Awesome Lists

awesome-websocket-security

by PalindromeLabs

awesome listpushed over 4 years ago

Awesome information for WebSockets security research

AI summary

WebSocket security info

A collection of resources and research on vulnerabilities and security best practices for WebSockets

stars
254
forks
26
watching
12
awesome list
1
entries
104
View on GitHub

Embed the badge

Show how many awesome lists link to your project. The count updates automatically.

Awesome Lists badge
Markdown
[![Awesome Lists Badge](https://awesome.facts.dev/shield/PalindromeLabs/awesome-websocket-security/links.svg)](https://awesome.facts.dev/awesome/PalindromeLabs/awesome-websocket-security)
HTML
<a href="https://awesome.facts.dev/awesome/PalindromeLabs/awesome-websocket-security"><img src="https://awesome.facts.dev/shield/PalindromeLabs/awesome-websocket-security/links.svg" alt="Awesome Lists Badge" /></a>
Image URL
https://awesome.facts.dev/shield/PalindromeLabs/awesome-websocket-security/links.svg

What's in the list

104 links in 17 sections, with live GitHub stats.activeno commit in 2y

WebSocket Library Vulnerabilities

2011

  • Paper

    Talking to Yourself for Fun and Profit

2011 / 2012

  • Video

    Blackhat 2012 - Mike Shema, Sergey Shekyan, Vaagn Toukharian - Hacking with WebSockets

2011 / 2019

  • Video

    Hacktivity 2019 - Mikhail Egorov - What’s Wrong with WebSocket APIs? Unveiling Vulnerabilities in WebSocket APIs

  • Video

    DerbyCon 2019 - Michael Fowl, Nick Defoe - Old Tools New Tricks Hacking WebSockets

2011 / 2021

  • Tool

    OWASP Global AppSec US 2021 - Erik Elbieh - We’re not in HTTP anymore: Investigating WebSocket Server Security

Common WebSocket Weaknesses / Unencrypted WebSockets

  • Link

    Black Hills WebSocket testing guide:

Common WebSocket Weaknesses / Cross-Site WebSocket Hijacking (CSWSH)

  • Link

    Original CSWSH blog post by Christian Schneider:

  • Link

    PortSwigger Web Academy CSWSH lab:

Common WebSocket Weaknesses / Insecure Authentication Mechanism

  • Link

    Stratum Security blog post:

  • Link

    Heroku WebSocket Security:

Common WebSocket Weaknesses / Reverse Proxy Bypass using Upgrade Header

  • Link

    Mikhail Egorov's initial PoC from Hacktivity 2019:

  • Link

    Jake Miller's HTTP 2 smuggling tool based on Mikhail's PoC work:

  • Link

    AssetNote blog post with golang h2smuggler tool:

DOM-based WebSocket-URL poisoning

  • Link

    Portswigger summary:

Useful Blog Posts & Resources

  • Link

    Portscanning using WebSockets

  • Link

    WebSocket fuzzing with Kitty fuzzing framework

  • Link

    WebSocket fuzzing harness

  • Link

    Project Zero WebSockets-based buffer overflow

  • Link

    Reserved Extension, Subprotocol values

WebSocket Security Tools / Discovery, Fingerprinting, Vulnerability Detection

WebSocket Security Tools / Fuzzing

  • GitHub

    websocket-fuzzer

  • GitHub

    websocket-harness

WebSocket Security Tools / Playgrounds

  • GitHub

    DVWS: A purposefully vulnerable WebSocket demo

  • GitHub

    WebSocket-Playground: Jumpstart multiple WebSockets servers

WebSocket Security Tools / General Utilities & Tools

Bug Bounty Writeups / CSWSH bugs

Bug Bounty Writeups / Other bugs

More related projects

Add a GitHub project

Missing a project or an awesome list? Paste its GitHub URL and we fetch it right away.