Web Hack List

Collected research

We Still Don't Have Secure Cross-Domain Requests: an Empirical Study of CORS

We Still Don't Have Secure Cross-Domain Requests: an Empirical Study of CORS (Paper)

Studies how CORS simple requests carry crafted headers and binary bodies across origins. Concrete cases include server-header-limit cookie inference and binary requests to an internal AFP service. Browser and framework testing also examines unsafe origin trust. These attacks distinguish permission to send a request from permission to read its response.

Record

Document
We Still Don't Have Secure Cross-Domain Requests: an Empirical Study of CORS (Paper)
Researcher
Jianjun Chen, Jian Jiang, Haixin Duan, Tao Wan, Shuo Chen, Vern Paxson and Min Yang
Published by
USENIX
Format
Whitepaper
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Jianjun Chen, Jian Jiang, Haixin Duan, Tao Wan, Shuo Chen, Vern Paxson and Min Yang, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .