Corsy is a lightweight program that scans for all known misconfigurations in CORS implementations.
Requirements
It only works with Python 3 and has the following dependencies:
To install these dependencies, navigate to the tool directory and execute pip3 install -r requirements.txt
Usage
Using it is pretty simple
python3 corsy.py -u https://example.com
Scan URLs from a file
python3 corsy.py -i /path/urls.txt
Number of threads
python3 corsy.py -u https://example.com -t 20
Also Read – AntiCheat : Framework To Test Any Anti-Cheat
Delay between requests
python3 corsy.py -u https://example.com -d 2
Export results to JSON
python3 corsy.py -i /path/urls.txt -o /path/output.json
Custom HTTP headers
python3 corsy.py -u https://example.com –headers “User-Agent: GoogleBot\nCookie: SESSION=Hacked”
Skip printing tips
-q can be used to skip printing of description, severity, exploitation fields in the output.
Tests implemented
Both git fetch and git pull talk to a remote repository, but they do very different things to your…
Sometimes the change you need already exists, just on the wrong branch. A hotfix lands…
Email is still one of the most important communication channels inside modern applications. Password resets,…
Nginx is a high-performance web server and reverse proxy trusted by some of the largest…
ufw (Uncomplicated Firewall) sits on top of iptables (or nftables on newer systems) and replaces…
When you share a server with a team or investigate unexpected activity, the first question…