[ More On Local Web Servers ]
Just thought I'd post a little discovery I made on the plane-ride home from San Jose. I was looking around in the C:\WINDOWS\system32\drivers\etc directory where the "hosts" file resides and found a file called "networks".
data:image/s3,"s3://crabby-images/6ce5e/6ce5e1d21c26ebd025f4fe9a103df504f48a7f5e" alt=""
In this file there's a line that looks like this:
loopback 127
Interesting. I fired up my little web server script that I wrote in Perl, entered "http://loopback" into the address bar of Internet Explorer and magically, I'm in the Local Intranet zone, our sweet spot from my previous post on this topic.
data:image/s3,"s3://crabby-images/6bb14/6bb1477b39ea6c806b0a68bcbad9d7b13eb687b6" alt=""
So this is yet another way we can perform Cross Zone Scripting if there's an XSS on a locally running web server.
Labels: computers, internet explorer, local intranet zone, local web servers, localhost, loopback, security, xss
0 Comments:
Post a Comment
<< Home