by ale42

Comment by ale42 3 days ago

3 replies

As far as I understand it, it is supposed to be a scan done by the browser on the user's computer, not an external scan, which a browser extension wouldn't be able to detect.

vaylian 3 days ago

I see. So the website would try to access private IP adresses (RFC 1918) by having elements like <iframe src="http://10.0.0.1"> in the web site and then the web site would check if the iframe was loaded successfully?

  • Delk 3 days ago

    It could also just try making the request with javascript. Or try a websocket connection.