4 ms·
Technically they can make the request. The server will receive and respond to the request. CORS is applied by the browser which prevents the response from being
by doakes 3y ago
Technically they can make the request. The server will receive and respond to the request. CORS is applied by the browser which prevents the response from being read. This is why CORS doesn't prevent a request from mutating something on a server. A CSRF token does.
- aidos 3y agoIs that true? There’s a preflight request that checks with the server as to what’s allowed and then the browser issues the original request if it’s ok, right?
- jakear 3y ago"Simple requests" are not preflighted, such as those that do not set any headers (among other qualifications). https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS#simple_requests https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS#simpl... (Aside, is MDN's href linking broken for everyone or just me?)
- bawolff 3y agoIt should be noted chrome is changing this behaviour for local networks - https://wicg.github.io/private-network-access/ https://wicg.github.io/private-network-access/
- wging 3y agoRe: your aside, the link works for me. I'm taken directly to the "Simple requests" section.
- devsegal 3y agolink works for me
- zaroth 3y ago"Simple" requests are sent without a OPTIONS preflight check. It's because old style forms could always do a cross-origin request, so you have to protect against it anyway. For the full definition of what is a "simple" request: https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS#simple_requests https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS#simpl... EDIT: Lol @ jakear making an almost identical response with the same Mozilla link.
- tomjakubowski 3y agoNot only forms, img and link tags supported cross origin sources too, with no user action required.
- thakoppno 3y agoThere are plenty of browser implementations in things like SmartTVs that don’t implement CORS and other security related features correctly.
- lights0123 3y agoFirst of all, you could probably do a timing attack on CORS response, you'd just have to deal with how much they're cached. Depends on the resource request. For example, <img> can be used to load remote resources without CORS, since the image data isn't shared with JS (trying to read it via a canvas marks it "tainted", and errors read requests). Meltdown/Spectre breaks this barrier down, which led to the introduction of COOP/COEP headers that require CORS on remote requests and would break this attack—except that you can ask the browser to send requests without cookies, re-introducing this timing attack.
- ekimekim 3y agoAnd none of this helps you if the server in question isn't actually a HTTP server, but something else (that only ever expected to be exposed on localhost). Depending on the exact syntax it expects, it's plausible that a HTTP request (even a CORS request) might be misinterpreted to do something nefarious.