Collected research
XSS-Track as a HTML5 WebSockets traffic sniffer
Kotowicz extends XSS-Track so one injected script sniffs HTML5 WebSocket traffic. It wraps window.WebSocket, replacing the constructor and prototype.send and attaching a message listener, so every frame sent and received is logged to the attacker's backend - showing ws:// is no safe channel for private data on a page with any XSS.
Record
- Published by
- blog.kotowicz.net
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of blog.kotowicz.net, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .