Collected research
Bypass firewalls with of-CORs and typo-squatting
Bypass firewalls with of-CORs and typo-squatting ◆ Truffle Security Co.
Shows that internal corporate web apps often enable wildcard CORS without authentication, and that an attacker can reach them by registering typo variants of a company's internal domain. A mistyped visit registers a background service worker that keeps probing internal hosts after the browser is redirected away, reporting back which are readable and their page content.
Record
- Document
- Bypass firewalls with of-CORs and typo-squatting ◆ Truffle Security Co.
- Researcher
- Chris Grayson
- Published by
- trufflesecurity.com
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Chris Grayson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .