vulns.co
/
GKData.io MCP

Back to Workflows

WebSocket channel authorization

Verify handshake origin, token binding, subscription authorization, and unsubscribe behavior using two test accounts. Subscribe only to channels and messages created for the assessment.

Level: advanced

Tools: Burp Suite, websocat, browser devtools

Pipeline

Capture a normal subscription for Account A, then compare the server response when Account B requests Account A's controlled test channel; document authorization errors without guessing identifiers.