It's not WebSockets it's your broken proxy
blog.pusherapp.com
It's not WebSockets it's your broken proxy
1–7 of 7 posts
Re: It's not WebSockets it's your broken proxy
#2Re: It's not WebSockets it's your broken proxy
#3I'd expect to see exploits using Flash sockets as the attack vector before seeing attacks using native WebSockets.
Re: It's not WebSockets it's your broken proxy
#4I'd expect to see exploits using Flash sockets as the attack vector before seeing attacks using native WebSockets.
A vast majority of the installations with these types of vulnerable firewalls don't allow outbound traffic on port 843 which flash needs to be able to communicate on to get raw socket communication permission.
Re: It's not WebSockets it's your broken proxy
#5Re: It's not WebSockets it's your broken proxy
#6Earlier quoted context omitted.
A vast majority of the installations with these types of vulnerable firewalls don't allow outbound traffic on port 843 which flash needs to be able to communicate on to get raw socket communication permission.
Where are you getting the 20-30x number from? There is no demonstrated WebSockets attack in the "Transparent Proxies: Threat or Menace?" paper.