Open cardosec

Case 33B4CC · Web AppSec · L3 Applied

CORS Misconfiguration

Practise as: Explain it
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. CORS relaxes the Same-Origin Policy for reading responses; it is not a CSRF defense and does not block requests
  2. Critical bug: reflecting the Origin header into Access-Control-Allow-Origin with Allow-Credentials: true
  3. Browsers refuse the wildcard * together with credentials, which is why devs reflect Origin instead
  4. Allowing null origin is exploitable via sandboxed iframes; loose regex like endsWith(example.com) matches evilexample.com
  5. Fix: strict exact-match allowlist of origins, Vary: Origin, and no credentials unless truly needed

If the interviewer pushes back

  • Why does a preflight OPTIONS request not protect against a simple cross-origin POST?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.