Web Hack List

Collected research

The Devil is in the (Implementation) Details: An Empirical Analysis of OAuth SSO Systems

A black-box study of three OAuth 2.0 identity providers and 96 Facebook relying parties, tracing SSO credentials through browser HTTP traffic with a Firefox add-on and semi-automatic exploit tools. Access tokens leaked unencrypted on 32% of RPs, could be stolen via XSS on 91%, and 64% let an attacker impersonate a user by replaying an unbound SSO credential.

Record

Researcher
San-Tsai Sun and Konstantin Beznosov
Published by
css.csail.mit.edu
Format
Whitepaper
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of San-Tsai Sun and Konstantin Beznosov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .