Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This problem doesn't just apply to localhost, although it's most straightfoward to exploit that way. You could also use this technique to scan the user's LAN or, in a more targeted attack, bypass IP address restrictions on specific servers.

Scripts from the public Internet shouldn't be able to access private or local networks as a matter of policy.

Similarly, in a high-security environment, scripts from a private network shouldn't be able to access the public Internet - to help prevent exfiltration of private data.



> Scripts from the public Internet shouldn't be able to access private or local networks as a matter of policy.

I agree, and it's encouraged some pretty stupid practices where it is used for things other than espionage or malicious intent.

Lenovo has a driver detection / update tool on their website, to run it you download a helper application that opens up a HTTP endpoint on localhost, then their website uses it to scan your system and (hopefully) shuts it down afterward. Why was this done in the first place, forcing users to download and run an executable (which has to be restarted each time you scan) that has no UI except for the web browser tab you already have open is dumb.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: