Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

localhost.microsoft.com and localhost.yahoo.com also used to redirect to 127.0.0.1. And, of course, this wreaked utter havoc with cookies (since cookies are accessible across the entire domain). Zalewski discusses in TTW (The Tangled Web).

DNS hackery is really dangerous.



I gather that Xip.io have the same issue with cookies.


Yes, but xip.io doesn't host any production services with which test cookies might interact.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: