Cross-Site WebSocket Hijacking — generic PoC, no hardcoded credentials required
| Check | Result |
|---|---|
| CORS allows any Origin | pending |
| WebSocket cross-origin accepted | pending |
| Engine.IO SID granted | pending |
| Socket.IO namespace connected | pending |
| Cookies exist for target domain | pending |
| Cookies sent in WS handshake | pending |
| Session auto-authenticated | pending |
| Real-time data leaked | pending |
No frames captured yet. Run the PoC to start.