Article 6PTZN 0.0.0.0 Day: Exploiting Localhost APIs From the Browser (Oligo Security)

0.0.0.0 Day: Exploiting Localhost APIs From the Browser (Oligo Security)

by
corbet
from LWN.net on (#6PTZN)
The Oligo Security blog disclosesa web-browser vulnerability that has been named "0.0.0.0 day". In short,browsers will allow JavaScript code to open connections to the all-zeroesIPv4 address; the result is that any port that is open on the local hostcan be accessed by a remote site. "When services use localhost, theyassume a constrained environment. This assumption, which can (as in thecase of this vulnerability) be faulty, results in insecure serverimplementations."
External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments