The 2026 localhost attack surface is massive and uncharted.
Every developer runs unauthenticated services on localhost.
This tool maps what's exposed on YOUR machine right now.
Attack Chain
01
Visit malicious page
Victim clicks link, opens page in browser
02
Port scan localhost
Timing-based probes detect open services
03
DNS rebinding
Rebind attacker domain to 127.0.0.1
04
Same-origin access
Browser treats localhost API as same-origin
05
Exfiltrate / Execute
Read files, run models, steal tokens, RCE
Ethical Notice
This scanner probes YOUR OWN localhost only. No data is sent anywhere unless you explicitly click "Report Results".
The scan uses timing-based detection (fetch + timeout) to determine if ports respond.
This is a research demonstration of the attack surface, not an exploitation tool.