Other nomination
Unveiling vulnerabilities in WebSocket APIs
The slides survey WebSocket API weaknesses, including cross-site hijacking through weak Origin checks and missing authentication or object-level authorization on messages. They also show how incomplete reverse-proxy upgrade validation can turn a WebSocket tunnel into arbitrary HTTP access to internal endpoints.
Record
- Researcher
- Mikhail Egorov
- Published by
- Speaker Deck
- Date
- Format
- Slides
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Mikhail Egorov, first published at the original source. Preserved copies are kept so the citation survives its host.