* Not yet widely supported
"The issue involves a third-party vendor that Equifax uses to collect website performance data, and that vendor's code running on an Equifax website was serving malicious content. Since we learned of the issue, the vendor's code was removed from the webpage and we have taken the webpage offline to conduct further analysis."
(https://www.cnbc.com/2017/10/12/equifax-says-it-might-have-been-breached-again.html
Exploiting CORS Misconfigurations for Bitcoins and Bounties
James Kettle
http://blog.portswigger.net/2016/10/exploiting-cors-misconfigurations-for.html
Get involved in the Rochester OWASP Chapter
https://www.owasp.org/index.php/Rochester
JohnNKing.com/slides/rss2017
github.com/JohnNKing/appsecdemo-php
John N. King <john@westwindsecurity.com>
Mary Beth King <marybeth@westwindsecurity.com>
This presentation made possible by:
Rochester Security Summit
Rochester Chapter of OWASP
Slides made with Reveal.js