Главная
Study mode:
on
1
Introduction
2
What is WebSocket
3
Demo
4
WebSocket Security History
5
WebSocket Tools
6
stews
7
websocket discovery
8
websocket scanning
9
DNS lookups
10
WebSocket endpoint discovery
11
WebSocket fingerprinting
12
Top WebSocket servers
13
Comparing WebSocket fingerprinting tools
14
Identifying features
15
Test categories
16
Test case 200
17
WebSocket vulnerability detection
18
Summary
19
Suggestions
Description:
Explore the often-overlooked security aspects of WebSocket servers in this 48-minute OWASP Foundation talk by Erik Elbieh, a security researcher and consultant at Palindrome Technologies. Delve into the widespread use of WebSockets since their inception in 2010, examining their prevalence in messaging platforms, finance websites, chat bots, real-time mapping applications, and even the Kubernetes API. Learn about the distinct nature of WebSocket servers compared to traditional web servers and understand why they have escaped rigorous security scrutiny. Discover a new tool suite designed to support future WebSockets research, including utilities for discovering WebSocket server endpoints, fingerprinting servers, and detecting vulnerabilities. Gain insights into implementation-level differences across various open-source libraries and explore the talk's comprehensive syllabus covering WebSocket basics, security history, scanning techniques, fingerprinting methods, and vulnerability detection strategies. Read more

Investigating WebSocket Server Security - Beyond HTTP

OWASP Foundation
Add to list