5 ms·
> My question is: What is the risk of running one of these servers and then visiting some random web page? It depends on what you're exposing on those ports. I
by maratd 7y ago
> My question is: What is the risk of running one of these servers and then visiting some random web page?
It depends on what you're exposing on those ports. If it's something sensitive, stop. Any web page can run javascript and as such, any web page has access to every port and service that your machine has access to ... because at that point, the web page is a program running on your machine with full network access.
However, this entire "vulnerability" makes no sense to me. Even if I'm running something on my machine or local network, I am not going to rely on the firewall as a security mechanism. That is profoundly stupid and is well known to be profoundly stupid. So all those servers, including the ones I am creating and running, will have their own security mechanisms. So you can ping my server? So what?
- echeese 7y agoIf it's got CORS enabled you can do a hell of a lot more than ping your server.
- maratd 7y agoWait, what? I think you means the opposite. If it's got CORS enabled, then you can't do anything unless the request is originating from the relevant domain. Anyway, do not rely on firewalls (and CORS is a firewall) as the sole security measure. Do not create unauthenticated endpoints unless you want everybody to use them.
- echeese 7y agoTo elaborate, I meant a permissive CORS policy, which is what I see most often.