Anu-bhav / Corsy

CORS Misconfiguration Scanner

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool


Corsy
Corsy

CORS Misconfiguration Scanner

Introduction

Corsy is a lightweight program that scans for all known misconfigurations in CORS implementations.

demo

Usage

Using Corsy is pretty simple

python corsy.py -u https://example.com

A delay between consecutive requests can be specified with -d option.

Note: This is a beta version, features such as JSON output and scanning multiple hosts will be added later.

Tests implemented

  • Pre-domain bypass
  • Post-domain bypass
  • Backtick bypass
  • Null origin bypass
  • Invalid value
  • Wild card value
  • Origin reflection test
  • Third party allowance test
  • HTTP allowance test

Support the developer

Liked the project? Donate a few bucks to motivate me to keep writing code for free.

Things I've added

Multiple target Support added by me

./multiple_targets.sh target/target

create your target file in the target folder without https://

Fixed packages not found

  • added init.py file in utils folder

Prints current target after logo

  • now corsy.py prints the current target from the script

About

CORS Misconfiguration Scanner

License:GNU General Public License v3.0


Languages

Language:Python 97.4%Language:Shell 2.6%