Web Hack List

Collected research

Automatic Forgery of Cryptographically Consistent Messages to Identify Security Vulnerabilities in Mobile Services

Mobile apps sign, hash or encrypt their API requests, so servers assume a client cannot forge a valid message. AUTOFORGE reverse-engineers how a client builds messages and automatically produces cryptographically consistent ones, letting an attacker brute-force passwords, probe leaked passwords and hijack Facebook access tokens against app backends.

Record

Researcher
Chaoshun Zuo, Wubing Wang, Rui Wang and Zhiqiang Lin
Published by
ndss-symposium.org
Format
Whitepaper
Topic
Crypto

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Chaoshun Zuo, Wubing Wang, Rui Wang and Zhiqiang Lin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .