hunt-websocket - Hunt WebSocket security vulnerabilities
Hunt WebSocket vulnerabilities by discovering endpoints, testing handshakes, assessing authentication and authorization, and validating impact.
Tags
Updated: 2026-10-08Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Discover WebSocket endpoints
- Probe WebSocket handshakes
- Assess CSWSH exposure
- Test message authorization
- Test signed-message replay
- Fingerprint socket.io versions
- Validate vulnerability impact
Inputs
- Authorized target scope
- Written testing authorization
- Target URLs or IPs
- Test account credentials
- Reconnaissance artifacts
- WebSocket testing tools
Outputs
- WebSocket endpoint inventory
- Handshake responses
- Validated vulnerability findings
- Proof-of-impact evidence
Requirements
- Explicit written authorization
- Permitted target scope
- Relevant testing tools
- Controlled testing environment
