Web Hack List

Collected research

Unveiling vulnerabilities in WebSocket APIs

What’s wrong with WebSocket APIs? Unveiling vulnerabilities in WebSocket APIs.

Surveys weaknesses in WebSocket APIs: cross-site WebSocket hijacking including a null-origin variant delivered from a data URI iframe, missing authentication and object-reference checks on individual messages, and smuggling arbitrary HTTP requests to internal endpoints through reverse proxies that blindly tunnel an upgraded connection.

Record

Document
What’s wrong with WebSocket APIs? Unveiling vulnerabilities in WebSocket APIs.
Researcher
Mikhail Egorov
Published by
Speaker Deck
Date
Format
Slides
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Mikhail Egorov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .