Web Hack List

Collected research

Attack Patterns for Black-Box Security Testing of Multi-Party Web Applications

Security protocols behind multi-party web applications, such as single sign-on and Cashier-as-a-Service payment flows, share structural features that let an attack on one be generalised to others. The paper distils thirteen published attacks into seven reusable attack patterns and builds a black-box tester on OWASP ZAP that instantiates them automatically, covering replay, login CSRF and stored XSS. It found twenty-one previously unknown vulnerabilities in prominent providers.

Record

Researcher
Avinash Sudhodanan, Alessandro Armando, Roberto Carbone and Luca Compagna
Published by
ndss-symposium.org
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Avinash Sudhodanan, Alessandro Armando, Roberto Carbone and Luca Compagna, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .