Decloaking an internal IP
Date: November 23, 2009 05:11PM
I want to use http://decloak.net/decloak.html in my XSS payload to extract the victim's internal IP. How can I include that script in the payload, via an iframe for example, then extract the results URL to send back to me?