Skip to main content

Awesome information for WebSockets security research

310
GitHub Stars
63
Curated Resources
7
Categories
5 hours ago
Last Refreshed
WebSocket Library Vulnerabilities2011Common WebSocket WeaknessesDOM-based WebSocket-URL poisoningUseful Blog Posts & ResourcesWebSocket Security ToolsBug Bounty Writeups

Use this list with your AI agent

Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:

"Show me other bugs resources from awesome-websocket-security"

Installation instructions →

What's inside

Bug Bounty Writeups

WebSocket Library Vulnerabilities

WebSocket Security Tools

DOM-based WebSocket-URL poisoning

Common WebSocket Weaknesses

  • LinkUnencrypted WebSockets

  • LinkCross-Site WebSocket Hijacking (CSWSH)

  • LinkCross-Site WebSocket Hijacking (CSWSH)

  • LinkInsecure Authentication Mechanism

  • LinkInsecure Authentication Mechanism

  • LinkReverse Proxy Bypass using Upgrade Header

Useful Blog Posts & Resources

2011

  • Paper

  • Video2012

    Mike Shema, Sergey Shekyan, Vaagn Toukharian - Hacking with WebSockets

  • Video2019

    Mikhail Egorov - What’s Wrong with WebSocket APIs? Unveiling Vulnerabilities in WebSocket APIs

  • Video2019

    Michael Fowl, Nick Defoe - Old Tools New Tricks Hacking WebSockets

Showing a sample of 63 resources. View the full list on GitHub →