nccgroup/singularity

SOP, Blocked requests

Closed this issue · 3 comments

Hi.

Files:

imagen

imagen

imagen

imagen

It's okay. The router / gateway HTTP server has iframes protection enabled.

But why can't I connect via AJAX connection?

I have inserted in the code of the file manager.html jQuery and the function get()

imagen

However:

imagen

imagen

What is the problem?

Thank you!

gdncc commented

The "Attack Host" form field and attackHostIPAddress variable should be set to the IP address of the Singularity server, not of the victim's IP address. If you see errors due to the X-FRAME-OPTIONS header, then DNS rebinding has not happened.

Sorry, I didn't understand what you mean.

Could it be more descriptive?

What IP address should I use? The public of singularity?

gdncc commented

The public of singularity?

Yep.