Web-Hook

Webhook as the name implies is anchor script that allow interaction between web-based applications through the use of customized callback sessions between platforms. It allows web applications to automatically communicate with other web-apps.

As a result, the controller or originator of the anchor script(s) can manipulate transfer of the subject’s system data automatically whenever some event occur. 

Webhooks operate entirely over the internet. It’s an HTTP-based callback function that allows lightweight, event-driven communication between application programming interfaces.

Webhooks rely on the availability of static Universal Resource Locator (URLs) that directs to APIs (Application Programmable Interfaces) in the subject’s system. This must be notified upon activation of event on the observer system.

While Webhooks help to keep applications informed of changes in other systems like a successful web-payment or a newly opened pull request, An attacker can inject malicious code into the payload of the webhook, which can then be executed by the receiving server.

This can be achieved by infecting the browser of the victim with bad scripts over the internet to intercept the data transfer as normally seen in Man-In-The Browser attack.

Its therefore advised that your browser be always checked for anomalies and constantly be upgraded and updated. Before transacting online, especially payment sites, you are advised to clear your browser cache history and possibly delete stored session cookies.

Thanks


Engr. Chikwado .F. Okeke
Cybersecurity Professional
Certified in Cybersecurity CC by ISC2
https://possibond.com.
+234(0)8127944123