Skip to main content

Posts

Featured

Your Localhost Is Not Private: Securing Developer Environments Against Localhost SSRF and DNS Rebinding

Most developers treat localhost as a trust boundary. Anything bound to 127.0.0.1 is assumed to be reachable only by you. That assumption has failed repeatedly, in browsers, AI tooling, dev servers and container runtimes. This article covers two related attack classes, how they hit developer machines, the browser changes of the last two years, and what to do about them. It also covers where a tunneling tool such as InstaTunnel helps and where it does not. Two attack classes, one false assumption Localhost SSRF is server-side request forgery aimed at loopback. An application fetches a URL the attacker controls (a webhook target, an image URL, a link preview) and the attacker points it at 127.0.0.1 , 0.0.0.0 or an internal address. The server then makes the request from inside the trust boundary, to services that never expected outside callers. DNS rebinding works from the browser. A victim visits an attacker's page. The attacker's domain first resolves to the attacker...

Latest Posts

Testing Local RAG Pipelines: Routing Production Webhooks to Local Vector Databases

The "No-Root" Enterprise Compliance Angle: Securing Developer Tunnels in 2026