CVE-2022-41924 - RCE in Tailscale, DNS Rebinding, and You

TL;DR Recommendations

@emilyposting @jamie really enjoyed the writeup, sick work :)
@gren @emilyposting @jamie fully agree… I understood like 15% of the writeup, but it felt like a crime novel… 😍
@emilyposting @tailscale @jamie
Loved the writeup. Loved Tailscale’s response. Impressive!

@emilyposting @tailscale @jamie “If you visit my website, I am granted the honour and the privilege of executing arbitrary Javascript on your computer.”

uMatrix would like to have a word

@emilyposting @jamie Freaking awesome write-up and awesome work. And incredible speed for fixes and communication from @tailscale! Wow to all of you!

@emilyposting @tailscale @jamie Wait @tailscale is here?

I just want to say I love to see you guys on here.  

(Yes tailscale.com is verified on their profile)

@emilyposting @tailscale @jamie Nice. Just got the warning email from Tailscale to update, which is also a cool move by them.
@emilyposting @jamie Awesome, thanks for the write up! I also have to give credit to @tailscale for detecting that I had a vulnerable install, emailing me with a notification, and providing a link that showed all the vulnerable installs.

@emilyposting @tailscale @jamie

"None of these words are in the Bible."

haha, this writeup rules! thanks for it

@emilyposting Nice writeup. Seems like nearly everyone who does the "Let's expose a local-only API via HTTP" hits this trap.
@emilyposting
Very, very, good work!! Fantastic read! Well done.
@tailscale @jamie
@emilyposting @tailscale @jamie awesome!!! Never saw such a great and entertaining (not to mention educational) write up as well as such fast response from vendor. Wow!👏🏻👏🏻👏🏻
@emilyposting @jamie @tailscale what a gorgeous writeup, featuring superfluous graphviz and trains!
@emilyposting @tailscale @jamie Amazing:
> Since we can make the SMB connection over Tailscale, we bypass any network-level egress filtering of SMB connections
@emilyposting @tailscale @jamie
What an educating and fun novella, thanks for your work!
@emilyposting @tailscale @jamie this is epic!   Thank you for sharing!
@emilyposting @jamie Great write up and nice findings. Well done folks!
@emilyposting this actually introduced me to tailscale and I super appreciate it being behind cgnat
Nice work! Also, I had a lol at the perl/python expansion under Becoming the Control Plane... very droll!
@emilyposting @tailscale @jamie Incredible write-up, and an incredibly thorough response from the Tailscale team!