paint-brush
How to Steal Secrets from Developers Using Websocketsby@stestagg
3,677 reads
3,677 reads

How to Steal Secrets from Developers Using Websockets

by Steve Stagg4mMay 22nd, 2020
Read on Terminal Reader
Read this story w/o Javascript
tldt arrow

Too Long; Didn't Read

Websockets allow browsers to open websockets connections to localhost without many protections. This got me thinking that popular JavaScript frameworks use websockets in development to automatically reload pages when content changes. Could a malicious website eaves-drop on that traffic, and find out when developers are saving their code? A simple web server that uses hot-reloading can be used to eavesdrop on web-socket messages being sent by a local dev server to my local browser. We use this to extract useful data from developers working on top secret projects.

Companies Mentioned

Mention Thumbnail
Mention Thumbnail
featured image - How to Steal Secrets from Developers Using Websockets
Steve Stagg HackerNoon profile picture
Steve Stagg

Steve Stagg

@stestagg

L O A D I N G
. . . comments & more!

About Author

Steve Stagg HackerNoon profile picture
Steve Stagg@stestagg

TOPICS

THIS ARTICLE WAS FEATURED IN...

Permanent on Arweave
Read on Terminal Reader
Read this story in a terminal
 Terminal
Read this story w/o Javascript
Read this story w/o Javascript
 Lite
Therecord
Constantcontact
Sta
Gitlab
Learnrepo
Wellthissucks