Collected research
We Still Don't Have Secure Cross-Domain Requests: an Empirical Study of CORS
We Still Don't Have Secure Cross-Domain Requests: an Empirical Study of CORS (Paper)
Studies how CORS simple requests carry crafted headers and binary bodies across origins. Concrete cases include server-header-limit cookie inference and binary requests to an internal AFP service. Browser and framework testing also examines unsafe origin trust. These attacks distinguish permission to send a request from permission to read its response.
Record
- Document
- We Still Don't Have Secure Cross-Domain Requests: an Empirical Study of CORS (Paper)
- Researcher
- Jianjun Chen, Jian Jiang, Haixin Duan, Tao Wan, Shuo Chen, Vern Paxson and Min Yang
- Published by
- USENIX
- Format
- Whitepaper
- Topic
- Browser
In the archive
Related sources
- We Still Don't Have Secure Cross-Domain Requests: an Empirical Study of CORS (Slides) Slides
- Conference recording
- Intranet shell demonstration
- AFP file creation demonstration
Tags
This page is the archive's own catalogue record. The research is the work of Jianjun Chen, Jian Jiang, Haixin Duan, Tao Wan, Shuo Chen, Vern Paxson and Min Yang, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .