The Analyzer v1.0 — autonomous bug bounty engine with 20 attack vectors and Ollama brain
This commit is contained in:
55
vectors/18-cors.sh
Executable file
55
vectors/18-cors.sh
Executable file
@@ -0,0 +1,55 @@
|
||||
#!/usr/bin/env bash
|
||||
# Vector 18: CORS Misconfiguration
|
||||
# Desc: Permissive CORS allowing cross-origin data theft
|
||||
# Detect: API endpoints with Access-Control headers
|
||||
# Severity: MEDIUM
|
||||
# Tools: curl
|
||||
|
||||
vector_cors() {
|
||||
local target="$1"
|
||||
local report="$2"
|
||||
local findings=0
|
||||
|
||||
print_info "Testing CORS configuration..."
|
||||
|
||||
local origins=("https://evil.com" "null" "https://attacker.com" "http://localhost" "https://evil.$domain")
|
||||
|
||||
for origin in "${origins[@]}"; do
|
||||
local headers=$(curl -sI --connect-timeout 5 --max-time 10 \
|
||||
-H "Origin: $origin" \
|
||||
-H "Referer: ${origin}/" \
|
||||
"$target" 2>/dev/null)
|
||||
|
||||
local acao=$(echo "$headers" | grep -i "^access-control-allow-origin:" | tr -d '\r' | sed 's/[Aa]ccess-[Cc]ontrol-[Aa]llow-[Oo]rigin: //')
|
||||
local acac=$(echo "$headers" | grep -i "^access-control-allow-credentials:" | tr -d '\r' | sed 's/[Aa]ccess-[Cc]ontrol-[Aa]llow-[Cc]redentials: //')
|
||||
|
||||
if [ -n "$acao" ]; then
|
||||
if echo "$acao" | grep -qi "^\*$"; then
|
||||
print_find "Wildcard CORS!" "Access-Control-Allow-Origin: *"
|
||||
echo "SEVERITY: MEDIUM
|
||||
VECTOR: CORS Wildcard
|
||||
DETAIL: Wildcard CORS allowed on $target
|
||||
EVIDENCE: Access-Control-Allow-Origin: *
|
||||
EXPLOIT: Cross-origin data theft from any domain" > "$REPORTS_DIR/.finding_$(date +%s)_cors-wildcard.txt"
|
||||
findings=$((findings + 1))
|
||||
break
|
||||
elif echo "$acao" | grep -qi "$origin"; then
|
||||
print_find "Reflective CORS!" "Origin $origin reflected in ACAO"
|
||||
echo "SEVERITY: MEDIUM
|
||||
VECTOR: CORS Reflection
|
||||
DETAIL: CORS reflects arbitrary origins on $target
|
||||
EVIDENCE: Origin '$origin' reflected in ACAO header
|
||||
CREDENTIALS: $acac
|
||||
EXPLOIT: Steal data via: fetch('$target', {credentials:'include'})" > "$REPORTS_DIR/.finding_$(date +%s)_cors-reflect.txt"
|
||||
findings=$((findings + 1))
|
||||
break
|
||||
fi
|
||||
fi
|
||||
done
|
||||
|
||||
if [ "$findings" -eq 0 ]; then
|
||||
print_ok "CORS configuration looks secure"
|
||||
fi
|
||||
|
||||
return $findings
|
||||
}
|
||||
Reference in New Issue
Block a user