
DEF COPN 32 - 0 0 0 0 Day Exploiting Localhost APIs From The Browser - Avi Lumel skyGal Elbaz
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 27:16
A critical vulnerability in all browsers allows malicious websites to bypass private network protections and execute code on internal services using the IP address 0.0.0.0 24:00-24:05.
Key Takeaways:
• The IP address 0.0.0.0 bypasses Private Network Access (PNA) security measures, allowing public websites to access local network services 12:21-12:25
• This vulnerability has existed for 18 years, affecting Mac OS and Linux systems (Windows blocks it at OS level) 9:02-9:05
• Researchers demonstrated RCE by exploiting Ray (AI framework) dashboards running on Local Host through a single HTTP request 15:01-15:04
• All major browsers have implemented fixes - Safari patched it in WebKit, Chrome deprecated 0.0.0.0, and Firefox updated the Fetch standard 20:00-20:04
This vulnerability highlights that localhost should no longer be considered a trusted security boundary 24:55-25:00.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[Applause] hello everyone Hi everyone thank you for attending our talk uh 000000 day um I don't know if you've uh heard or saw the news it got a little bit of coverage but this is the first time that we're actually disclosing the technical details it's going to be fun it's going to be risky and uh let's start so uh I'm G I'm the co-founder and CTO of oo security with me is AI our number one ninja and um really quickly about ourself before we start and begin hi I'm uh AI I'm AI security researcher in the city office of oligo I have around 10 years of experience in uh research and development mostly researching AI these days and uh I love to climb mountains so if you want to join me on the trip let me know and with me my is my awesome CTO thank you AI I'm paying you to say good things about …