Later archive addition
Übersicht Remote Code Execution, Spotify takeover: security implications of locally hosted web services
The article exploits an unauthenticated local web service exposed by Übersicht so that any visited website can submit attacker-controlled widget code and achieve host command execution. It compares the flaw with Spotify's localhost integration to show why privileged local HTTP services require strong origin and request authentication.
Record
- Researcher
- Zemnmez and @zemnmez
- Published by
- Medium
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Zemnmez and @zemnmez, first published at the original source. Preserved copies are kept so the citation survives its host.