Decoding BlazorPack
ID: 5800835c-7fd4-5a12-a2bb-bcd6ff1af637
STIX ID: report--5800835c-7fd4-5a12-a2bb-bcd6ff1af637
Feed Name: SensePost Blog
This post explains how to analyze and tamper with server-side Blazor (BlazorPack) WebSocket traffic by using Mallet instead of BurpSuite, which lacks support for aggregating continuation frames. It outlines a Netty-based pipeline (SOCKS, SSL sniffing, HTTP/WebSocket upgrade, Protobuf varint framing, and MessagePack decoding/encoding), provides Groovy scripts for dynamically inserting codecs after the initial JSON negotiation, and references required libraries—enabling researchers to convert opaque binary streams into readable, modifiable objects.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
