• Dave@lemmy.nz
    link
    fedilink
    arrow-up
    4
    ·
    6 hours ago

    The linked blog post explains about the vulnerability, I thought it was quite interesting.

    • Possibly linux
      link
      fedilink
      English
      arrow-up
      25
      ·
      12 hours ago

      On Linux it is just a catch all address (listen on all interfaces)

      Elsewhere it doesn’t do anything since I don’t believe it is part of the networking standards

        • sugar_in_your_tea@sh.itjust.works
          link
          fedilink
          arrow-up
          2
          ·
          44 minutes ago

          If I were implementing it, I’d just list all interfaces on the machine and see if there’s a service bound to it on the given port. There’s probably only one, but it’s technically undefined behavior I think.

    • sugar_in_your_tea@sh.itjust.works
      link
      fedilink
      arrow-up
      1
      ·
      46 minutes ago

      0.0.0.0 binds to all addresses on the machine for servers, but I don’t know what a browser would do when trying to resolve it. I guess look at all addresses on the machine and see if anything has bound to the indicated port on that address? First one it finds wins?

    • flux@lemmy.ml
      link
      fedilink
      English
      arrow-up
      3
      ·
      5 hours ago

      Do you have standard Firefox with default options that does this? This has not been my experience.

      You could try out with a new profile if it works out the same.

          • RedWeasel@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            32 minutes ago

            Unable to connect

            Firefox can’t establish a connection to the server at 192.168.2.210.

            The site could be temporarily unavailable or too busy. Try again in a few moments.
            If you are unable to load any pages, check your computer’s network connection.
            If your computer or network is protected by a firewall or proxy, make sure that Firefox Developer Edition is permitted to access the web.
            

            I don’t see an error in the log about the specific page I am trying to access, but another had a link to https://support.mozilla.org/en-US/kb/https-only-prefs

            • Possibly linux
              link
              fedilink
              English
              arrow-up
              1
              ·
              11 minutes ago

              I don’t think they ware going to start disabling http. Http is needed in a lot of cases to get https plus there are still use cases for http like testing.

              Have you fired up Wireshark and looked at what port it is connecting to?

  • Eager Eagle@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    12 hours ago

    Fine by me. I self-host a lot of stuff but never used 0.0.0.0 for browsing, so I just disabled it here to try it out.

  • HubertManne@moist.catsweat.com
    link
    fedilink
    arrow-up
    5
    arrow-down
    10
    ·
    12 hours ago

    seriously. I like the federation but people way overuse the spoiler tag or nsfw or whatever. I usually skip over but had to vent. Oh uh. ankle in this one. better make sure no one gets fired over it.