Module 7: Cross-Origin Attacks
Same-Origin Policy
Accessing the CORS Sandbox
Introduction to the Same-Origin Policy
SameSite Cookies
Cross-Site Request Forgery (CSRF)
Detecting and Preventing CSRF
Exploiting CSRF
Case Study: Apache OFBiz
Accessing Apache OFBiz
Apache OFBiz - Discovery










Apache OFBiz - Exploitation




Revising the CSRF Payload
Cross-Origin Resource Sharing (CORS)
Anatomy of the CORS Request
Response Headers
Exploiting Weak CORS Policies
Weak CORS Policies - Discovery



Trusting Any Origin


Improper Domain Allowlist
Last updated