> For the complete documentation index, see [llms.txt](https://gowthams.gitbook.io/bughunter-handbook/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://gowthams.gitbook.io/bughunter-handbook/intresting-vulnerabilities/web-sockets.md).

# Web Sockets

* Whats Wrong With WebSockets - <https://speakerdeck.com/0ang3el/whats-wrong-with-websocket-apis-unveiling-vulnerabilities-in-websocket-apis?slide=7>
* <https://footstep.ninja/posts/websockets-testing/>
* <https://ysamm.com/?p=363>
* <https://www.blackhillsinfosec.com/how-to-hack-websockets-and-socket-io/>
* <https://medium.com/@osamaavvan/exploiting-websocket-application-wide-xss-csrf-66e9e2ac8dfa>
* <https://twitter.com/Hfuhs/status/1470855248596058127?s=20>
*
