Found the error Not allowed to load local resource: file:///etc/passwd while looking at infosec.pub’s communities page. There’s a community called “ignore me” that adds a few image tags trying to steal your passwd file.

  • BlueBockser@programming.dev
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    But… why? Why even put that URL there? Even if it was most likely harmless for all users, this still looks like an attempt at data exfiltration.

    • himazawa@infosec.pub
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 year ago

      Because I wanted to try if others URI schemas were supported instead of http / https. file:// was a valid one. Don’t worry, the day an attempt of data exfil will happen, you will not see it though your console logs.