Civilloquy
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Dnb@lemmy.dbzer0.com to Technology@beehaw.orgEnglish · 11 months ago

0.0.0.0 Day - 18 Yr Old Vulnerability Let Attackers Bypass All Browser Security

cybersecuritynews.com

external-link
message-square
8
fedilink
55
external-link

0.0.0.0 Day - 18 Yr Old Vulnerability Let Attackers Bypass All Browser Security

cybersecuritynews.com

Dnb@lemmy.dbzer0.com to Technology@beehaw.orgEnglish · 11 months ago
message-square
8
fedilink
alert-triangle
You must log in or register to comment.
  • tyler@programming.dev
    link
    fedilink
    arrow-up
    20
    ·
    11 months ago

    The article literally doesn’t explain the vulnerability at all.

    • floofloof@lemmy.ca
      link
      fedilink
      English
      arrow-up
      21
      ·
      edit-2
      11 months ago

      It keeps promising to, then goes off into more ChatGPT-style rambling. It’s a bad article. This one is more informative:

      https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser

      • Kissaki@beehaw.org
        link
        fedilink
        English
        arrow-up
        15
        ·
        edit-2
        11 months ago

        notably

        Windows is not impacted by this issue.

        quoting the main, critical part:

        1. Under public domain (.com), the browser sent the request to 0.0.0.0.
        2. The dummy server is listening on 127.0.0.1 (only on the loopback interface, not on all network interfaces).
        3. The server on localhost receives the request, processes it, and sends the response.
        4. The browser blocks the response content from propagating to Javascript due to CORS.

        This means public websites can access any open port on your host, without the ability to see the response.

    • The Doctor@beehaw.org
      link
      fedilink
      English
      arrow-up
      8
      ·
      11 months ago

      Everybody who could explain it well is at Hacker Summer Camp right now.

      • unconfirmedsourcesDOTgov@lemmy.sdf.org
        link
        fedilink
        arrow-up
        4
        ·
        11 months ago

        I didn’t realize DEFCON was this weekend already, but this is a solid point 😂

  • Boomkop3@reddthat.com
    link
    fedilink
    arrow-up
    4
    ·
    11 months ago

    Welp, I guess sandboxing a browser that has a sandbox might still be a good idea

  • Destide@feddit.uk
    link
    fedilink
    English
    arrow-up
    4
    ·
    11 months ago

    hunter2 Wow it works!

  • ssm@lemmy.sdf.org
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    11 months ago

    Yes! Another huge win for links2gang !links2@lemmy.sdf.org

Technology@beehaw.org

technology@beehaw.org

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@beehaw.org

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:

  • Free and Open Source Software
  • Programming
  • Operating Systems

This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 228 users / day
  • 521 users / week
  • 1.7K users / month
  • 5.46K users / 6 months
  • 1 local subscriber
  • 39.5K subscribers
  • 2.95K Posts
  • 37.2K Comments
  • Modlog
  • mods:
  • alyaza [they/she]@beehaw.org
  • TheRtRevKaiser@beehaw.org
  • gyrfalcon@beehaw.org
  • rs5th@beehaw.org
  • coldredlight@beehaw.org
  • Leigh@beehaw.org
  • TheRtRevKaiser@kbin.social
  • Chris Remington@beehaw.org
  • BE: 0.19.5
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org