4 ms·
Thanks. When I saw the title I assumed it was a network exploit related to the localhost 127.0.0.1 etc.
by bumblebird 17y ago
Thanks. When I saw the title I assumed it was a network exploit related to the localhost 127.0.0.1 etc.
- tptacek 17y agoAnd then you clicked through and you were all, like, "dammit, I was hoping to read about a vulnerability that could only be exploited by an attacker who could already run code on the target by using sockets, but it turns out it was really about a vulnerability that could only be exploited by an attacker who could already run code on the target using the environment!", and I am very sorry for misleading you.
- bumblebird 17y agoUm chill out. It could have been some weird IP spoofing attack where the host gets confused and thinks a remote connection is actually localhost and grants it some privilege or other. For example maybe you have a ton of services setup to only listen on localhost:port. Maybe there's some exploit that allows connections from outside. That's what the title sounds like to me, which is quite different. anyway.