For the complete documentation index, see llms.txt. This page is also available as Markdown.

CORS

Misconfigured CORS

Here are few methods and steps you can do to check for misconfigure cors.

  • Hunting method 1(Single target):

Step->1. Capture the target website and spider or crawl all the website using burp.
Step->2. Use burp search look for Access-Control
Step->3. Try to add Origin Header i.e,Origin:attacker.com or Origin:null or Origin:attacker.target.com or Origin:target.attacker.com
Step->4  If origin is reflected in response means the target is vuln to CORS

Automate Way :

Another Method

Tools You Will Need for this method.

Steps

Authors

Last updated

Was this helpful?