March 20, 2023, 5:08 a.m. | Serhat ÇİÇEK

InfoSec Write-ups - Medium infosecwriteups.com

In this article, we will talk about some websocket vulnerabilities. To test for security vulnerabilities, it is necessary to install the repo in the github (https://github.com/Serhatcck/vulnsocket).

After installation we see it on the login page.

Vulnsocket Login Page

We must create a user before login.

Vulnsocket Register Page

After registration we are redirected to index.php. We see two different vulnerabilities on this page.

Vulnsocket Index Page

CSWSH

Vulnsocket CSWSH Page

On this page we see a simple messaging …

cswsh server vulnerable websocket

Information Security Problem Manager

@ Deutsche Bank | Bucharest

Information System Security Officer

@ Booz Allen Hamilton | USA, VA, Chantilly (15009 Conference Ctr Dr)

Senior Account Executive - Cybersecurity

@ OpenText | Virtual, CA

Grants Compliance Senior Specialist

@ Plan International | Bamako, Mali

Sr. Cybersecurity Engineer- Tenable

@ phia, LLC | Arlington, VA

Portfolio Manager- Enterprise Information Security Auditing

@ American Chemical Society | Columbus, OH, US, 43202