Web Sockets
Protocol Basics
Handshake Request
GET /chat HTTP/1.1
Host: normal-website.com
Sec-WebSocket-Version: 13
Sec-WebSocket-Key: wDqumtseNBJdhkihL6PW7w==
Connection: keep-alive, Upgrade
Cookie: session=KOsEJNuflw4Rd9BDNrVmvwBF9rEijeE2
Upgrade: websocket
Origin: https://normal-website.comHandshake Response
HTTP/1.1 101 Switching Protocols
Connection: Upgrade
Upgrade: websocket
Sec-WebSocket-Accept: 0FFP+2nmNIf/h+4BP36k9uzrYGk=Security Testing
Cross-Site WebSocket Hijacking (CSWSH)
Message Manipulation
Common Vulnerabilities
Vulnerability
Test
Testing Tools
STEWS - Security Testing for WebSockets
Burp Suite
wscat (CLI WebSocket Client)
websocat
Exploitation Scenarios
XSS via WebSocket
SQL Injection via WebSocket
Authorization Bypass
Browser Console Testing
Related Topics
Last updated
Was this helpful?