Hacker News new | ask | show | jobs
by 0x0 4131 days ago
Knowing the LAN IP behind any NAT is useful for silently launching behind-the-firewall cross-site attacks against the router web admin interface (or any other local services) via a browser, without having to blindly guess addresses. Someone posted a POC LAN scanner elsewhere in a thread here, too.
1 comments

How many guesses would you need for typical NAT gateway LAN side IP?

I'd say two.