Web Hack List

Other nomination

Bypass firewalls with of-CORs and typo-squatting

Shows that internal corporate web apps often enable wildcard CORS without authentication, and that an attacker can reach them by registering typo variants of a company's internal domain. A mistyped visit registers a background service worker that keeps probing internal hosts after the browser is redirected away, reporting back which are readable and their page content.

Record

Researcher
Chris Grayson

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Chris Grayson, first published at the original source. Preserved copies are kept so the citation survives its host.