<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WebSockets on an's security blog</title><link>https://panman4040.github.io/training/portswigger/websocket/</link><description>Recent content in WebSockets on an's security blog</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 15 Jul 2026 08:36:00 +0700</lastBuildDate><atom:link href="https://panman4040.github.io/training/portswigger/websocket/index.xml" rel="self" type="application/rss+xml"/><item><title>Manipulating the WebSocket handshake to exploit vulnerabilities | &lt;span style="color:#3498db">Practitioner&lt;/span></title><link>https://panman4040.github.io/training/portswigger/websocket/ws_practitioner1/</link><pubDate>Fri, 03 Jul 2026 15:39:16 +0800</pubDate><guid>https://panman4040.github.io/training/portswigger/websocket/ws_practitioner1/</guid><description>&lt;p>Since the only useful functionality on the lab is the live chat feature, we will be trying out payloads on it, but this proved much harder than I thought (lol).&lt;/p>
&lt;p>After sending the WebSocket message to Repeater and crafting a simple &lt;code>alert&lt;/code> payload, we are immediately IP banned with no room to spare (damn).
&lt;img src="https://panman4040.github.io/images/301b9b8d-fd58-4c94-83bb-a5d4d52610e9.jpg" alt="">
Upon inspection of the WebSocket history, we should see that the server detects our payload as an attack and acts accordingly:
&lt;img src="https://panman4040.github.io/images/2feb5ab7-2051-4c54-a515-25006951804d.jpg" alt="">&lt;/p></description></item></channel></rss>