- From: Zack Weinberg <notifications@github.com>
- Date: Sat, 13 May 2017 07:49:23 -0700
- To: whatwg/fetch <fetch@noreply.github.com>
- Cc: Subscribed <subscribed@noreply.github.com>
Received on Saturday, 13 May 2017 14:49:59 UTC
Please consider adding the ports used for Microsoft's SMB protocol (139, 445) to the "bad port" blacklist. This is prompted by the [MS17-010](https://github.com/RiskSense-Ops/MS17-010) exploit, but there's quite a long history of remotely exploitable SMB bugs. This will, at least, make it harder to [scan for exploitable systems](http://www.andlabs.org/tools/jsrecon/jsrecon.html) from a malicious website. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/whatwg/fetch/issues/544
Received on Saturday, 13 May 2017 14:49:59 UTC