4 ms·
0.0.0.0 Day: Exploiting Localhost APIs from the Browser
- outsidein 2y agoText reads like AI generated logorrhea
- supermatou 2y agoIt's a pretty comprehensive article, with proofs-of-concept for several browsers, don't know why you got the impression it's junk.
- browser1 2y ago[dead]
- 3np 2y agoI wouldn't say "junk" but there's a bit too much fluff and filler. The noise-to-signal is high which makes it tiresome to dig through to the meat. E.g. > Browsers—we’ve all got a favorite, and we all use them daily. Even non-browser applications often load resources from external domains, like when using Google Analytics and similar client-side SDKs or embedding scripts or videos. > With the 0.0.0.0 Day vulnerability,, a single request can be enough to cause damage. The repetitive "Oligo [Researchers] [discovered/found] ..." adds to this.
- dytir 2y agoThis is not a zero day. The 0.0.0.0 bypass has been documented for a while now[1], including PNA bypass[2]. [1] https://github.com/nccgroup/singularity/wiki/Protection-Bypasses https://github.com/nccgroup/singularity/wiki/Protection-Bypa... [2] https://research.nccgroup.com/2023/04/27/state-of-dns-rebinding-in-2023/ https://research.nccgroup.com/2023/04/27/state-of-dns-rebind...
- 3np 2y agoThe post includes some good remediation advice for application developers at the end. As a user, an already available mitigation step is using uBlock Origin and enabling the prebundled "Block Outsider Intrusion into LAN" list. It's been an option for years and protects against this very vector (including 0.0.0.0). That should give you an idea of how novel this finding is, BTW.
- 3np 2y agohttps://github.com/easylist/easylist/issues/19041 https://github.com/easylist/easylist/issues/19041 https://github.com/uBlockOrigin/uBlock-issues/issues/1070#issuecomment-2054231917 https://github.com/uBlockOrigin/uBlock-issues/issues/1070#is...
- zapperdulchen 2y agoTldr; Enabling Block Outsider Intrusion into LAN list is the solution for this issue. (hidden in Privacy)
- putlake 2y agoAs someone who runs nginx locally for web development, this is scary. One mitigation I can think of is to use this config for you Mac's local nginx: server { listen 80 default_server; server_name _; # some invalid name that won't match anything return 444; } And do the same thing for server_name localhost. For actual apps you are building, use a server_name like myapp.local rather than localhost. (edit: formatting)