Overview
Cross-Origin Resource Sharing (CORS) controls which origins can access resources. Misconfigured CORS headers allow attacker’s site to read responses from victim’s authenticated session.Key Headers
Detection
Check Headers
Variations to Test
Vulnerable Configurations
1. Origin Reflection
Server reflects anyOrigin header back.
2. Null Origin Allowed
3. Weak Regex
Server checks if origin contains target domain:4. Wildcard with Credentials
5. Pre-Domain Wildcard
Exploitation — Origin Reflection
https://evil.com → victim visits → their authenticated data sent to attacker.
Exploitation — Null Origin
Origin: null.
Exploitation — Subdomain Takeover + CORS
If*.TARGET.com is allowed and an unused subdomain exists:
- Take over
unused.TARGET.com(dangling CNAME, cloud service) - Host exploit on
unused.TARGET.com - CORS allows it → read authenticated responses