This looks neat, but it seems like DNS Rebinding is likely more powerful here -- that would get you access to servers on the entire local network (not just the victim's own machine) without having to know the local browser's own IP first, so both the exploitation potential and the ease of carrying out the attack seem better for DNS Rebinding to me.
Also, DNS Rebinding exposes services which are only listening on local interfaces (127.0.0.1) and I suppose this wouldn't.
Could someone help me understand some common circumstances in which using NAT Slipstreaming would be a better choice?