LAN-port-scan forbidder, browser addon to protect private network
github.com
github.com
> Chrome is deprecating direct access to private network endpoints from public websites as part of the Private Network Access (PNA) specification.
> Chrome will start sending a CORS preflight request ahead of any private network request for a subresource, which asks for explicit permission from the target server. This preflight request will carry a new header, `Access-Control-Request-Private-Network: true`, and the response to it must carry a corresponding header, `Access-Control-Allow-Private-Network: true`
> The aim is to protect users from cross-site request forgery (CSRF) attacks targeting routers and other devices on private networks. These attacks have affected hundreds of thousands of users, allowing attackers to redirect them to malicious servers.
What would a browser setting to just block all PWA requests (`DENY * TO *` (to {192.168.0.1, .1.1, .100.1,}) - regardless of the appropriate new HTTP headers - actually prevent a normal user from doing?
So random websites can scan for out of date network components? I have no words.
Please note that this is a copy of a comment I made 2 years ago and I have not tested the links to see if they are still correct.
[0]: https://web.archive.org/web/20101128053633/http://www.andlab...
[1]: https://forum.ultravnc.net/viewtopic.php?f=7&t=33509
[2]: https://www.reddit.com/r/AskNetsec/comments/4j0nas/why_is_fa...
[3]: https://www.theregister.com/2018/08/07/halifax_bank_ports_sc...
What if you live alone?