Hunting Websockets @AmrSecOfficial
Hunting Websockets  @AmrSecOfficial
Uploaded July 2026 | Updated September 2026, 2 hours ago
Most hunters test the app, hit 101 Switching Protocols, and move on. That is the blind spot. In this one I go fully hands-on in Caido and pull real bugs straight out of WebSocket frames: broken authorization, an IDOR that turns into a database dump through error-based SQL injection, a GraphQL subprotocol auth bypass, and a cross-site WebSocket hijack that ends in a shell. Same bugs you already hunt, hiding in the one place no scanner reads.

🎯 Get My Full Caido For Hackers Course: hhub.io/AMRCAIDO

πŸ’‘ Support AmrSec on Patreon:
patreon.com/AmrSec

πŸ”₯ Join Our Community:
Discord: discord.gg/nxHKyJTy3h

πŸ“ Resources
Video Article: amrelsagaei.com/hunting-websockets-bugs-behind-101-switching-protocols
YWH Agentic Pentest: yeswehack.com/news/yeswehack-agentic-pentest
🟠 Get 20% off Caido Premium with code "AMRSEC20" (yearly plan only)

⭐ Become a Channel Member:
youtube.com/@AmrSecOfficial/join

⚠️ Disclaimer
This channel is for educational purposes only. The goal is to teach cybersecurity, ethical hacking, and red team/blue team skills through real tools, techniques, and experience. Always hack ethically. 🫑

πŸ• Timestamps
00:00 β€” Introduction
01:58 β€” What a WebSocket Actually Is
03:44 β€” Why WebSockets Are a Blind Spot
05:04 β€” The Five-Step Recipe and Your Caido Toolkit
11:53 β€” Broken Authorization: Talking Like an Admin
17:43 β€” One ID Field: From IDOR to SQL Injection
22:16 β€” The GraphQL Subprotocol Nobody Picks
28:29 β€” From a Webpage to a Shell (CSWSH)
31:43 β€” Is CSWSH Still Worth Hunting in 2026?
33:39 β€” How Deep the Rabbit Hole Goes
35:12 β€” Recap: Don't Quit at the 101

Follow AmrSec
LinkedIn: linkedin.com/in/amrelsagaei
Twitter/X: twitter.com/amrelsagaei
Instagram: instagram.com/amrelsagaei

#BugBounty #WebSockets #Caido #WebSecurity #EthicalHacking
Hunting WebsocketsStop Guessing. Start Hunting. (The Roadmap)Cache Poisoning | The Cache You Cant PurgeJavaScript Analysis Masterclass - Part 1SSTI From Input To RCEForget Low-Hanging Fruit. Hunt These InsteadGraphQL for Bug Bounty HuntersThe Bug Bounty Report Blueprint Triagers Don’t IgnoreAPI Penetration Testing πŸ”GraphQL For HackersπŸ€”Bug Bounty Hunting Methodology 2025 πŸͺ²What is ServiceWorker and Who it works
AmrSec |

Hunting Websockets

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER