Skip to content
P
非影
精选
最新
漏洞
研究
工具
主题
来源
搜索
搜索
English
面向安全从业者的中英双语安全研究与漏洞情报精选。
CORS 安全:超越基本配置
aikido.dev
| 博客 |
#appsec
|
#browser-security
|
#web-security
|
#http
|
#api
|
#cors
|
#same-origin-policy
摘要
深入解析 CORS:从同源策略(SOP)的演进讲起,说明浏览器与服务器如何协商预检请求和凭据,剖析「看似配置正确却仍失败」的常见场景,并指导如何围绕它安全设计 API。
发布时间
2025-11-21 00:00
收录时间
2026-07-04 09:33
原文 ↗
相关内容
为什么 REST 取代 SOAP 成为跨应用通信的首选
(hackerone.com)
Eradicating image authentication injection from the entire internet
(samcurry.net)
标签名称中包含什么?显然,JavaScript
(portswigger.net)
绕过浏览器跟踪保护以滥用 CORS 配置错误
(swarm.ptsecurity.com)
AI 能发明新的攻击技术吗?来自 James Kettle 和 PortSwigger Research 的新研究
(portswigger.net)
HTTP/1.1 必须消亡:攻克 0.CL 挑战
(portswigger.net)
返回