Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Learn how to exploit localhost APIs from web browsers through a critical security vulnerability in this 40-minute conference talk from BSidesSF 2025. Discover how services running on localhost, despite appearing local and secure, can actually be accessed by browsers through a newly discovered flaw that exposes ports on the localhost network interface. Explore the technical details of the 0.0.0.0 exploit research, understand how this vulnerability opens the door to remote network attacks, and examine the implications for web application security. Gain insights into browser security mechanisms, localhost networking vulnerabilities, and the potential attack vectors that emerge when local services become remotely accessible through browser-based exploitation techniques.
Syllabus
BSidesSF 2025 - 0.0.0.0 Day: Exploiting Localhost APIs From The Browser (Gal Elbaz)
Taught by
Security BSides San Francisco