Hunt Websocket

Hunt WebSocket vulnerabilities — Cross-Site WebSocket Hijacking (CSWSH), missing/weak Origin validation on the WS handshake, no per-message authentication, message tampering, socket.io namespace/room authorization bypass, and handshake-layer Upgrade smuggling. Use when target has WebSocket endpoints (ws:// or wss://), socket.io / SignalR / Phoenix Channels, real-time features, chat, live dashboards, notifications, or trading platforms.

uphiago 5979fbe 20.0 KB Updated

File contents

uphiago/recon-skills/tree/main/redteam/hunt-websocket commit 5979fbea5a

Frequently asked questions

npx skillmds@latest add uphiago/hunt-websocket