3 ms·
This would lead to a massive confused deputy vulnerability for unix domain sockets as already exists for localhost + port. For a great example of this, see how
by paroneayea 3y ago
This would lead to a massive confused deputy vulnerability for unix domain sockets as already exists for localhost + port.
For a great example of this, see how Guile's live REPL was localhost + port... cool, only local users could access it, right? Except browsers could access localhost + port, and it turned out this was a path to being able to do arbitrary code execution in the browser https://lists.gnu.org/archive/html/guile-user/2016-10/msg00007.html https://lists.gnu.org/archive/html/guile-user/2016-10/msg000...
Switching to unix domain sockets was the recommended path, and that's only because browsers don't support them.
If you want to support unix domain sockets, you could, but it would have to be via object capability security discipline, and the poster explicitly talks about an ACL "protecting" things... it wouldn't.
Luckily this is 3 years old and hopefully will never make progress.
- eqvinox 3y ago> Switching to unix domain sockets was the recommended path, and that's only because browsers don't support them. Maybe the recommended path should have been to implement some actual security? > https://lists.gnu.org/archive/html/guile-user/2016-10/msg00007.html https://lists.gnu.org/archive/html/guile-user/2016-10/msg000... > DNS rebinding attack Can't DNS rebind to a "unix socket address" — feels like that by itself would considerably improve security for anything you're working on locally?