From kalilinuxtutorials.com
- Reflect Origin checks
- Prefix Match
- Suffix Match
- Not Esacped Dots
- Null
- ThirdParties (Like => github.io, repl.it etc.)
- Taken from Chenjj’s github repo
- SpecialChars (Like => “}”,”(“, etc.)
- See more in Advanced CORS Exploitation Techniques