3 ms·
Seems I was wrong. I am utterly surprised at the lack of security in modern browsers. Yes, that backend is misconfigured, but why this request is even allowed t
by thwaysec 1y ago
Seems I was wrong. I am utterly surprised at the lack of security in modern browsers. Yes, that backend is misconfigured, but why this request is even allowed to take place in the first place is utterly mindblowing to me.
- shakna 1y agoWhere did the browser go wrong, here? They followed all security practices. The browser isn't what is running the payload. Unless, you're suggesting that nobody should be able to download programs, unless blessed by some large company?
- thwaysec 1y agoThe browser is allowing remote code to talk with 127.0.0.1
- shakna 1y agoRight... And that's only blocked in the host asks for it via CORS, or Same-Origin policies. Because otherwise you break any combination of apps. It's up to the server on the localhost not to blindly trust. And has been since the beginning.
- thwaysec 1y agoMight have been there since the beginning, but doesn't make it less surprising or bad. That's a _ridiculously_ bad thing to allow. Any website to talk with just about ANY port on your local machine. Incredible.
- immibis 1y agoBecause the browser tells the backend exactly where the request came from, and the backend agrees to allow requests from there.
- bdavbdav 1y agoWhat would you suggest the browser did? All it’s does is sends the correct origin - as it would be - downloads.asus.badsite(.)com