HomeSecurityGoogle Chrome blocks port 10080 to stop phishing attacks...

Google Chrome blocks port 10080 to stop NAT Slipstreaming attacks

Google Chrome now blocks HTTP, HTTPS, and FTP access to TCP port 10080 to prevent port abuse in NAT Slipstreaming 2.0 attacks.

Google Chrome NAT Slipstreaming

Last year, security researcher Samy Kamkar uncovered a new version of the NAT Slipstreaming vulnerability that allows scripts on malicious websites to bypass visitors' NAT firewalls and gain access to any TCP/UDP port on the visitor's internal network.

Using these vulnerabilities, threat actors can perform a wide range of attacks, including modifying router settings and accessing private network services.

Since this vulnerability only works on specific ports monitored by a router's Application Level Gateway (ALG), browser developers block vulnerable ports that don't receive much traffic.

See also: Google Chrome: You will soon be able to restore tab groups you had closed

Currently, Google Chrome blocks FTP, HTTP, and HTTPS access to ports 69, 137, 161, 554, 1719, 1720, 1723, 5060, 5061, and 6566.

Today, Google said it plans to block TCP port 10080 in Chrome, which Firefox has already blocked since November 2020.

In discussions about whether the port should be blocked, the browser developers decided that the Amanda backup software and VMWare vCenter use the port, but would not be affected by the blocking.

See also: How to disable the "Apps" button in Google Chrome

The most worrying point about blocking port 10080 is that some developers may use it as an alternative to port 80.

To allow developers to continue using this port, Google Chrome developer Adam Rice will add a corporate policy that developers can use to bypass the blocking.

See also: How to enable Google Chrome's "Reading List" on Android

Once a port is blocked, users see an error message stating "ERR_UNSAFE_PORT" when they try to access the port, as shown below.

NAT Slipstreaming

If you are currently hosting a website on port 10080, you may want to use a different port to allow Google Chrome to continue to access the website.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS