Skip to content

This repository provides an HTML file containing a JavaScript script designed to test for Cross-Origin Resource Sharing (CORS) vulnerabilities.

Notifications You must be signed in to change notification settings

exploit-development/cors-vulnerability-test

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 

Repository files navigation

CORS Vulnerability Test

Overview

This repository provides an HTML file containing a JavaScript script designed to test for Cross-Origin Resource Sharing (CORS) vulnerabilities. The script uses XMLHttpRequest to make a cross-origin request to a target site with an insecure CORS configuration and post the endpoint data to Burp Collaborator.

Note: This HTML file is intended for ethical and educational purposes only. Ensure you have proper authorization before testing on any website. Unauthorized testing may violate terms of service and legal agreements.

Instructions

  1. Clone or download this repository to your local machine.

  2. Open the provided HTML file (cors-test.html) in a text editor of your choice.

  3. Replace VULNERABLE_ENDPOINT_HERE with the API endpoint of the target site you want to test for CORS vulnerabilities.

  4. Replace YOUR_COLLABORATOR_URL with your burp collaborator URL

  5. Save the changes to the file.

  6. Open the HTML file in the web browser.

  7. If vulnerable, the data will be sent to Burp Collaborator with a GET request.

Caution: Use this HTML file responsibly and only on websites where you have explicit permission to test. Unauthorized testing may lead to legal consequences.

Disclaimer

This HTML file is provided for educational and testing purposes only. The author is not responsible for any misuse or damage caused by the use of this file. Ensure compliance with applicable laws and ethical guidelines when conducting security testing.

About

This repository provides an HTML file containing a JavaScript script designed to test for Cross-Origin Resource Sharing (CORS) vulnerabilities.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages