Collected research
Unveiling vulnerabilities in WebSocket APIs
What’s wrong with WebSocket APIs? Unveiling vulnerabilities in WebSocket APIs.
Surveys weaknesses in WebSocket APIs: cross-site WebSocket hijacking including a null-origin variant delivered from a data URI iframe, missing authentication and object-reference checks on individual messages, and smuggling arbitrary HTTP requests to internal endpoints through reverse proxies that blindly tunnel an upgraded connection.
Record
- Document
- What’s wrong with WebSocket APIs? Unveiling vulnerabilities in WebSocket APIs.
- Researcher
- Mikhail Egorov
- Published by
- Speaker Deck
- Date
- Format
- Slides
- Topic
- HTTP
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Mikhail Egorov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .