7 ms·
The greater issue is that browsers are allowing code executing from the public Internet scope (scope meaning security domain) network access to the localhost sc
by souterrain 6y ago
The greater issue is that browsers are allowing code executing from the public Internet scope (scope meaning security domain) network access to the localhost scope or the Intranet scope (RFC1918 addresses.)
If anything, this should require very explicit permission granting from the user. I’d prefer it be something more like an undocumented toggle accessible solely to developer types.
- api 6y agoYeah, that's the best solution. It should be like microphone or camera access. It should say "this web site is attempting to access a resource on your local system / network." I don't think you need to overdo it in terms of making the warning red, etc. Just a popup will really discourage people from trying to use this for fingerprinting. BTW the site says: "Port scanning is malicious." I don't agree. There are many many things that can look like a port scan but are not malicious, most notably NAT traversal attempts by WebRTC, games, chat apps, and so on.
- grendelt 6y agoRight. "it is clearly malicious behavior and may fall on the wrong side of the law." It's not against the law. It might be _shady_ but it's not illegal. When I'm teaching cyber intro classes, I let folks know portscanning is NOT illegal but shady. It's like going to a business after hours. It's not illegal to rattle doors and windows to see if they're locked. The police might have a different take on it, but it's not illegal.
- fossuser 6y agoYeah - if anything this post is evidence of a use case that isn't malicious. While it can be used to get information to bad things, it itself can be used for good things too.
- alex_duf 6y agoAgreed, or at least disabling localhost and 192.168.0.1 and whatever that is in IPV6
- pantalaimon 6y agoYou will usually have a public address with IPv6
- n0tam3m3 6y agoThe company may be interested in whether they want to grant access to the user to access to their systems. Does the user shoulder any responsibility?
- imglorp 6y agoNo, absolutely not. It shouldn't matter what malware is on a client device as long as the client has authenticated; the server/company/ebay should be protecting their API from abuse at the API layer, not the client layer.
- souterrain 6y agoI think what you’re saying is the user might be an employee on some internal trusted company network. The employer should have control of that browser (and entire endpoint), otherwise the network should likely not be considered trusted. So, in this case, no, the user shouldn’t have the ability to authorize this; the administrator of that browser should. Know your network.
- 3fe9a03ccd14ca5 6y agoConsent.
- marcojrfurtado 6y agoThere are legitimate reasons for port scanning, but I'm not sure most websites out there are using it for noble purposes. I guess browsers could allow it based on explicit permission from the user, just like it's already done for microphone and camera.
- souterrain 6y agoPort scanning from a user’s browser is effectively sneaking behind a user’s firewall. The only legitimate reasons I can envision are security research, and this, to me, is such a small edge case that I’m not sure such access is ever warranted. I’d be all for a user notification that says “fnord.com wants to access 192.168.0.10 on tcp/443, which seems to be a web server on your home/work network. Are you sure you want to allow this?” I’d want to see this for each new access request, such that port scanning would not be a use case that was supported. Sure, have an about:config toggle to shut this off, with appropriate warnings.
- asudosandwich 6y ago>> There are legitimate reasons for port scanning Such as?
- jimmaswell 6y agoIRC servers detect open proxies that way.
- jorams 6y ago
- marcosdumay 6y ago> to the localhost scope or the Intranet scope That's too little. All access from a different origin should be blocked by default, not only to local nets.
- oplav 6y agoThat's what CORS is for, but it appears that there is no CORS for WebSockets.
- souterrain 6y agoCORS is not in the hands of the user. I don’t want a CORS policy authorizing access to my intranet or localhost.
- oplav 6y agoIf the user decides to run a service on their intranet or localhost with a wide open CORS policy, isn't that their choice? Forgoing CORS and making all inter domain requests user opt-in would make the web experience a lot worse, IMO. Making all intranet or localhost requests user opt-in seems less disruptive.
- souterrain 6y agoHowever, TCP sockets can't publish CORS policies. In the case of scanning, a CORS denial can still reveal information about the user's internal network, as a CORS denial is a different result than a network timeout or a TCP RST.
- kevingadd 6y agoCORS is set by the target, so localhost CORS policy is directly in the hands of the user. intranet CORS policy is set by whoever operates that intranet service
- souterrain 6y ago
- _bxg1 6y agoYes, it's very similar to CORS. They just need to block all localhost requests from non-localhost pages. Maybe carve out an exception for when the dev tools are open.
- csagan5 6y agoExactly, port scans on my public IP address are not an attack, but crossing the boundary to my localhost and private networks is malicious behavior.
- titzer 6y agoServes you right for browsing the web, you dumb dummy! /s