Web Hack List

Collected research

Pre-hijacked Accounts: An Empirical Study of Security Failures in User Account Creation on the Web

[2205.10174] Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the Web

Account pre-hijacking: an attacker knowing only a victim's email address creates or primes an account at a service before the victim signs up, then regains access after the victim registers or recovers it. Five variants abuse the interaction of classic passwords with federated sign-in; 35 of 75 popular services tested were vulnerable, often invisibly to the victim.

Record

Document
[2205.10174] Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the Web
Researcher
Avinash Sudhodanan and Andrew Paverd
Published by
arXiv.org
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Avinash Sudhodanan and Andrew Paverd, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .