Collected research
Attack Patterns for Black-Box Security Testing of Multi-Party Web Applications
Security protocols behind multi-party web applications, such as single sign-on and Cashier-as-a-Service payment flows, share structural features that let an attack on one be generalised to others. The paper distils thirteen published attacks into seven reusable attack patterns and builds a black-box tester on OWASP ZAP that instantiates them automatically, covering replay, login CSRF and stored XSS. It found twenty-one previously unknown vulnerabilities in prominent providers.
Record
- Researcher
- Avinash Sudhodanan, Alessandro Armando, Roberto Carbone and Luca Compagna
- Published by
- ndss-symposium.org
- Format
- Whitepaper
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Avinash Sudhodanan, Alessandro Armando, Roberto Carbone and Luca Compagna, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .