socket-connection

1 article
sort: new top best
clear filter
0 7/10

A researcher demonstrates a full account takeover vulnerability combining misconfigured CORS with socket-based connections. By exploiting CORS headers that allow credentials and replicating a chain of five interdependent socket requests through JavaScript, an attacker can extract sensitive session tokens from victims and hijack their accounts.

HackerOne Meteor Samuel XMLHttpRequest
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details