CORS || Bypass CORS Misconfiguration Leads to Sensitive Exposure POC || Cashfree || Bug Bounty

Поделиться
HTML-код
  • Опубликовано: 26 окт 2024

Комментарии • 33

  • @thechannelofmine
    @thechannelofmine 6 месяцев назад +6

    You already have access to these endpoints + there's no sensitive information inside them only public info, it's an informative in the best case.

  • @Adarsh.-.
    @Adarsh.-. 16 дней назад

    Bro i got my domain reflection in request but when i add the target in HTML code and try to open it, it's giving me 403. Any idea how to bypass this?

  • @cyber_india
    @cyber_india 3 месяца назад +2

    This vulnerability is N/A

  • @pra15mesh
    @pra15mesh 5 месяцев назад

    where did you reported this vulnerability? like do they have bb program or email from website only?

  • @baraamansi7637
    @baraamansi7637 Год назад +1

    Bro if you can access it by default ,why the need for CORS ?!

    • @CybeR_FrosT
      @CybeR_FrosT  Год назад

      We need to check is there CORS misconfiguration vulnerability or not

    • @baraamansi7637
      @baraamansi7637 Год назад

      thanks for the reply dude!!
      So if there was proper authorization control on the endpoint you would exploit the CORS misconfiguration ,but in your case its just Sensitive Data Exposure by just navigating to the endpoint ,right??!@@CybeR_FrosT

  • @coffinplayz
    @coffinplayz Год назад +3

    can you please explain both exploit bcz i know first one but not second...also the given link of github have not that script plz paste it in comment if possoble..

    • @kirtimanmohanty7575
      @kirtimanmohanty7575 3 месяца назад

      github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CORS%20Misconfiguration

  • @CyberNinja-p1t
    @CyberNinja-p1t 8 месяцев назад +1

    bounty?

  • @0xSaikat
    @0xSaikat 4 месяца назад

    how to get the html code ?

  • @cinematicRecapss
    @cinematicRecapss 8 месяцев назад +1

    is getting the /wp/v2/users/ also a vuln ?

  • @brice2825
    @brice2825 Год назад

    Bro , did you buy burpsuite professional or crack ?

  • @SankoIGL
    @SankoIGL Год назад

    What is the Bypass here?

  • @deglorexgaming9273
    @deglorexgaming9273 Год назад

    need both scripts...
    where i will get?

    • @CybeR_FrosT
      @CybeR_FrosT  Год назад +2

      github.com/swisskyrepo/PayloadsAllTheThings/blob/master/CORS%20Misconfiguration/README.md

  • @monKeman495
    @monKeman495 Год назад +1

    rewarded ?

    • @CybeR_FrosT
      @CybeR_FrosT  Год назад

      Yup💲💲💲💲😉

    • @jwd42
      @jwd42 Год назад

      ​@@CybeR_FrosT1000$ 😅I know

  • @lukeastorw
    @lukeastorw Год назад

    critical??

  • @Digital_Hawks7
    @Digital_Hawks7 Месяц назад

    N/A😂

  • @jwd42
    @jwd42 Год назад

    Platform.... Hackerone?Yogosha😊

  • @jwd42
    @jwd42 Год назад

    Bro i message you on LinkedIn