Re: Ban ICE-LITE? webRTC and Content Security Policy connect-src

On 12 January 2018 at 14:52, Lennart Grahl <lennart.grahl@gmail.com> wrote:
> I'm not sure restricting STUN/TURN servers, or banning ICE lite, or what
> you've suggested now would resolve this issue:
>
> What if I create an RTCPeerConnection and I use allowed STUN/TURN
> servers (if any). I create an offer and provide a fake answer with some
> data encoded as part of ICE ufrag/pwd. Then I'll pass fake remote
> candidates that include an IP I want to send this information to. The
> ICE agent will start sending STUN binding requests to that IP which
> contains my data as part of the username. Shouldn't that work?

B-R-I-L-L-A-N-T

-- 
Iñaki Baz Castillo
<ibc@aliax.net>

Received on Friday, 12 January 2018 13:55:40 UTC