1. Web Security Academy
  2. WebSockets
  3. Lab

Lab: Manipulating the WebSocket handshake to exploit vulnerabilities


This online shop has a live chat feature implemented using WebSockets.

It has an aggressive but flawed XSS filter.

To solve the lab, use a WebSocket message to trigger an alert() popup in the support agent's browser.