The Alt-Svc HTTP header can be used for scanning ports in an internal network.
Researchers from Boston University have developed an attack method (CVE-2019-11728) that allows scanning of IP addresses and open network ports in a user's internal network, separated from the external network by a firewall, or on the current system (localhost). The attack can be executed by opening a specially crafted page in a browser. The proposed technique is based on the use of the HTTP header Alt-Svc (HTTP Alternate Services, RFC-7838). The issue manifests itself […]
