Security Research // Bountyy Oy

LocalTap

The 2026 localhost attack surface is massive and uncharted. Every developer runs unauthenticated services on localhost. This tool maps what's exposed on YOUR machine right now.
01
Visit malicious page
Victim clicks link, opens page in browser
02
Port scan localhost
Timing-based probes detect open services
03
DNS rebinding
Rebind attacker domain to 127.0.0.1
04
Same-origin access
Browser treats localhost API as same-origin
05
Exfiltrate / Execute
Read files, run models, steal tokens, RCE
Ports Scanned
0
Open / Responding
0
No Auth Required
0
DNS Rebind Possible
0