What are SOP, CORS and ways to exploit it

Same-Origin-Policy (or SOP) and Origin-Resource-Sharing (or CORS)are the key security concepts in web application. This post would focus the concepts around these topics. Also, we would discuss some common approaches used to exploit it.

Before go deep in what SOP is, we first need to understand definition of same origin. Same origin means two site with exact same protocol, host name and port. Here are some examples:


