CORS Exploit

Published: 04 April 2022
on channel: All about Hacking
5,169
like

Summary(What is CORS): Cross-origin resource sharing (CORS) is a browser mechanism that enables controlled access to resources located outside of a given domain. However, it also provides the potential for cross-domain-based attacks, if a website's CORS policy is poorly configured and implemented. CORS can be exploited to trust any arbitrary domain attacker-controlled domain name and send the data to it. Attackers can make an exploit and ask the domain to send data of the victim to the attacker domain.
Severity: High
Impact: An Adversary can carry out CORS attack to exfiltrate the sensitive details of a victim
Recommendations: All the REST Api's should be authenticated and the domain should not trust any other domains. Allow only selected, trusted domains in the Access-Control-Allow-Origin header.

Commands: curl https://Domain -I -H Origin:evil.com

★★★ Contact me ★★★

📍Medium:   / karandarjishack  

📍 Instagram:   / karandarjishack  

📍Twitter:   / karandarjishack  

📍Github: https://github.com/karandarjishack


On this page of the site you can watch the video online CORS Exploit with a duration of hours minute second in good quality, which was uploaded by the user All about Hacking 04 April 2022, share the link with friends and acquaintances, this video has already been watched 5,169 times on youtube and it was liked by like viewers. Enjoy your viewing!