Web Hack List

Collected research

Bypass firewalls with of-CORs and typo-squatting

Bypass firewalls with of-CORs and typo-squatting ◆ Truffle Security Co.

Shows that internal corporate web apps often enable wildcard CORS without authentication, and that an attacker can reach them by registering typo variants of a company's internal domain. A mistyped visit registers a background service worker that keeps probing internal hosts after the browser is redirected away, reporting back which are readable and their page content.

Record

Document
Bypass firewalls with of-CORs and typo-squatting ◆ Truffle Security Co.
Researcher
Chris Grayson
Published by
trufflesecurity.com
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Chris Grayson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .