ContentsThe library

The Mistakes Behind Most Breaches

Your Server Can Reach Things Nobody Outside Can

Last timeRunning What You Were Given

Accept an address and fetch it, and you have offered a stranger the use of your server's network position. That position reaches administrative ports, neighbours, and credential services.

The position is the prize

The feature is ordinary and useful. Give us the address of your profile

picture and we will fetch it. Give us a link and we will show a preview.

Tell us where your webhook receiver lives. Import from this address. Here

is a document to convert, at this location.

In each case your server takes an address from a stranger and connects

to it. The thing to notice is that the stranger did not gain a file. They

gained the use of your server's position on the network, and that position

is worth far more than any single file, because a great deal of

infrastructure is protected by nothing except being hard to reach.

FIG 1The same request, from two positions
Eleven nodes, and the comparison between the two branches out of the stranger is the whole lesson. The left branch is blocked by the network boundary. The right branch asks your own server to make the request, and your server is on the inside.

What is actually reachable

Being concrete matters here, because the abstract version of this flaw

sounds minor and the concrete version does not.

FIG 2Four destination classes, by who can reach them
reachable from outside, reachable from your servtypically requires no authe destination the feat
your own server, bound l0110
a neighbour on a private0110
a link-local credential 0110
an ordinary address on t1101
Only the bottom row was intended, and only the bottom row is reachable from outside anyway. The three rows above it are the ones the feature adds, and the third column explains why they matter: those services were configured on the assumption that reaching them was the hard part.

The first class is the one teams overlook because it feels absurd: your

own server, addressed as itself. Administrative interfaces, debugging

endpoints, metrics, a database bound locally, a message broker. All of

them configured over the years on the assumption that a local caller is a

trusted caller.

The second class is the neighbours, and the shape there is a flat

internal network where services authenticate callers weakly or not at

all, because the boundary was the control.

The third class is the one that turns this from a disclosure into a

takeover: a service that exists to hand machine credentials to whatever

process asks from the right position. One fetch, and the supplied address

returns a credential for your infrastructure.

The lesson stops here

3 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01One Mistake, Wearing Different Clothes
  2. 02The Caller Is Not Running Your Softwareopening only
  3. 03The Most Common Serious Finding There Isopening only
  4. 04Follow It From the Field to the Place It Runsopening only
  5. 05Your Server Can Reach Things Nobody Outside Canyou are here
  6. 06Nobody Chose This, Which Is the Problemopening only
  7. 07Most of What You Ship, You Did Not Writeopening only
  8. 08Could You Reconstruct It Afterwardsopening only

Read alongside