diff --git a/strix/skills/vulnerabilities/cors_misconfiguration.md b/strix/skills/vulnerabilities/cors_misconfiguration.md new file mode 100644 index 00000000..d42c7a6c --- /dev/null +++ b/strix/skills/vulnerabilities/cors_misconfiguration.md @@ -0,0 +1,147 @@ +--- +name: cors-misconfiguration +description: CORS misconfiguration testing for cross-origin theft of authenticated data via ACAO reflection, null origin, and weak origin validation +--- + +# CORS Misconfiguration + +Cross-Origin Resource Sharing misconfigurations let a malicious site read authenticated responses from a victim's session. This is distinct from CSRF: CSRF abuses ambient authority to *send* state-changing requests, while broken CORS lets the attacker *read* the cross-origin response (PII, tokens, CSRF tokens, API keys). The dangerous combination is a reflected or overly-trusting `Access-Control-Allow-Origin` together with `Access-Control-Allow-Credentials: true`. + +## Attack Surface + +**Credentialed APIs** +- Cookie- or HTTP-auth-backed JSON/REST and GraphQL endpoints that return user data + +**Response Headers** +- `Access-Control-Allow-Origin` (ACAO), `Access-Control-Allow-Credentials` (ACAC) +- `Access-Control-Allow-Methods/Headers`, `Access-Control-Expose-Headers` + +**Token-in-Body/Header APIs** +- Endpoints returning bearer tokens, API keys, or CSRF tokens where `ACAO: *` still exposes data to any origin + +## High-Value Targets + +- `/api/me`, `/account`, `/profile`, session and settings endpoints +- Endpoints returning CSRF tokens, bearer tokens, or API keys +- Internal admin dashboards trusting `*.corp` or `localhost` origins +- OAuth/OIDC userinfo and token introspection endpoints +- GraphQL endpoints reachable via GET + +## Reconnaissance + +### What to Send + +- Add an `Origin:` header to every authenticated request and inspect the response ACAO/ACAC +- Test with a clearly external origin: `Origin: https://evil.example` +- Test `Origin: null` +- Test a subdomain: `Origin: https://attacker.target.com` +- Compare responses with and without the `Origin` header to detect reflection + +### Signals of Weakness + +- ACAO exactly reflects the arbitrary `Origin` you sent +- `ACAO: null` is returned +- `ACAC: true` present alongside a reflected or wildcard-ish ACAO +- ACAO derived from `Origin` via substring/regex rather than an exact allowlist + +## Key Vulnerabilities + +### Origin Reflection + Credentials + +- Server copies the request `Origin` into ACAO and sets `ACAC: true` +- Any attacker origin can `fetch(..., {credentials:'include'})` and read the response +- Highest severity: full cross-origin theft of authenticated data + +### Null Origin Trust + +- `ACAO: null` with `ACAC: true` +- The `null` origin is produced by sandboxed iframes, `data:`/`file:` documents, and some redirects +- Exploit: `