[HN Gopher] LAN-port-scan forbidder, browser addon to protect pr...
___________________________________________________________________
LAN-port-scan forbidder, browser addon to protect private network
Author : gry_gh
Score : 38 points
Date : 2022-01-15 13:18 UTC (9 hours ago)
(HTM) web link (github.com)
(TXT) w3m dump (github.com)
| synthos wrote:
| Does anyone have ideas for Firefox on mobile? It looks like OP
| add-on isn't supported on Android Firefox.
| rand0mx1 wrote:
| Use ublock origin and add Block Access to LAN filter list.
| anthropodie wrote:
| I don't think this is useful because you may install this on your
| browser but what about others who are on same network?
| rovr138 wrote:
| There are many what if's, but are they always true?
|
| What if you live alone?
| gk1256 wrote:
| Extension will fail for Websocket connections since manifest
| fails to include ws protocol.
| donkarma wrote:
| webscan doesn't work on my browser
| josefx wrote:
| > Some manufacturers provide web for user's browser to scan LAN
| for their product that need updating.
|
| So random websites can scan for out of date network components? I
| have no words.
| [deleted]
| nitrogen wrote:
| Every random flashlight app has full network access, too. It's
| insane.
| suifbwish wrote:
| Yup I recall seeing simple calculator and alarm clock apps
| that want full network access, microphone, camera, photos,
| contacts and Bluetooth.
| tomudding wrote:
| Scanning the LAN through your browser is nothing new. JS-Recon
| from AnD Labs [0] is a tool from 2010 that could do it. I have
| seen eBay [1], Facebook [2], and Halifax [3] do it too, albeit
| for other reasons than scanning for outdated devices
| (fraud/loss prevention). LexisNexis' ThreatMetrix [4] is
| commonly used to do this.
|
| Please note that this is a copy of a comment I made 2 years ago
| and I have not tested the links to see if they are still
| correct.
|
| [0]:
| https://web.archive.org/web/20101128053633/http://www.andlab...
|
| [1]: https://forum.ultravnc.net/viewtopic.php?f=7&t=33509
|
| [2]:
| https://www.reddit.com/r/AskNetsec/comments/4j0nas/why_is_fa...
|
| [3]:
| https://www.theregister.com/2018/08/07/halifax_bank_ports_sc...
|
| [4]: https://risk.lexisnexis.com/products/threatmetrix
| howdydoo wrote:
| [3] is pretty insane. They have to scan my network to check
| for malware... does that mean I can scan their network to
| check for malware?
| formerly_proven wrote:
| See also: https://wicg.github.io/private-network-access/
| omgitsabird wrote:
| And https://developer.chrome.com/blog/private-network-access-
| upd...
| howdydoo wrote:
| Are there any test pages where I can see if I'm vulnerable to
| this? I've been assuming that uMatrix prevents this, but this
| post is a good reminder to double-check
| gry_gh wrote:
___________________________________________________________________
(page generated 2022-01-15 23:01 UTC)