0.0.0.0 Day: Exploiting Localhost APIs from the Browser
oligo.security
oligo.security
[1] https://github.com/nccgroup/singularity/wiki/Protection-Bypa...
[2] https://research.nccgroup.com/2023/04/27/state-of-dns-rebind...
server {
listen 80 default_server;
server_name _; # some invalid name that won't match anything
return 444;
}
And do the same thing for server_name localhost. For actual apps you are building, use a server_name like myapp.local rather than localhost. (edit: formatting)As a user, an already available mitigation step is using uBlock Origin and enabling the prebundled "Block Outsider Intrusion into LAN" list. It's been an option for years and protects against this very vector (including 0.0.0.0).
That should give you an idea of how novel this finding is, BTW.
E.g.
> Browsers—we’ve all got a favorite, and we all use them daily. Even non-browser applications often load resources from external domains, like when using Google Analytics and similar client-side SDKs or embedding scripts or videos.
> With the 0.0.0.0 Day vulnerability,, a single request can be enough to cause damage.
The repetitive "Oligo [Researchers] [discovered/found] ..." adds to this.