1. CORS 安全:超越基本配置 博客 | 2025-11-21 00:00 | aikido.dev | 原文 ↗ | #appsec | #browser-security | #web-security
2. 设置Access-Control-Allow-Origin: *的安全风险 研究 | 2025-03-17 01:38 | projectblack.io | 原文 ↗ | #web-security | #data-exfiltration | #cors
3. URL验证绕过速查表正式发布 研究 | 2024-09-05 12:36 | portswigger.net | 原文 ↗ | #burp-suite | #ssrf | #open-redirect
4. 绕过浏览器跟踪保护以滥用 CORS 配置错误 研究 | 2024-01-25 13:37 | swarm.ptsecurity.com | 原文 ↗ | #browser-security | #web-security | #cors
5. 使用 Semgrep 保护你的 Apollo GraphQL 服务器 博客 | 2023-08-29 12:00 | blog.trailofbits.com | 原文 ↗ | #graphql | #csrf | #static-analysis
6. 利用 CORS 配置错误赚取比特币和赏金 研究 | 2022-08-16 09:24 | portswigger.net | 原文 ↗ | #bug-bounty | #web-security | #misconfiguration
7. 如何在代码审查中发现失效的访问控制漏洞(第 2 部分) 博客 | 2022-01-05 00:00 | hackerone.com | 原文 ↗ | #access-control | #code-review | #privilege-escalation
8. 绕过 AngularJS 的 bind HTML 研究 | 2020-09-08 12:23 | portswigger.net | 原文 ↗ | #xss | #portswigger | #cors
9. CORS 正在过时吗? 博客 | 2017-09-06 00:00 | bishopfox.com | 原文 ↗ | #browser-security | #web-security | #w3c