Top 10 winner
Flickr's API Signature Forgery Vulnerability (MD5 extension attack)
Flickr's API Signature Forgery Vulnerability
Advisory MOCB-01 combines MD5 length extension with delimiter-free API parameter signing to forge requests for Flickr applications without their shared secret. It documents the attack, PHPFlickr redirect abuse, vendor responses, and HMAC-based remediation, while distinguishing application impersonation from user account compromise.
Record
- Document
- Flickr's API Signature Forgery Vulnerability
- Researcher
- Thai Duong and Juliano Rizzo
- Published by
- Netifera
- Date
- Format
- Paper
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Thai Duong and Juliano Rizzo, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .