> Begin forwarded message: > > From: Monty Solomon <[email protected]> > Subject: 0.0.0.0 Day: Exploiting Localhost APIs From the Browser > Date: August 10, 2024 at 22:44:30 EDT > > 0.0.0.0 Day: Exploiting Localhost APIs From the Browser > > Oligo Security's research team recently disclosed the “0.0.0.0 Day” > vulnerability. This vulnerability allows malicious websites to bypass > browser security and interact with services running on an organization’s > local network, potentially leading to unauthorized access and remote code > execution on local services by attackers outside the network. > > The issue stems from the inconsistent implementation of security mechanisms > across different browsers, along with a lack of standardization in the > browser industry. As a result, the seemingly innocuous IP address, 0.0.0.0, > can become a powerful tool for attackers to exploit local services, including > those used for development, operating systems, and even internal networks. > > ... > > https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser > >
-- Iw mailing list [email protected] http://sticklist.org/mailman/listinfo/iw_sticklist.org
