Testing Websocket API Security

Use when tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocket messages, insufficient input validation, denial-of-service via message flooding, and information leakage through WebSocket frames. The tester intercepts WebSocket handshakes and messages using Burp Suite, crafts malicious payloads, and tests for authorization bypass on WebSocket channels.

oyi77 12d47e8 4.3 KB Updated 10 repo stars

File contents

oyi77/1ai-skills/tree/main/cybersecurity/testing-websocket-api-security commit 12d47e8078

Frequently asked questions

npx skillmds add oyi77/testing-websocket-api-security