Cross-Site WebSocket Hijacking: CSRF on a Connection That Talks Back
A WebSocket handshake carries the user's cookies but faces no CORS check. When the server skips Origin validation, any page the user visits can open an authenticated socket, read what it pushes and send commands back. Here is how to test for it and how to close it.