Hacker News .hnnew | past | comments | ask | show | jobs | submitlogin

It's a common bypass of server side request forgery filtering. Backends will try to validate that a user-submitted url doesn't resolve to an internal IPv4 address, but they'll happily allow an IPv6 mapped version for the same IPv4 address.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: