Hacker News new | ask | show | jobs
by heax 1634 days ago
That is how I understood it also.

The new part of their discovery is that visiting a malicious website can run the attack on servers in the private network via a JavaScript application and websockets.

That means even applications which are not exposed to the internet can be attacked.

1 comments

still confused why browsers allow private network access from non-private domains