Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

does teamviewer start any webserver on a local port which the banking page could connect to and check a _running_ instance? Would be much more interesting for fraud detection than a _installed_ instance


I can confirm 100% that there are banks checking to see if teamviewer ports are open.


you can't query local services from a remote webpage unless you use a dns rebinding attack which is probably a bit over the top for "whitehat" activity.


I have encountered numerous sites that port scan localhost via websocket/img onerror/etc.


The point of a check like this wouldn't be to bypass a firewall, just to see if the port is open on your public IP.


shouldn’t it work by using websockets to localhost?



but only because the local service in this example is not prepared to accept the websocket connection, the teamviewer client would be able to do this to enable some functions on the teamviewer website if a instance is running




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: