Hacker News new | ask | show | jobs
by mbrock 3263 days ago
That actually scares me enough to disable Swank on my laptop. Actually, to disable all localhost services that could by any stretch of the imagination execute code.

Tl;dr: web sites can send requests to localhost TCP sockets despite origin restrictions using a trick called DNS rebinding.

1 comments

Yes, it certainly a gaping security hope. Yet I cant bring myself to submit a patch