How to Steal Secrets from Developers Using Websocketsby@stestagg
3,621 reads

How to Steal Secrets from Developers Using Websockets

May 22nd 2020
4 min
by @stestagg 3,621 reads
tldt arrow
Read on Terminal Reader🖨️
JS🚫

Too Long; Didn't Read

Websockets allow browsers to open websockets connections to localhost without many protections. This got me thinking that popular JavaScript frameworks use websockets in development to automatically reload pages when content changes. Could a malicious website eaves-drop on that traffic, and find out when developers are saving their code? A simple web server that uses hot-reloading can be used to eavesdrop on web-socket messages being sent by a local dev server to my local browser. We use this to extract useful data from developers working on top secret projects.

Companies Mentioned

Mention Thumbnail
Mention Thumbnail
featured image - How to Steal Secrets from Developers Using Websockets
Steve Stagg HackerNoon profile picture

@stestagg

Steve Stagg
react to story with heart

RELATED STORIES

L O A D I N G
. . . comments & more!
Hackernoon hq - po box 2206, edwards, colorado 81632, usa