阿甘 on Nostr: 直接插cloudflared 內網滲透 我猜可能是這個問題 Cross origin headers ...
直接插cloudflared 內網滲透
我猜可能是這個問題
Cross origin headers
Servers MUST set the Access-Control-Allow-Origin: * header on all responses to ensure compatibility with applications hosted on other domains.
For preflight (OPTIONS) requests, servers MUST also set, at minimum, the Access-Control-Allow-Headers: Authorization, * and Access-Control-Allow-Methods: GET, PUT, DELETE headers.
The header Access-Control-Max-Age: 86400 MAY be set to cache the results of a preflight request for 24 hours.
Published at
2025-05-12 01:31:08Event JSON
{
"id": "a435ea8c5724b023b89ed978355e3a5cca7a1f0fd33116812351c6cd26c5515d",
"pubkey": "8888888890493e0c6a6e4a24ae3319a0d7fc595ca3d8e5cae19954e1139008d3",
"created_at": 1747013468,
"kind": 1,
"tags": [
[
"e",
"7da33483a3d85e3b6f78477681d3cf20072b9d85cd1ca0815bf67625a4c5b26a",
"",
"root",
"8888888890493e0c6a6e4a24ae3319a0d7fc595ca3d8e5cae19954e1139008d3"
],
[
"e",
"cb7a9a2fd165ae6251ccd5ea14eeb736e44ca59eab14dce17a285c310f51444f",
"wss://nos.lol/",
"reply",
"ef083fa11ec451c9083bc0fec21123f3d4f87c6a922e8112398d58bdd953d6a2"
],
[
"p",
"09fbf8f3be5ae763435881698d6e845de83be9b5e1cca99988918d17fa3d60f0"
],
[
"p",
"ef083fa11ec451c9083bc0fec21123f3d4f87c6a922e8112398d58bdd953d6a2"
]
],
"content": "直接插cloudflared 內網滲透\n\n我猜可能是這個問題\n\nCross origin headers\n\nServers MUST set the Access-Control-Allow-Origin: * header on all responses to ensure compatibility with applications hosted on other domains.\n\nFor preflight (OPTIONS) requests, servers MUST also set, at minimum, the Access-Control-Allow-Headers: Authorization, * and Access-Control-Allow-Methods: GET, PUT, DELETE headers.\n\nThe header Access-Control-Max-Age: 86400 MAY be set to cache the results of a preflight request for 24 hours.",
"sig": "6f33227318c649dbe8edf3572e7377c9c6b8aa718b87555557114bb167fecf6140678bbd271c96f315a4ddb2ea41e707883b2941a2305e53a5038ed8d050dfab"
}