Collected research
Automatic Forgery of Cryptographically Consistent Messages to Identify Security Vulnerabilities in Mobile Services
Mobile apps sign, hash or encrypt their API requests, so servers assume a client cannot forge a valid message. AUTOFORGE reverse-engineers how a client builds messages and automatically produces cryptographically consistent ones, letting an attacker brute-force passwords, probe leaked passwords and hijack Facebook access tokens against app backends.
Record
- Researcher
- Chaoshun Zuo, Wubing Wang, Rui Wang and Zhiqiang Lin
- Published by
- ndss-symposium.org
- Format
- Whitepaper
- Topic
- Crypto
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Chaoshun Zuo, Wubing Wang, Rui Wang and Zhiqiang Lin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .