logo

How to Hack WebSockets and Socket.io

ID: 881df2b2-05de-5583-ade8-49333e46862f

STIX ID: report--881df2b2-05de-5583-ade8-49333e46862f

Feed Name: Black Hills Infosec Blog

Date Published: 2018-08-09

Date Updated: 2026-04-27

Author: BHIS

...
...

### WebSockets and socket.io testing with Burp Suite This post demonstrates practical techniques for intercepting and manipulating socket.io WebSocket communications using Burp Suite, including forcing polling transport, breaking the WebSocket upgrade handshake with match-and-replace rules, and creating session-handling macros to manage socket.io session IDs and message lengths so Repeater/Intruder testing can be performed over HTTP polling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.