JSONP Broadcast Auth Demo
Demonstrates the JSONP auth token leakage vulnerability in Laravel's
PusherBroadcaster.
How it works:
- Log in to establish an authenticated session
- The dashboard connects to Reverb via Echo on a private channel
- Open the attacker page (exploit/attacker.html) separately
- The attacker page steals your auth token via JSONP
- The attacker subscribes to the private channel using the stolen token
- Send a message from the dashboard — the attacker receives it
See FINDING-JSONP-BROADCAST-AUTH.md for the full vulnerability disclosure.