WSSiP Logo

WSSiP

0
Free
Visit Website

Short for "WebSocket/Socket.io Proxy", this tool, written in Node.js, provides a user interface to capture, intercept, send custom messages and view all WebSocket and Socket.IO communications between the client and server. Upstream proxy support also means you can forward HTTP/HTTPS traffic to an intercepting proxy of your choice (e.g. Burp Suite or Pappy Proxy) but view WebSocket traffic in WSSiP. There is an outward bridge via HTTP to write a fuzzer in any language you choose to debug and fuzz for security vulnerabilities. See Fuzzing for more details. Written and maintained by Samantha Chalker (@thekettu). Icon for WSSiP release provided by @dragonfoxing. Installation From Packaged Application See Releases. From npx via npm (for CLI commands) Run the following in your command line: npx wssip. From Source Using a command line: # Clone repository locally git clone https://github.com/nccgroup/wssip # Change to the directory cd wssip # If you are developing for WSSiP: # npm i # If not... (as to minimize disk space): npm i electron npm i --production # Yarn version: # yarn add electron # yarn install

FEATURES

ALTERNATIVES

A powerful directory/file, DNS and VHost busting tool written in Go.

A tool for extracting files from network traffic based on file signatures with support for various file formats and scalable search algorithm.

Smart traffic sniffing tool for penetration testers

A tool to discover new target domains using Content Security Policy

Authenticated SSRF in Grafana

Chaosreader is a tool for ripping files from network sniffing dumps and replaying various protocols and file transfers.

Hale is a botnet command & control monitor/spy with a modular design and various monitoring capabilities, including IRC and HTTP, to aid in botnet hunting and research.

A next-generation network scanner for identifying security configuration weaknesses in devices like routers, firewalls, and switches.