[HN Gopher] LAN-port-scan forbidder, browser addon to protect pr...
       ___________________________________________________________________
        
       LAN-port-scan forbidder, browser addon to protect private network
        
       Author : gry_gh
       Score  : 38 points
       Date   : 2022-01-15 13:18 UTC (9 hours ago)
        
 (HTM) web link (github.com)
 (TXT) w3m dump (github.com)
        
       | synthos wrote:
       | Does anyone have ideas for Firefox on mobile? It looks like OP
       | add-on isn't supported on Android Firefox.
        
         | rand0mx1 wrote:
         | Use ublock origin and add Block Access to LAN filter list.
        
       | anthropodie wrote:
       | I don't think this is useful because you may install this on your
       | browser but what about others who are on same network?
        
         | rovr138 wrote:
         | There are many what if's, but are they always true?
         | 
         | What if you live alone?
        
       | gk1256 wrote:
       | Extension will fail for Websocket connections since manifest
       | fails to include ws protocol.
        
       | donkarma wrote:
       | webscan doesn't work on my browser
        
       | josefx wrote:
       | > Some manufacturers provide web for user's browser to scan LAN
       | for their product that need updating.
       | 
       | So random websites can scan for out of date network components? I
       | have no words.
        
         | [deleted]
        
         | nitrogen wrote:
         | Every random flashlight app has full network access, too. It's
         | insane.
        
           | suifbwish wrote:
           | Yup I recall seeing simple calculator and alarm clock apps
           | that want full network access, microphone, camera, photos,
           | contacts and Bluetooth.
        
         | tomudding wrote:
         | Scanning the LAN through your browser is nothing new. JS-Recon
         | from AnD Labs [0] is a tool from 2010 that could do it. I have
         | seen eBay [1], Facebook [2], and Halifax [3] do it too, albeit
         | for other reasons than scanning for outdated devices
         | (fraud/loss prevention). LexisNexis' ThreatMetrix [4] is
         | commonly used to do this.
         | 
         | Please note that this is a copy of a comment I made 2 years ago
         | and I have not tested the links to see if they are still
         | correct.
         | 
         | [0]:
         | https://web.archive.org/web/20101128053633/http://www.andlab...
         | 
         | [1]: https://forum.ultravnc.net/viewtopic.php?f=7&t=33509
         | 
         | [2]:
         | https://www.reddit.com/r/AskNetsec/comments/4j0nas/why_is_fa...
         | 
         | [3]:
         | https://www.theregister.com/2018/08/07/halifax_bank_ports_sc...
         | 
         | [4]: https://risk.lexisnexis.com/products/threatmetrix
        
           | howdydoo wrote:
           | [3] is pretty insane. They have to scan my network to check
           | for malware... does that mean I can scan their network to
           | check for malware?
        
       | formerly_proven wrote:
       | See also: https://wicg.github.io/private-network-access/
        
         | omgitsabird wrote:
         | And https://developer.chrome.com/blog/private-network-access-
         | upd...
        
           | howdydoo wrote:
           | Are there any test pages where I can see if I'm vulnerable to
           | this? I've been assuming that uMatrix prevents this, but this
           | post is a good reminder to double-check
        
       | gry_gh wrote:
        
       ___________________________________________________________________
       (page generated 2022-01-15 23:01 UTC)