Aerosol Posted January 13, 2015 Report Posted January 13, 2015 Cross Site Request Forgery? No trust relationship between browser and router? Can’t forge Basic Authentication credentials? Anti-CSRF? Limited by the same origin policy? DNS Rebinding? Rebinding prevention by OpenDNS / NoScript / DNSWall? Most rebinding attacks no longer work? Most…Read More: https://www.defcon.org/images/defcon-18/dc-18-presentations/Heffner/DEFCON-18-Heffner-Routers.pdf Quote