4 ms·
hidden img tags to all common gateways (eg 192.168.0.1) are loaded in background And why would browsers allow this? If I connect to external IP address, why wo
by revanx_ 6y ago
hidden img tags to all common gateways (eg 192.168.0.1) are loaded in background
And why would browsers allow this? If I connect to external IP address, why would the browser happly parse such html tags that allows introspection of my local network? Unless of same origin, browsers should not allow this, seems like a bug.
- ship_it 6y agoFrom an Infosec perspective, this is normal. CORS should be put on place per local network visibility or host to disallow such feature.
- revanx_ 6y agoI thought CORS is blocked by default in modern browsers?
- 19870213 6y agoCORS is only applied to javascript, not GET requests via img, link or other tags that load resources.
- wongarsu 6y agoIt is, but it's a bit leaky simply because it's such a late addition. Img tags aren't subject to CORS (you can display images from anywhere). Access to the loaded image data is CORS controlled, but the onload and onerror handlers or the dimensions of the final img tag aren't restricted. If you know for example the path of the netgear logo on a router, you can try loading it and determine success/failure. Existing CORS isn't strict enough to prevent this, and it's debatable whether it should be
- intricatedetail 6y agoWhat are the arguments against?
- wongarsu 6y agoIf we could go back 30 years we might decide that img tags can only show images from the same domain. That would also have solved the whole hotlinking mess of the 2000s. We might also decide that img tags need explicit width/height declarations. That would also have prevented lots of reflow issues. But we didn't do either of those. Changing that now would be too disruptive, the web is built on the assumption of basically eternal backwards compatibility. And with the amount of insight JavaScript has into the DOM of its own page it's basically impossible to hide the dimensions of a rendered element such as an image. So once you have an img tag without explicit size declaration, onload is basically a performance optimization that could be replaced by polling the position of surrounding elements.
- deleted 6y ago[deleted]
- fulafel 6y agoThe browser can't know what's an external or internal address (not that even we humans have a meaningful definition, not really a compatible concept with current networking) This is one of the reasons network level controls are problematic and the solution is being reinvented as "zero trust networking".
- revanx_ 6y agoBut it does know, 192.168.x.x is a reserved private network address.
- fulafel 6y agoRFC1918 space and cgn nat space etc are ambiguous addresses (vs unique like global ip space), but can be external or internal from your pov depending on circumstances.
- fulafel 6y agoReplying to myself with an addition: RFC1918 addresses are strictly worse wrt making up network level policy than normal IP addresses, you can apply the same rules for normal addresses on your network with the advantage that you know what they mean. (Good reason to prefer IPv6 too)
- nl 6y agoPages with mixed content isn't uncommon on corporate intranets. There's an argument against it, but it has always been allowed for things like images so far.