CORS Misconfiguration
Abuse permissive cross-origin policies to read authenticated responses from a victim's browser.
Tags: cors, authz, data-theft
Level: intermediate
Method
Probe ACAO reflection
Send an Origin header and see if it's reflected in Access-Control-Allow-Origin, especially with Access-Control-Allow-Credentials: true.
curl -s -H 'Origin: https://evil.com' https://target.com/api/me -ITools: httpx
Test weak validation
Try null origin, suffix/prefix matches (target.com.evil.com), and unescaped-dot regex bypasses.
curl -s -H 'Origin: null' https://target.com/api/me -IExploit
Host a page that fetches the victim's authenticated endpoint with credentials and exfiltrates the response. Impact = account data theft.
Field notes
- Reflected Origin + Allow-Credentials:true is almost always a finding.
- null origin is reachable via a sandboxed iframe or data: URL.