Skip to content
← LibraryTechnique entry
W-CSWSHImpact

Cross-Site WebSocket Hijacking (CSWSH)

WebSocket handshake auth via cookies + no Origin check — attacker origin opens an authenticated WS to the target.

§ Where this technique fits

W-CSWSH is catalogued under the Impact tactic of the offensive-security kill-chain. It appears in 0 approved dossiers in the registry, typically.