Deprecate 0.0.0.0 for Private Network Access
chromestatus.com
chromestatus.com
It seems they're saying if you have a service listening to localhost (private), Chrome is supposed to not resolve 0.0.0.0 (public) to localhost, yet it currently does so.
So seems to me they're solving a security bug. But if I got this right, it's surprising how it got like that in the first place, doesn't make sense in any scenario I can think of to resolve 0.0.0.0 to localhost? Why would a browser try to resolve 0.0.0.0 to anything in the first place?
>>develop their tools / libraries according to whatever they feel it is the cool kids currently do?<<
versus:
>>adhere to the letter of the spec maliciously instead of understanding current practice.<<
$ ping 0.0.0.0
PING 0.0.0.0 (127.0.0.1) 56(84) bytes of data.
64 bytes from 127.0.0.1: icmp_seq=1 ttl=64 time=0.028 ms
64 bytes from 127.0.0.1: icmp_seq=2 ttl=64 time=0.056 ms
64 bytes from 127.0.0.1: icmp_seq=3 ttl=64 time=0.105 ms
...
$ nc 0.0.0.0 22
SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.10
...Incidentally, this is not a legitimate use-case. It's insane to me that companies act like blatant violations of the CFAA are okay. You are not authorized to start scanning a user's private network and making requests to internal services because they loaded a web page.
The engineers, managers, and product people involved in doing that kind of thing should be prosecuted for it.
IIRC adding 0.0.0.0 0.0.0.0 to your hosts file helps ???
On macOS;
% ping 0.0.0.0 PING 0.0.0.0 (0.0.0.0): 56 data bytes ping: sendto: Socket is not connected ping: sendto: Socket is not connected Request timeout for icmp_seq 0 ping: sendto: Socket is not connected Request timeout for icmp_seq 1 ping: sendto: Socket is not connected Request timeout for icmp_seq 2 ping: sendto: Socket is not connected Request timeout for icmp_seq 3
% ping 0 PING 0 (0.0.0.0): 56 data bytes ping: sendto: Socket is not connected
ping: sendto: Socket is not connected Request timeout for icmp_seq 0 ping: sendto: Socket is not connected Request timeout for icmp_seq 1 ping: sendto: Socket is not connected Request timeout for icmp_seq 2 ping: sendto: Socket is not connected Request timeout for icmp_seq 3 ping: sendto: Socket is not connected
Is this correct ???
Yup because typically you're not running a webserver on 0.0.0.0, especially not one that listen on ports 80/443 (say in dev you may be listening to 8080 or something).
I mean: on Linux if you ping 0.0.0.0 (or the shortcut "ping 0"), you'll be getting answers from 127.0.0.1.
But as I don't run a webserver on my machine (except a dev one at times, on a specific port which is not 80/443/8080 etc.), routing domains to 0.0.0.0 still works.
I also used in the past dnsmasq to automatically reply NX_DOMAIN when the browser attempts to resolve 0.0.0.0 but atm I'm not even bothering (maybe I should do it again after reading TFA though).
P.S: it's another aging brain answering, so take this with a grain of salt