Web Hack List

Collected research

CORS vulnerabilities: Weaponizing permissive CORS configurations

Exploiting trust: Weaponizing permissive CORS configurations

A scan of every domain in a managed pentest estate for permissive Cross-Origin Resource Sharing, followed by exploitation, argues such findings are routinely under-rated. The article classifies the origin-validation errors seen: unconditional reflection of Origin, trusting the null origin a sandboxed iframe can send, prefix matching on the trusted domain or localhost, and blanket subdomain trust. Case studies reach session theft and account takeover.

Record

Document
Exploiting trust: Weaponizing permissive CORS configurations
Researcher
Thomas Stacey
Published by
Outpost24
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Thomas Stacey, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .