The Target:
| ip: | ||
| path: | (Some testcases try to load intranet-data into an IMG-tag. For nicest visual feedback enter the path of image-file that is hosted on a private IP-address.) |
The Testcases
Image-tag with local URL
Script-tag with local URL
iFrame
IP with authentication information (thanks to RSnake)
iFrame with data-url (thanks to S. Esser)
Form with local target in iframe with data-url source (thanks to S. Esser)
Hostname (as returned by gethostbyaddr() in this case: localhost) with authentication information
301-Redirect
302-Redirect
303-Redirect
307-Redirect
Meta-Refresh
JavaScript Refresh
Dynamically filled iframe
Dynamically filled Iframe (GET):Dynamically filled Iframe (POST):